11-08-2013 08:38 AM
Hello All,
I've been looking all over the place to try and find if it's possible to create more then one admin account on a Cisco ASA 5510. I search google but couldn't find anything. I looked through the CLI using telnet and also on the "Cisco ASDM 7.1 for ASA" application window and still can't find a way, or if its even possible.
I was hoping to abe able to create a secondary admin account, is this possible?
Thanks,
Matt
11-08-2013 09:18 AM
Hi,
What is your "aaa" configuration?
The output of the following command should tell this
show run aaa
I am just wondering if you are using the configuration
aaa authentication enable console LOCAL
If you are using the "aaa" configurations only for the "http" , "telnet" and "ssh" and not "enable" then I guess no matter what ever "username" configuration you log in with then using the enable password will grant you full rights with regards to configurations.
If you had "aaa authentication enable console LOCAL" then I think the "privilege" set in the "username" configuration for the account sets the amount of commands you can use.
- Jouni
11-08-2013 09:39 AM
Hey Jouni, thanks for the reply.
Yes, we are setup to need a password when entering "enable" command. But here is the 'aaa' config below...
show run aaa:
aaa authentication ssh console LOCAL
aaa authentication telnet console LOCAL
aaa authentication http console LOCAL
aaa authorization command LOCAL
But what I was trying to see was if it's possible to create a "secondary" account for another administrator/user.
For example:
Say there is 5 of us administrators who look at the ASA from time-to-time, is it possible to create an admin account for each person?
Thanks again for your reply!
Thanks,
Matt
11-08-2013 10:23 AM
Hi,
You can create as many "username" configurations as you want to login to the ASA.
username
- Jouni
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide