We help IT Professionals succeed at work.

Router, Switch, ASA priviledge levels

Last Modified: 2012-05-06
i am trying to lcokdown my cisco equipment and need some assistance.

i created a test account and assigned in a 7 priviledge; why is it i am able to create a user account with a higher privilidge level?  

what i am looking to do is to lock down all of the accounts and limit the changes to our equipment.
Watch Question

atlas_shudderedSr. Network Engineer

Your new account is provisioning with default privileging at creation.  To limit access you will need to configure the privilege level with the access/permissioning you wish it to levy.  For more information on how to configure privilege level authorizations, reference the following documentation from Cisco -


By default the only privilege levels configured on a Cisco device are 0 and 15. All the others must be configured by you for what you want them to be able to do.


what i am looking to do is to lock down all of the accounts and limit the changes to our equipment.
How much equipment do you have?
You may want to look into an ACS server. It supports a much greater degree of granularity and would allow you keep all of your accounts centrally.


we have 6 devices....nothing that crazy.  

it seems as if people dont understand what i am asking.

i need to restrict accounts on my ASA from being able to make any changes to the firewall.  i.e. creating users is one of them.  i assumed that by lowering the pirvilidge number it reduced the amount of rights an acount can have but that isnt the case.  

To do what you want will require allot of manual permission configuration on these devices. The guide that atlas put up contains instructions on how to do this but it will take a great deal of time to get this working how you want it.
Sr. Network Engineer
This one is on us!
(Get your first solution completely free - no credit card required)

Gain unlimited access to on-demand training courses with an Experts Exchange subscription.

Get Access
Why Experts Exchange?

Experts Exchange always has the answer, or at the least points me in the correct direction! It is like having another employee that is extremely experienced.

Jim Murphy
Programmer at Smart IT Solutions

When asked, what has been your best career decision?

Deciding to stick with EE.

Mohamed Asif
Technical Department Head

Being involved with EE helped me to grow personally and professionally.

Carl Webster
CTP, Sr Infrastructure Consultant
Empower Your Career
Did You Know?

We've partnered with two important charities to provide clean water and computer science education to those who need it most. READ MORE

Ask ANY Question

Connect with Certified Experts to gain insight and support on specific technology challenges including:

  • Troubleshooting
  • Research
  • Professional Opinions
Unlock the solution to this question.
Join our community and discover your potential

Experts Exchange is the only place where you can interact directly with leading experts in the technology field. Become a member today and access the collective knowledge of thousands of technology experts.

*This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.


Please enter a first name

Please enter a last name

8+ characters (letters, numbers, and a symbol)

By clicking, you agree to the Terms of Use and Privacy Policy.