Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
New Member

How to create ASA ASDM read only account?

I tried creating a privilege 0 account for a client for read-only access to their ASA firewalls. For the CLI login, it won't matter cause they don't know the enable password, so that keeps them from making changes. But for the ASDM login, I was able to login with the privilege 0 account and make changes to the device (adding users).

I searched cisco.com and of course I found nothing good.

Should I create some 'privilege level 0' commands? I looked at that command and I didn't see anything to specify ASDM read only.

Any comments appreciated ,

Chris Serafin

Security Engineer

chris@chrisserafin.com

1 REPLY

Re: How to create ASA ASDM read only account?

Hi,

Yes you can bring show commands to a level say 3,

and the users with privilege level 3 should only have access to that level commands only.

But for management purpose, I would suggest not to change the level of command on device.

Rather use the command authorization feature on PIX/ASA, and make use of ACS(TACACS+),

http://www.cisco.com/en/US/docs/security/asa/asa72/configuration/guide/mgaccess.html#wp1042034

In above link you have information about both local and TACACS+ command authorization.

Regards,

Prem

355
Views
5
Helpful
1
Replies
CreatePlease to create content