cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
202
Views
0
Helpful
3
Replies

Creating user with different permission

raju
Level 1
Level 1

Hi,

I'm in the process of changing the passwords for all Cisco devices in my Network. As of now, everyone in Network Group can change the secret password , creation/deletion of vlan and changing port speed , checking logs etc..

As per new requirement , we are forming Network Operations Group , will do change of ports to different Vlan , change of port speed , checking logs etc.. and creation of Vlans and change of secret password will be Network Admin people. I want to create a local users for Network Operators in Cisco devices for doing above activities and they should not use secret password for doing above activities. What is the level of permission should I give and secret password will not be given to them.

Thanks

Raju

3 Replies 3

spremkumar
Level 9
Level 9

Hi

Would suggest to set different privilege levels and assign the activities like executing show commands accordingly to each privilege level.

keep privilege level 15 reserved coz that has the whole super level access to your box.

for more info do refer this link ..

http://www.cisco.com/en/US/products/ps6350/products_configuration_guide_chapter09186a00803f3bb7.html#wp1027188

regds

attrgautam
Level 5
Level 5

The best thing to do in such a case is to install a TACACS server. There will be the advantage of AAA though there may be cost overheads depending on the TACACS model.

amit-singh
Level 8
Level 8