08-23-2017 07:06 AM - edited 03-08-2019 11:48 AM
Is it possible to disable entering an enable mode on IOS ?
Im deploying radius servers with two user groups (lvl 1 and lvl 15) my goal is to do that users who are lvl 1 would be not permited to enter enable mode.
Yes, i know i can create a password for enable mode. But maybe it's possible to even not to let the enter that mode for level 1 users ? Thanks.
Solved! Go to Solution.
08-23-2017 08:10 AM
yes thats a good way too dont even let them see the command in level 1
08-23-2017 07:19 AM
Hi
I have done it in ACS for our NOC alright
set user up as priv 1 they cant get out of > mode then too
privilege level 1 — Normal level on Telnet; includes all user-level commands at the router> prompt.
see this doc exaplins it more
08-23-2017 07:24 AM
Thnank you, but priv lvl 1 user can enter to enable mode.
R1>en
R1>enable
R1#
For me the best thing would be not to enter to priviledge mode at all.
08-23-2017 07:27 AM
hi can you post the show privilege there while logged in as that , you shouldnt even be able to run show run in priv 1
08-23-2017 07:31 AM - edited 08-23-2017 07:37 AM
the levels work up to 16 , 1-15 with 1 being basically no access to the router no show run , you can do very basic checks only
Privilege level 0 — includes the disable, enable, exit, help, and logout commands.
Privilege level 1 — Normal level on Telnet; includes all user-level commands at the router> prompt.
Privilege level 15 — includes all enable-level commands at the router# prompt.
if its still allowing enable even in level 1 you can lock down the level to only allow certain commands to be typed thats another way to block them , dont allow enable in your custom list for what they can do
can you not block them from your radius server when you set them up as user on it , is there no option for that ?
08-23-2017 07:51 AM
on privilege 1 i've no right to enter the "show priviledge" :)
yes, i know i can limit the commands but maybe theres some global command to enabe disable the entering to that mode.
08-23-2017 07:56 AM
ok well that should block them even though the enable may work priv 1 should stop them seeing or doing anything in that mode , they will have a couple of commands but very limited i dont think you can even see the interfaces its the most restricted mode available
im not aware of a global command to do it , we had to do it through ACS and AAA configuration and theres a bit in it , theres no just 1 command to turn it off i dont think anyway
08-23-2017 08:08 AM
Hello,
on a side note, you can remove the 'enable' command from level 1 altogther by assigning it to the lext level:
Router(config)#privilege exec level 2 enable
Once you do that, and you login with level 1, the 'enable' command is not there anymore...
Not sure if this is relevant to your question...
08-23-2017 08:10 AM
yes thats a good way too dont even let them see the command in level 1
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide