Cisco PIX 525 Especificações Página 308

  • Descarregar
  • Adicionar aos meus manuais
  • Imprimir
  • Página
    / 466
  • Índice
  • MARCADORES
  • Avaliado. / 5. Com base em avaliações de clientes
Vista de página 307
9-6
Cisco PIX Firewall and VPN Configuration Guide
78-15033-01
Chapter 9 Accessing and Monitoring PIX Firewall
Command Authorization and LOCAL User Authentication
Overview
LOCAL and TACACS+ Command Authorization is supported in PIX Firewall Version 6.2 and higher.
With the LOCAL command authorization feature, you can assign PIX
Firewall commands to one of 16
levels.
Caution When configuring the Command Authorization feature, do not save your configuration until you are sure
it works the way you want. If you get locked out because of a mistake, you can usually recover access
by simply restarting the PIX
Firewall from the configuration that is saved in Flash memory. If you still
get locked out, refer to the section “Recovering from Lockout.”
Configuring LOCAL Command Authorization
In the default configuration, each PIX Firewall command is assigned to either privilege level 0 or
privilege level 15. To reassign a specific command to a different privilege level, enter the following
command:
[no] privilege [{show | clear | configure}] level level [mode {enable|configure}] command
command
Replace level with the privilege level and command with the command you want to assign to the
specified level. You can use the show, clear, or configure parameter to optionally set the privilege level
for the show, clear, or configure command modifiers of the specified command. Replace command with
the command for which you wish to assign privileges. For the full syntax of this command, including
additional options, refer to the PIX Firewall Command Reference.
For example, the following commands set the privilege of the different command modifiers of the
access-list command:
privilege show level 10 command access-list
privilege configure level 12 command access-list
privilege clear level 11 command access-list
The first line sets the privilege of show access-list (show modifier of cmd access-list) to 10. The second
line sets the privilege level of the configure modifier to 12, and the last line sets the privilege level of
the clear modifier to 11.
To set the privilege of all the modifiers of the access-list command to a single privilege level of 10, you
would enter the following command:
privilege level 10 command access-list
For commands that are available in multiple modes, use the mode parameter to specify the mode in
which the privilege level applies.
The following are examples of setting privilege levels for mode-specific commands:
privilege show level 15 mode configure command configure
privilege clear level 15 mode configure command configure
privilege configure level 15 mode configure command configure
privilege configure level 15 mode enable command configure
privilege configure level 0 mode enable command enable
privilege show level 15 mode configure command enable
privilege configure level 15 mode configure command enable
privilege configure level 15 mode configure command igmp
privilege show level 15 mode configure command igmp
privilege clear level 15 mode configure command igmp
Vista de página 307
1 2 ... 303 304 305 306 307 308 309 310 311 312 313 ... 465 466

Comentários a estes Manuais

Sem comentários