cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
402
Views
0
Helpful
1
Replies

deny router command on priv level 15

cfajardo1_2
Level 1
Level 1

device=ACS

objective=allow particular user to have privilege level 15 access to a device except router command

- i was trying to achieve the above but cant. my observation is i cant deny any commands under the config mode. but commands like ping,show,configure which are under the exec mode could be denied easily.

thanks in advance for any help.

1 Reply 1

smalkeric
Level 6
Level 6

By default, there are three command levels on the router:

• privilege level 0-Includes the disable, enable, exit, help, and logout commands

• privilege level 1-Includes all user-level commands at the router> prompt

• privilege level 15-Includes all enable-level commands at the router> prompt

You can move commands around between privilege levels with this command:

privilege exec level priv-lvl command

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: