40-13
Cisco Security Appliance Command Line Configuration Guide
OL-12172-03
Chapter 40 Managing System Access
Configuring AAA for System Administrators
hostname(config)#
privilege clear level 15 mode cmd command configure
hostname(config)#
privilege cmd level 15 mode cmd command configure
hostname(config)#
privilege cmd level 15 mode enable command configure
Note
This last line is for the
configure terminal
command.
Viewing Command Privilege Levels
The following commands let you view privilege levels for commands.
•
To show all commands, enter the following command:
hostname(config)#
show running-config all privilege all
•
To show commands for a specific level, enter the following command:
hostname(config)#
show running-config privilege level
level
The
level
is an integer between 0 and 15.
•
To show the level of a specific command, enter the following command:
hostname(config)#
show running-config privilege command
command
For example, for the
show running-config all privilege all
command, the system displays the current
assignment of each CLI command to a privilege level. The following is sample output from the
command.
hostname(config)#
show running-config all privilege all
privilege show level 15 command aaa
privilege clear level 15 command aaa
privilege configure level 15 command aaa
privilege show level 15 command aaa-server
privilege clear level 15 command aaa-server
privilege configure level 15 command aaa-server
privilege show level 15 command access-group
privilege clear level 15 command access-group
privilege configure level 15 command access-group
privilege show level 15 command access-list
privilege clear level 15 command access-list
privilege configure level 15 command access-list
privilege show level 15 command activation-key
privilege configure level 15 command activation-key
....
The following command displays the command assignments for privilege level 10:
hostname(config)#
show running-config privilege level 10
privilege show level 10 command aaa
The following command displays the command assignment for the
access-list
command:
hostname(config)#
show running-config privilege command access-list
privilege show level 15 command access-list
privilege clear level 15 command access-list
privilege configure level 15 command access-list
Configuring Command Authorization
If you enable command authorization, and a user enters a command at the CLI, the security
appliance sends the command and username to the server to determine if the command is
authorized.
Summary of Contents for 500 Series
Page 38: ...Contents xxxviii Cisco Security Appliance Command Line Configuration Guide OL 12172 03 ...
Page 45: ...P A R T 1 Getting Started and General Information ...
Page 46: ......
Page 277: ...P A R T 2 Configuring the Firewall ...
Page 278: ......
Page 561: ...P A R T 3 Configuring VPN ...
Page 562: ......
Page 891: ...P A R T 4 System Administration ...
Page 892: ......
Page 975: ...P A R T 5 Reference ...
Page 976: ......