40-11
Cisco Security Appliance Command Line Configuration Guide
OL-12172-03
Chapter 40 Managing System Access
Configuring AAA for System Administrators
To configure the local database, see the
“Configuring the Local Database” section on page 13-7
.
–
RADIUS users—Configure the user with Cisco VSA CVPN3000-Privilege-Level with a value
between 0 and 15.
–
LDAP users—Configure the user with a privilege level between 0 and 15, and then map the
LDAP attribute to Cisco VAS CVPN3000-Privilege-Level according to the
“LDAP Attribute
Mapping” section on page 13-14
.
Default Command Privilege Levels
By default, the following commands are assigned to privilege level 0. All other commands are at
level 15.
•
show checksum
•
show curpriv
•
enable
•
help
•
show history
•
login
•
logout
•
pager
•
show pager
•
clear pager
•
quit
•
show version
If you move any configure mode commands to a lower level than 15, be sure to move the
configure
command to that level as well, otherwise, the user will not be able to enter configuration mode.
To view all privilege levels, see the
“Viewing Command Privilege Levels” section on page 40-13
.
Assigning Privilege Levels to Commands and Enabling Authorization
To assign a command to a new privilege level, and enable authorization, follow these steps:
Step 1
To assign a command to a privilege level, enter the following command:
hostname(config)#
privilege
[
show
|
clear
|
cmd
]
level
level
[
mode
{
enable
|
cmd
}]
command
command
Repeat this command for each command you want to reassign.
See the following information about the options in this command:
•
show
|
clear
|
cmd
—These optional keywords let you set the privilege only for the show, clear, or
configure form of the command. The configure form of the command is typically the form that
causes a configuration change, either as the unmodified command (without the
show
or
clear
prefix)
or as the
no
form. If you do not use one of these keywords, all forms of the command are affected.
•
level
level
—A level between 0 and 15.
Summary of Contents for 500 Series
Page 38: ...Contents xxxviii Cisco Security Appliance Command Line Configuration Guide OL 12172 03 ...
Page 45: ...P A R T 1 Getting Started and General Information ...
Page 46: ......
Page 277: ...P A R T 2 Configuring the Firewall ...
Page 278: ......
Page 561: ...P A R T 3 Configuring VPN ...
Page 562: ......
Page 891: ...P A R T 4 System Administration ...
Page 892: ......
Page 975: ...P A R T 5 Reference ...
Page 976: ......