Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

Cisco router user limited configuration access level

Posted on 2012-03-26
7
Medium Priority
?
567 Views
Last Modified: 2012-06-22
Hello Experts,

I have a Cisco Router and I would like to limit a user access to the following:
1. Can not read or view the entire cisco router configuration
2. Can not add, change modify the configuration
3. I would like to only allow ping access to different network resources for troubleshooting

Any ideas are greatly apprecialted.
0
Comment
Question by:RandallVillalobos
  • 4
  • 3
7 Comments
 
LVL 5

Expert Comment

by:abhishek1986
ID: 37769783
If you want users not to be able to access switch via telnet, you can simply not tell them the password for the switch. Pinging is allowed by default and so you need not do anything for that.
If you have something else in mind, please be more specific as to your requirements and there are various features and privilege and roles that can be set for users, there are options to use AAA servers, Radius Servers as well for role definition and setup.
0
 

Author Comment

by:RandallVillalobos
ID: 37772329
Hello,

I would like to create a restricted local database user authentication (not AAA).
I remember a long time a ago, I was given a router username where I could only run certain features.

Not giving the enable password will not work (just tried it) because I can not run extended pings.

Thank you
0
 

Author Comment

by:RandallVillalobos
ID: 37778149
Any ideas?
0
2017 Webroot Threat Report

MSPs: Get the facts you need to protect your clients.
The 2017 Webroot Threat Report provides a uniquely insightful global view into the analysis and discoveries made by the Webroot® Threat Intelligence Platform to provide insights on key trends and risks as seen by our users.

 
LVL 5

Expert Comment

by:abhishek1986
ID: 37780269
Do you want other users to log in to the switch or not?
0
 

Author Comment

by:RandallVillalobos
ID: 37783717
Hi abhishek1986,

Yes, I would like for them to log in the router with local authentication.  Thanks for the help.
0
 
LVL 5

Accepted Solution

by:
abhishek1986 earned 2000 total points
ID: 37785552
There are ways regarding that:

Cisco routers have options to configure and customize 14 levels of privileged access.

http://www.cisco.com/en/US/docs/ios/12_2t/12_2t13/feature/guide/ftprienh.html
0
 

Author Closing Comment

by:RandallVillalobos
ID: 37787257
thanks
0

Featured Post

Veeam Task Manager for Hyper-V

Task Manager for Hyper-V provides critical information that allows you to monitor Hyper-V performance by displaying real-time views of CPU and memory at the individual VM-level, so you can quickly identify which VMs are using host resources.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Unable to change the program that handles the scan event from a network attached Canon/Brother printer/scanner. This means you'll always have to choose which program handles this action, e.g. ControlCenter4 (in the case of a Brother).
Tech spooks aren't just for those who are tech savvy, it also happens to those of us running a business. Check out the top tech spooks for business owners.
With Secure Portal Encryption, the recipient is sent a link to their email address directing them to the email laundry delivery page. From there, the recipient will be required to enter a user name and password to enter the page. Once the recipient …
NetCrunch network monitor is a highly extensive platform for network monitoring and alert generation. In this video you'll see a live demo of NetCrunch with most notable features explained in a walk-through manner. You'll also get to know the philos…

877 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question