Solved

setup AAA account in pix 525

Posted on 2007-11-30
1
1,106 Views
Last Modified: 2012-05-05
hi
i have pix 525 and i want to setup username and password for telnet ,console,https,enable
now i have username and password for telnet and for enable
first question how i can change password for enable and telnet
if i wnat to remove old username and password for enable and telnet how i can do that

now i want to use AAA in local account in pix
is this command true
pix(config)#username home password pixhome
pix(config)#aaa authentication telnet console local
pix(config)#aaa authentication ssh console local
pix(config)#aaa authentication http console local
pix(config)#aaa authentication enable console local
pix(config)#aaa authentication serial console local
pix(config)#aaa local authentication attempts max-fail 5

i want to made this user administrator
if i wnat to made user can only enter to enable mode and only show some command in this mode how i can do that and how i can prevent him from enter to config mode
must i use privilege command for each command in each mode
best regards
0
Comment
Question by:nasemabdullaa
1 Comment
 
LVL 29

Accepted Solution

by:
Alan Huseyin Kayahan earned 500 total points
ID: 20384239
  Hi nasemabdullaa
        For removing the username and password, simply type
        no username home password pixhome
       Users have privilege levels from 15 to 1. 15 is the full administrator, and 1 is the most restricted. For example
      username admin password admin priv 15     ------> full rights
      username guest password guest priv 1       ------->most restricted user

   you can use 14 13 12.....2 1 if you like, functionality gets restricted towards lowest level

Regards
0

Featured Post

Top 6 Sources for Identifying Threat Actor TTPs

Understanding your enemy is essential. These six sources will help you identify the most popular threat actor tactics, techniques, and procedures (TTPs).

Join & Write a Comment

This article assumes you have at least one Cisco ASA or PIX configured with working internet and a non-dynamic, public, address on the outside interface. If you need instructions on how to enable your device for internet, or basic configuration info…
Hi All,  Recently I have installed and configured a Sonicwall NS220 in the network as a firewall and Internet access gateway. All was working fine until users started reporting that they cannot use the Cisco VPN client to connect to the customer'…
Internet Business Fax to Email Made Easy - With eFax Corporate (http://www.enterprise.efax.com), you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, fr…
In this seventh video of the Xpdf series, we discuss and demonstrate the PDFfonts utility, which lists all the fonts used in a PDF file. It does this via a command line interface, making it suitable for use in programs, scripts, batch files — any pl…

760 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

18 Experts available now in Live!

Get 1:1 Help Now