
9-5
Cisco PIX Firewall and VPN Configuration Guide
78-15033-01
Chapter 9 Accessing and Monitoring PIX Firewall
Command Authorization and LOCAL User Authentication
Viewing the Current User Account
The PIX Firewall maintains usernames in the following authentication mechanisms:
• LOCAL
• TAC ACS+
• RADIUS
To view the user account that is currently logged in, enter the following command:
show curpriv
The system displays the current user name and privilege level, as follows:
Username:admin
Current privilege level: 15
Current Mode/s:P_PRIV
As mentioned in the section “Privilege Levels,” you use the enable command to obtain access to
different privilege levels with the following command:
pix> enable [privilege level]
When you assign a password to a privilege level, the privilege level is associated with the password in
the LOCAL database in the same way a username is associated with a password. When you obtain access
to a privilege level using the enable command, the show curpriv command displays the current privilege
level as a username in the format enable_n, where n is a privilege level from 1 to 15.
An example follows:
pix(config)# show curpriv
Username : enable_9
Current privilege level : 9
Current Mode/s : P_PRIV
When you enter the enable command without specifying the privilege level, the default privilege level
(15) is assumed and the username is set to enable_15.
When you log into the PIX Firewall for the first time or exit from the current session, the default user
name is enable_1, as follows:
pix> show curpriv
Username : enable_1
Current privilege level : 1
Current Mode/s : P_UNPR
Command Authorization
This section describes how to assign commands to different privilege levels. It includes the following
topics:
• Overview, page 9-6
• Configuring LOCAL Command Authorization, page 9-6
• Enabling LOCAL Command Authorization, page 9-7
• Viewing LOCAL Command Authorization Settings, page 9-7
• TACACS+ Command Authorization, page 9-8
Comentarios a estos manuales