Solved

Cisco router user limited configuration access level

Posted on 2012-03-26
7
548 Views
Last Modified: 2012-06-22
Hello Experts,

I have a Cisco Router and I would like to limit a user access to the following:
1. Can not read or view the entire cisco router configuration
2. Can not add, change modify the configuration
3. I would like to only allow ping access to different network resources for troubleshooting

Any ideas are greatly apprecialted.
0
Comment
Question by:RandallVillalobos
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 3
7 Comments
 
LVL 5

Expert Comment

by:abhishek1986
ID: 37769783
If you want users not to be able to access switch via telnet, you can simply not tell them the password for the switch. Pinging is allowed by default and so you need not do anything for that.
If you have something else in mind, please be more specific as to your requirements and there are various features and privilege and roles that can be set for users, there are options to use AAA servers, Radius Servers as well for role definition and setup.
0
 

Author Comment

by:RandallVillalobos
ID: 37772329
Hello,

I would like to create a restricted local database user authentication (not AAA).
I remember a long time a ago, I was given a router username where I could only run certain features.

Not giving the enable password will not work (just tried it) because I can not run extended pings.

Thank you
0
 

Author Comment

by:RandallVillalobos
ID: 37778149
Any ideas?
0
NEW Veeam Agent for Microsoft Windows

Backup and recover physical and cloud-based servers and workstations, as well as endpoint devices that belong to remote users. Avoid downtime and data loss quickly and easily for Windows-based physical or public cloud-based workloads!

 
LVL 5

Expert Comment

by:abhishek1986
ID: 37780269
Do you want other users to log in to the switch or not?
0
 

Author Comment

by:RandallVillalobos
ID: 37783717
Hi abhishek1986,

Yes, I would like for them to log in the router with local authentication.  Thanks for the help.
0
 
LVL 5

Accepted Solution

by:
abhishek1986 earned 500 total points
ID: 37785552
There are ways regarding that:

Cisco routers have options to configure and customize 14 levels of privileged access.

http://www.cisco.com/en/US/docs/ios/12_2t/12_2t13/feature/guide/ftprienh.html
0
 

Author Closing Comment

by:RandallVillalobos
ID: 37787257
thanks
0

Featured Post

Free Tool: Port Scanner

Check which ports are open to the outside world. Helps make sure that your firewall rules are working as intended.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article describes my battle tested process for setting up delegation. I use this process anywhere that I need to setup delegation. In the article I will show how it applies to Active Directory
Many old projects have bad code, but the budget doesn't exist to rewrite the codebase. You can update this code to be safer by introducing contemporary input validation, sanitation, and safer database queries.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Internet Business Fax to Email Made Easy - With  eFax Corporate (http://www.enterprise.efax.com), you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, f…

756 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question