How to: Create a limited user account on a Cisco Pix Firewall.
This is a snippet for the Cisco Pix firewall that create a ‘limited user‘ account on the firewall itself. That user will have access to all ‘show‘ diagnostic commands, as well as the ability to clear the error/usage counters on interfaces and to ping other devices.
This configuration does the following things:
Defines two user levels, ‘show‘ at 5 and ‘enable_15‘ at 15. (15 is the highest possible).
Sets all the ‘show’ commands to level 5
Sets the ‘configure’ level of ‘ping’ to level 5
Sets the ‘clear’ level of ‘interface’ to level 5
All other clear + configure commands remain only available to the level 15 user.
Here is the snippet :
aaa-server LOCAL protocol local
aaa authentication enable console LOCAL
aaa authorization command LOCAL
!
!
username enable_15 password [PUT YOUR ENABLE PASSWORD HERE] privilege 15
!
!
username show password [PUT YOUR SHOW PASSWORD HERE] privilege 5
!
!
privilege show level 5 command object-group
privilege show level 5 command access-group
privilege show level 5 command access-list
privilege show level 5 command arp
privilege show level 5 command banner
privilege show level 5 command capture
privilege show level 5 command clock
privilege show level 5 command conn
privilege show level 5 command console
privilege show level 5 command cpu
privilege show level 5 command Crashinfo
privilege show level 5 command crypto
privilege show level 5 command debug
privilege show level 5 command domain-name
privilege show level 5 command established
privilege show level 5 command fixup
privilege show level 5 command flashfs
privilege show level 5 command fragment
privilege show level 5 command icmp
privilege show level 5 command interface
privilege show level 5 command ip
privilege show level 5 command ipsec
privilege show level 5 command isakmp
privilege show level 5 command map
privilege show level 5 command memory
privilege show level 5 command mtu
privilege show level 5 command name
privilege show level 5 command nameif
privilege show level 5 command names
privilege show level 5 command nat
privilege show level 5 command ntp
privilege show level 5 command outbound
privilege show level 5 command processes
privilege show level 5 command route
privilege show level 5 command route-map
privilege show level 5 command router
privilege show level 5 command routing
privilege show level 5 command running-config
privilege show level 5 command service
privilege show level 5 command ssh
privilege show level 5 command startup-config
privilege show level 5 command static
privilege show level 5 command tcpstat
privilege show level 5 command tech-support
privilege show level 5 command telnet
privilege show level 5 command terminal
privilege show level 5 command traffic
privilege show level 5 command who
privilege show level 5 command xlate
!
privilege configure level 5 command ping
privilege configure level 5 command disable
!
privilege clear level 5 command interface
By default, there are three privilege levels on the router.
- privilege level 1 = non-privileged (prompt is router>), the default level for logging in
- privilege level 15 = privileged (prompt is router#), the level after going into enable mode
- privilege level 0 = seldom used, but includes 5 commands: disable, enable, exit, help, and logout
Comments
(There are currently no comments for this post.)