12-13-2018 05:01 PM - edited 03-08-2019 04:48 PM
Hello everyone
How to restrict access to line console 0 for the specific user on the switch ?
Solved! Go to Solution.
12-14-2018 04:39 AM
Hello,
I have not found how to filter a created user.
But, in the line console configuration, you can remove the command login local and leave only the command login with a new password.
Then, you can share this new password only with authorized users.
Regards
12-14-2018 05:57 AM - edited 12-14-2018 05:57 AM
You won't be able to filter access and if the user has privilege 15, then he can do whatever if want.
However you have a feature called role based cli views. The goal is to create view and give them some commands they can run. Maybe it could be a workaround to give some users very few commands (like show ver) and they will connect to the console they will only get the command you defined.
There are multiple docs for this in Cisco website. Here one of them: https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_usr_cfg/configuration/15-mt/sec-usr-cfg-15-mt-book/sec-role-base-cli.pdf
12-13-2018 07:17 PM
12-13-2018 07:51 PM - edited 12-13-2018 07:53 PM
12-14-2018 12:01 AM - edited 12-14-2018 12:03 AM
Hi, luis_cordova
Basically I have to restrict access to only one user to the console line. This user exists locally.
12-14-2018 12:29 AM
Local to switch? As long as log in in enabled on the switch any user will need this credential to access, so you will have one log in? Unless Im am missing something here.
12-14-2018 12:33 AM
The user is created on the switch, but I want to restrict console access to this user only. In other words, it will not be able to login through the console line.
12-14-2018 04:39 AM
Hello,
I have not found how to filter a created user.
But, in the line console configuration, you can remove the command login local and leave only the command login with a new password.
Then, you can share this new password only with authorized users.
Regards
12-14-2018 05:57 AM - edited 12-14-2018 05:57 AM
You won't be able to filter access and if the user has privilege 15, then he can do whatever if want.
However you have a feature called role based cli views. The goal is to create view and give them some commands they can run. Maybe it could be a workaround to give some users very few commands (like show ver) and they will connect to the console they will only get the command you defined.
There are multiple docs for this in Cisco website. Here one of them: https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_usr_cfg/configuration/15-mt/sec-usr-cfg-15-mt-book/sec-role-base-cli.pdf
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide