
9-7
Cisco PIX Firewall and VPN Configuration Guide
78-15033-01
Chapter 9 Accessing and Monitoring PIX Firewall
Command Authorization and LOCAL User Authentication
privilege show level 15 mode configure command logging
privilege clear level 15 mode configure command logging
privilege configure level 15 mode configure command logging
privilege clear level 15 mode enable command logging
privilege configure level 15 mode enable command logging
Note Do not use the mode parameter for commands that are not mode-specific.
By default, the following commands are assigned to privilege level 0:
privilege show level 0 command checksum
privilege show level 0 command curpriv
privilege configure level 0 command help
privilege show level 0 command history
privilege configure level 0 command login
privilege configure level 0 command logout
privilege show level 0 command pager
privilege clear level 0 command pager
privilege configure level 0 command pager
privilege configure level 0 command quit
privilege show level 0 command version
Enabling LOCAL Command Authorization
Once you have reassigned privileges to commands from the defaults, as necessary, enable the command
authorization feature by entering the following command:
aaa authorization command LOCAL
By specifying LOCAL, the user’s privilege level and the privilege settings that have been assigned to the
different commands are used to make authorization decisions.
When users log in to the PIX Firewall, they can enter any command assigned to their privilege level or
to lower privilege levels. For example, a user account with a privilege level of 15 can access every
command because this is the highest privilege level. A user account with a privilege level of 0 can only
access the commands assigned to level 0.
Viewing LOCAL Command Authorization Settings
To view the CLI command assignments for each privilege level, enter the following command:
show privilege all
The system displays the current assignment of each CLI command to a privilege level. The following
example illustrates the first part of the display:
pix(config)# show privilege all
privilege show level 15 command aaa
privilege clear level 15 command aaa
privilege configure level 15 command aaa
privilege show level 15 command aaa-server
privilege clear level 15 command aaa-server
privilege configure level 15 command aaa-server
privilege show level 15 command access-group
privilege clear level 15 command access-group
privilege configure level 15 command access-group
privilege show level 15 command access-list
Comentarios a estos manuales