Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

Restrict ASDM access via AAA server

I cannot seem to restrict a users' access to the monitor tab or to read-only access. I have been told it can be done. Help!

PIX 7.0(2) - ASDM 5.0(2)


Re: Restrict ASDM access via AAA server


In the ADSM you should find the settings under

Configuration > Features > Device Administration > Administration > AAA Access > Authorization Tab

Authorization lets you control access per user after you authenticate with a valid username and

password. You can configure the security appliance to authorize management commands.

Authorization lets you control which services and commands are available to an individual user.

Authentication alone provides the same access to services for all authenticated users.

When you enable command authorization, you have the option of manually assigning privilege levels to

individual commands or groups of commands (using the Advanced... button) or enabling the Predefined

User Account Privileges (using the Restore Predefined User Account Privileges button).

The Predefined User Account Privileges Setup panel displays a list of commands and privileges ASDM

issues to the security appliance if you click Yes. Yes allows ASDM to support the three privilege levels:

Admin, Read Only and Monitor Only.

The complete explanation can be found in "ASDM Online Help, Release 5.0" at

Hope this helps! Please rate all posts.

Regards, Martin

New Member

Re: Restrict ASDM access via AAA server

Yes, I can see how this is done if I am doing LOCAL authentication, but if I am authenticating through a AAA server I have to set the authorization on the AAA server and it doesn't seem to work. I am using Cisco ACS TACAS+ server.

Re: Restrict ASDM access via AAA server

Oh, sorry I have overlooked your request for ACS.

The description on how to setup command authorization with ACS is found at

In your case the description on how to configure the ACS with examples is at "Configuring Commands on the TACACS+ Server" at

Hope this helps! Please rate all posts.

Regards, Martin