Cisco - level privilege is always 15

I use RADIUS for the AAA process.

When I was running IOS 12.2 on routers, that everything was fine, but after the upgrade for users of 12.4 (12) IOS Version still gets priv-lvl 15 without worrying
what I put in RADIUS profile for the user.

I do not understand why router CISCO AV pair priv-lvl = y twice. And why, in the most recent version of the CISCO-AV-pair priv-lvl = came (value set to the RADIUS) first?

IOS 12.2

19 August 15:09:17.926: AAA/AUTHOR/EXEC(0000059A): treatment AV priv-lvl = 15

19 August 15:09:17.926: AAA/AUTHOR/EXEC(0000059A): treatment AV priv-lvl = 1

19 August 15:09:17.926: AAA/AUTHOR/EXEC(0000059A): successful authorization

IOS 12.4 (12)

19 August 15:09:17.926: AAA/AUTHOR/EXEC(0000059A): treatment AV priv-lvl = 1

19 August 15:09:17.926: AAA/AUTHOR/EXEC(0000059A): treatment AV priv-lvl = 15

19 August 15:09:17.926: AAA/AUTHOR/EXEC(0000059A): treatment AV service-type = 6

19 August 15:09:17.926: AAA/AUTHOR/EXEC(0000059A): successful authorization

Thank you

GOING

Looks like the type of service = 'administration', that is what triggers the privilege level escalation.

Tags: Cisco Security

Similar Questions

  • Object-level privileges granted...

    Hello

    I want to grant object-level privileges to some user so that he can view (select) any object which resides under another user. Don't select any option from the table.

    I tried in vain to do something like that.

    Kind regards

    Why do you have thousands of tables in a schema?

    And Yes quite easy to grant privileges in this way

    Connect the schema that you want to grant of in.

    -- 'Granting select on tables and views to  scott'
    declare
    v_sql varchar2(4000);
    begin
          for cur in
          (
              select object_name from user_objects
              where object_type in ('TABLE','VIEW','MATERIALIZED VIEW')
          )
          loop
              v_sql := 'grant select on '||cur.object_name||' to scott';
              execute immediate v_sql;
          end loop;
    end;
    /
    

    If I were you, I would create a role.
    And then grant privileges to this role.
    He can then grant this role to users.
    And it's much easier than the grant select on thousands of tables

    Published by: Keith Jamieson on August 28, 2012 10:02

  • Check the package/procedure for a user level privileges

    Hi gurus,
    How to check the package/procedure for a user-level privileges? as dba_tab_privs for the tables.

    for example: grant execute on User1 dbms_scheduler.
    now I must verify that user1 has run on dbms_scheduler privilege or not.

    What is the advice for this?

    Thanks in advance,
    Charles
    SQL> select privilege, count(*) from dba_tab_privs group by privilege order by 1;
    
    PRIVILEGE                       COUNT(*)
    ---------------------------------------- ----------
    ALTER                               19
    DEBUG                              256
    DELETE                              131
    DEQUEUE                            3
    EXECUTE                           19315
    FLASHBACK                          52
    INDEX                               14
    INSERT                              137
    MERGE VIEW                          36
    ON COMMIT REFRESH                     52
    QUERY REWRITE                          52
    
    PRIVILEGE                       COUNT(*)
    ---------------------------------------- ----------
    READ                                7
    REFERENCES                          54
    SELECT                                3752
    UNDER                                3
    UPDATE                              111
    WRITE                                5
    
    17 rows selected.
    

    DBA_TAB_PRIVS is more than simple tables.

  • CISCO CLEAN ACCESS AGENT ALWAYS OPENS EVEN ALREADY AUTHENTICATED

    Hello

    Just wonder why officer own access always opens even already authenticated. Please how can I eliminate multiple pop-ups?

    Thank you and best regards,

    Edwin

    Edwin,

    This occurs because of a misconfiguration and is not normal. Give more details about your configuration, a diagram of network if possible.

    Faisal

  • Configure the read-access via user-defined privilege level

    Hello everyone,

    I m looking for the best configuration to restrict a user read-only. The restriction must be configured through CLI not GANYMEDE.

    Material: 3750 (probably not interesting for that matter)

    More old IOS: 12.2 (53) SE1

    The user should be allowed to:

    • See the running configuration
    • trigger all sorts of orders-show
    • Ping and traceroute of the device

    The user should not be allowed to:

    • Download/delete/rename files on the flash memory
    • Enter the level 15 (not sure if I can avoid it)
    • all orders despite those level 1 and those specified above

    Can someone help me with this?

    Thanks in advance!

    I have won´t forgotten messages useful rates

    Hi Tobias,.

    You can

    set up multiple levels of privilege on a switch as explained below.

    By default, the Cisco IOS Software has two modes of password security: user EXEC and

    Privileged EXEC. You can configure up to 16 levels of commands for each mode.

    By configuring multiple passwords, you can allow different sets of users to have access to

    specified commands.

    For example, if you want many users to have access to the clear line command, you can

    He attributed a level 2 security and distribute the level 2 password fairly widely. But if you

    want more restricted access to the command configure, you can assign security to level 3

    and distribute the password to a more restricted group of users.

    Definition of the level of privilege for a command

    Beginning in privileged EXEC mode, follow these steps to set the privilege level for a

    control mode:

    Purpose of command

    Step 1

    Configure the terminal

    Enter global configuration mode.

    Step 2

    level privilege mode level control

    Set the level of privilege for a command.

    For mode, enter set for the global configuration mode, exec to EXEC mode, interface

    for the interface configuration mode, or the line for line configuration mode.

    For level, the range is from 0 to 15. Level 1 is normal user EXEC mode privileges.

    Level 15 is the level of access allowed by the enable password.

    For command, enter the command that you want to restrict access.

    Step 3

    activate the password level

    Specify the password to enable for the privilege level.

    . For level, the range is from 0 to 15. Level 1 is normal user EXEC mode privileges.

    Password, specify a string from 1 to 25 alphanumeric characters. The string cannot

    start with a number, is case sensitive and allows spaces but ignores leading spaces. By

    by default, no password is defined.

    Step 4

    end

    Return to privileged mode.

    Step 5

    Show running-config

    or

    Show privilege

    Check your entries.

    The first command shows the level of the password configuration and access. The second command

    Displays the privilege level configuration.

    Step 6

    copy running-config startup-config

    (Optional) Save your entries in the configuration file.

    When you set a command to a privilege level, all commands whose syntax is a subset of this

    control can also be programmed at this level. For example, if you set the show ip traffic command

    level 15 show commands and show ip commands are automatically set to privilege level

    15 unless you set them individually at different levels.

    To return to the privilege by default for a given command, use the no privilege mode level

    control of level global configuration command.

    This example shows how to set the command configures to focus on level 14 and set

    SecretPswd14 as the password users must enter to use 14 level controls:

    Switch (config) # level 14 exec privileges set up

    Switch (config) # enable password 14 SecretPswd14 level

    You can also change the default privilege for every user level.

    Change the level of privilege by default for lines beginning in privileged EXEC mode follow these steps to change the default privilege for a line level: complete order

    Step 1 Configure terminal enter global configuration mode.

    Step 2 line vty select the virtual terminal line to restrict access.

    Step 3 privilege level change the default privilege for the line level.

    For level, the range is from 0 to 15. Level 1 is normal user EXEC mode

    privileges. Level 15 is the level of access allowed by the enable password.

    End of step 4 back in privileged mode.

    Step 5 show running-config or show privilege

    Check your entries. The first command shows the level of the password configuration and access.

    The second command shows the privilege level configuration.

    Step 6 copy running-config startup-config (optional) save your entries in the configuration file.

    Users can replace the privilege level that you set by using the privilege level line configuration command

    you connect to the line and enabling a different privilege level.

    They can lower the privilege level by using the disable command.

    If users know the password to a higher privilege level, they can use this password to enable the higher privilege level. You can specify a privilege for your console line level to restrict the use of the line or high-level.

    To restore the default line privilege level, use the no privilege level line configuration command. Also I send you a document for your reference.

    http://www.Cisco.com/univercd/CC/TD/doc/product/LAN/cat3750/12225see/SCG/swauthen.htm #wp1154063

    HTH

    Concerning

    Reem

  • Installation of Nexus 1000v / vCenter user privilege level

    Good afternoon

    I had a question about the necessary privilege concerning the installation of a Nexus 1000v.

    Last week, we install last version of the Nexus1000v on ESXi 5.0.0 Releasebuild-721882 switch.

    After a first installation, we noticed we could not establish the connection between the Nexus1000v and the vCenter [error = > the vCenter Extension key was not saved before use].

    The key was present on the Nexus 1000v but was not registered under the vCenter MOB (Extension Manager).

    We had to increase the privilege level of the service (to vCenter admin) account and re-install to get registred the extension key.

    Cisco said that we must use vCenter user with administrator-level privileges to install the Nexus 1000v, but please find my questions:

    1 / is it possible to install a Nexus 1000v with administrator privileges "Data center" (no admin vCenter). In general, what is the minimum level of privileges possible to install a Nexus 1000v?

    2 / once the privilege is passed to vCenter admin and the installation, it is possible to reduce to a privilege of lower level without affecting the Nexus 1000v?

    I'm a network guy, not a guy of sorry server if I'm unclear in my questions :-)

    Thanks in advance for your answers.

    Kind regards.

    Kara

    You cannot change the privilege level after the initial connection. He needs to remain at the same level of private.

    One of the things to keep in mind is that there is a constant back and forth between the MSM and vCenter. We are pulling and pushing data into vcenter. Every time a VM vmotions, gets turned on, destroyed or changed requires communication between the MSM and vCenter.

    Louis

  • Level of different privilege for users Active directory

    Hello

    We have integrated the Acs 4.1se with directory.now active windows, must be given some full privige of users some client devices, and show only level privilege to some devices.what is that the steps required in ACS and ACS customers. Also how long dynamic users will stay in ACSthanks in advance

    Also in acs an aaa client or user may not be a part of the group then one more.

    Kind regards

    ~ JG

  • Impossible to obtain the privileges on Dell OpenManage

    Hello

    I installed OpenManage 7.4.0 on a new server EP R320 running Ubuntu 14.04.  I installed the same way I've always done successfully, but now I can't get the "Administrator" privileges  When I login with user and password of my system, I get only the 'User' access level (I got "Power User" once (!)).

    My content in the/opt/dell/srvadmin/etc/omarolemap file:

    # This is the default entries specified to allow users with OS-level privileges in OMSA
    root * Administrator
    #+ root * Poweruser
    #*      *       User
    + SMA * administrator

    My user is a member of the ADM group:

    # id xxxx
    UID = 1001 (xxxx) gid = 1001 (xxxx) groups = 1001 (xxxx), 4 (adm), 27 (sudo)

    What's wrong?

    Try changing the permissions of files on omarolemap 640 http://lists.us.dell.com/pipermail/linux-poweredge/2015-March/049712.html

  • AAA authentication in Cisco router

    I want to create the user name and password with the level of prévilige for each user in the Cisco 3640 router. I don't have any authentication server, and I want to use the local database of the Cisco router to do this. Can someone suggest me how should I proceed.

    Thanks in advance

    Hello

    If you want to create users in the local database of the router, you must use the following command

    username cisco password privilege 5 test

    AAA new-model

    AAA authentic login default local

    AAA exec default local author

    http://www.Cisco.com/univercd/CC/TD/doc/product/software/ios122/122cgcr/fsecur_c/fsaaa/scfathen.htm#12277

    Thank you

    Sujit

  • Custom privileges for the user, MSE 8510 blade

    Hello!

    Does anyone know if it is possible to create a user account on the MSE 8510 blade with 'custom' privileges more than the preconfigured settings?

    Example: You can create a user who can display one or more conferences (and only) and "limited control" for those conferences WITHOUT giving the user the ability to view/edit other conferences?

    Kind regards

    OLA

    HI, Ola,

    I'm afraid that this is not possible at the moment, and my suggestion here is to wear a request functionality, through the Key Account Manager - based on the effect of nbusiness this feature has on your business, we can consider this to be implemented.

    Currently there are 7 different level privileges, but none of the people not can be customized, as requested.

    The levels of prvivilegel are:

    1 Administrator

    2. conference creation and control

    3. creation and restricted control conference

    4. creation of the Conference

    5. details of conference

    6 conference list more streaming

    7 list Conference only

    Please let me know if you need more details about each individual privilege.

    Concerning

    Cristian

  • Cisco 79xx Auto composition! = Boring!

    Hi all

    I use 6 x IP 7960 G's mode SIP phones, you use an operator of Kerio server.

    When a user connects to any of the phones, they seem to auto-dial too quickly. For example if the user types the first numbers of the phone number they wish to achieve, it will automatically dial after about one second. It's annoying because if the user dialed the number of a piece of paper, they would have to memorize the number before dialing.

    Is there some way that I can disable the automatic dialing of phones feature or at least increase the time before they go ahead and one line?

    Thank you!

    -BensTechTips

    You will need to modify the file called dialplan.xml it and download it to the phone. This file contains entries as "9.1..." that cause the phone automatically dial after a game.

    You can follow these steps:

    Information on dialing (DIAL plan. XML)

    The DIAL plan. XML file control of the corresponding phone numbers.  By default ' * ' matches anything and expires after 5 seconds.  Users should run a push "Dial" or "#" to connect if they do not want to wait 5 seconds.  For various reasons, not least including is that most phone users are not accustomed to pushing "Dial" on their desks, it may be desirable to set up a dial for your organization plan.

    If you want to use the hash (default that it immediately dials the entered number) include explicitly in the context of a model in DIALPLAN. XML

    Another example: we immediately validate 9 + 10digits or 9 + 1 + 10digits and match 5 + 2digits as receivers

    In the example above, a high tone is called by the comma.  If your attribute is left blank, the default value will be used.  Or you can specify one of the following:

    • Bellcore alert
    • Bellcore-busy
    • Bellcore-BusyVerify
    • Bellcore-CallWaiting
    • Bellcore-Confirmation
    • Bellcore-dr1
    • Bellcore-dr2
    • Bellcore-dr3
    • Bellcore-dr4
    • Bellcore-dr5
    • Bellcore-dr6
    • Bellcore-Hold
    • Bellcore-Inside
    • Bellcore - no
    • Bellcore-outside (default)
    • Permanent Bellcore
    • Bellcore-reminder
    • Bellcore-Reorder
    • Bellcore-stuttering
    • CallWaiting-2
    • CallWaiting-3
    • CallWaiting-4
    • Cisco-BeepBonk
    • Cisco-Zip
    • Cisco-Steve

    Note: This file is case-sensitive in some versions of firmware; all elements and attributes must be capitalized (except tone) or entries can be ignored.  According to Cisco, the phone will always match the expression LONGER.

    Remember messages useful rate by clicking on the stars below.
    Favor calificar todos las responses useful dando click in las estrellas mas abajo.
    ___________________________________________
    LinkedIn profile: do.linkedin.com/in/leosalcie

  • Cisco RV110w CLI

    Hello

    Is it possible to configure the router via CLI (command line interface)

    In other Cisco devices, we could always just insert a configuration through the CLI.

    However, it seems that it is only possible with the Webbrowser.

    Kind regards

    Tom

    Tom,

    N ° the RV110W can only be configured via a web browser.  There is no support for this router command line interface.

    Chris

  • SQL Query hierarchical select 2 level parent over sheet.

    Here, we use Oracle 11 g R1. Here is a sample of our Tables of the employee.

    I want you select all managers managers above them (which we call the Site Manager) and direct (that we call the Service Manager)

    Here is the example for the base table.

    SET DEFINE OFF;
    CREATE TABLE EMP_SAMPLE 
    (
      AGENT_ID VARCHAR2(100 BYTE) 
    , FULL_NAME VARCHAR2(100 BYTE) 
    , AGENT_MANAGER VARCHAR2(100 BYTE) 
    ) ;
    
    Insert into EMP_SAMPLE (AGENT_ID,FULL_NAME,AGENT_MANAGER) values ('JS001','JOHN SMITH',null);
    Insert into EMP_SAMPLE (AGENT_ID,FULL_NAME,AGENT_MANAGER) values ('AL001','ANN LEE','JS001');
    Insert into EMP_SAMPLE (AGENT_ID,FULL_NAME,AGENT_MANAGER) values ('JD001','JOHN DOE','AL001');
    Insert into EMP_SAMPLE (AGENT_ID,FULL_NAME,AGENT_MANAGER) values ('MB002','MARY BAKER','AL001');
    Insert into EMP_SAMPLE (AGENT_ID,FULL_NAME,AGENT_MANAGER) values ('HM003','HOWARD MONROE','MB002');
    Insert into EMP_SAMPLE (AGENT_ID,FULL_NAME,AGENT_MANAGER) values ('RM001','ROBYN MILLER','MB002');
    Insert into EMP_SAMPLE (AGENT_ID,FULL_NAME,AGENT_MANAGER) values ('DJ002','DAVID JONES','RM001');
    Insert into EMP_SAMPLE (AGENT_ID,FULL_NAME,AGENT_MANAGER) values ('WW001','WENDY WONG','MB002');
    Insert into EMP_SAMPLE (AGENT_ID,FULL_NAME,AGENT_MANAGER) values ('PB001','PETER RABBIT','JS001');
    Insert into EMP_SAMPLE (AGENT_ID,FULL_NAME,AGENT_MANAGER) values ('BB002','BEN BUNNY','PB001');
    Insert into EMP_SAMPLE (AGENT_ID,FULL_NAME,AGENT_MANAGER) values ('TM001','TONY MILLER','BB002');
    Insert into EMP_SAMPLE (AGENT_ID,FULL_NAME,AGENT_MANAGER) values ('PP002','PETER PARKER','RM001');
    Insert into EMP_SAMPLE (AGENT_ID,FULL_NAME,AGENT_MANAGER) values ('PP003','PEPPA PIG','PB001');
    Insert into EMP_SAMPLE (AGENT_ID,FULL_NAME,AGENT_MANAGER) values ('DB002','daniel baker','HM003');
    Insert into EMP_SAMPLE (AGENT_ID,FULL_NAME,AGENT_MANAGER) values ('TL001','Tom Lee','WW001');
    Insert into EMP_SAMPLE (AGENT_ID,FULL_NAME,AGENT_MANAGER) values ('MS001','Mary Smith',null);
    

    With the example like this data, I would like to that the result looks similar to

    Name of the Manager

    MARY BAKER - Manager of the Site

    HOWARD MONROE - Service Manager

    ROBYN MILLER - Service Manager

    WENDY WOND - Service Manager

    PETER RABBIT Site Manager

    BEN BUNNY - Service Manager

    I guess I should use the hierarchical query to achieve this. I googled to see all the solutions, I tried this under request

    SELECT agent_id, agent_manager, RPAD('.', (level-1)*2, '.') || full_name AS tree,
           level, CONNECT_BY_ROOT agent_id as root_id
           ,CONNECT_BY_ISLEAF AS is_leaf
    
    FROM EMP_SAMPLE
    START WITH agent_manager IS NULL
    CONNECT BY agent_manager = PRIOR agent_id
    ORDER SIBLINGS BY agent_id;
    

    But it seems that the level always starts from the root at the top of the page. I wonder, is it possible to identify even just the level two above the sheet.

    Here is some basic information. We are working on our oracle APEX application. One of the reports can be filtered by the Manager. The list currently shows a little all managers, regardless of what they are 1 senior as general manager, or the first line as a Service Manager Manager. Now, users want to be able to select only Service Manager and Site Manager.

    There is a DB work for updating the table Employee of LDAP. And the LDAP structure is not tidy this (we have some staff members who have no Manager, they are not even CEO). The Administrator told us that it is too busy to store it.

    We have about 20,000 employees in total including 800 East of managers.

    Thanks in advance.

    Ann

    Hi, Ann.

    Ann586341 wrote:

    Here, we use Oracle 11 g R1. Here is a sample of our Tables of the employee.

    I want you select all managers managers above them (which we call the Site Manager) and direct (that we call the Service Manager)

    Here is the example for the base table.

    1. TOGETHER TO DEFINE
    2. CREATE TABLE EMP_SAMPLE
    3. (
    4. AGENT_ID VARCHAR2 (100 BYTE)
    5. FULL_NAME VARCHAR2 (100 BYTE)
    6. AGENT_MANAGER VARCHAR2 (100 BYTE)
    7. ) ;
    8. Insert into EMP_SAMPLE (AGENT_ID, FULL_NAME, AGENT_MANAGER) values ('JS001', 'JOHN SMITH', null);
    9. Insert into EMP_SAMPLE (AGENT_ID, FULL_NAME, AGENT_MANAGER) values ('AL001', "ANN LEE", "JS001");
    10. Insert into EMP_SAMPLE (AGENT_ID, FULL_NAME, AGENT_MANAGER) values ('JD001', 'JOHN DOE', "AL001");
    11. Insert into EMP_SAMPLE (AGENT_ID, FULL_NAME, AGENT_MANAGER) values ('MB002', "MARY BAKER", "AL001");
    12. Insert into EMP_SAMPLE (AGENT_ID, FULL_NAME, AGENT_MANAGER) values ('HM003', 'HOWARD MONROE', 'MB002');
    13. Insert into EMP_SAMPLE (AGENT_ID, FULL_NAME, AGENT_MANAGER) values ('RM001", 'ROBYN MILLER', 'MB002');
    14. Insert into EMP_SAMPLE (AGENT_ID, FULL_NAME, AGENT_MANAGER) values ('DJ002', 'DAVID JONES', "RM001");
    15. Insert into EMP_SAMPLE (AGENT_ID, FULL_NAME, AGENT_MANAGER) values ('WW001', "WENDY WONG", "MB002");
    16. Insert into EMP_SAMPLE (AGENT_ID, FULL_NAME, AGENT_MANAGER) values ('PB001', 'PETER RABBIT', "JS001");
    17. Insert into EMP_SAMPLE (AGENT_ID, FULL_NAME, AGENT_MANAGER) values ('BB002', "BEN BUNNY", "PB001");
    18. Insert into EMP_SAMPLE (AGENT_ID, FULL_NAME, AGENT_MANAGER) values ('TM001', 'TONY MILLER', "BB002");
    19. Insert into EMP_SAMPLE (AGENT_ID, FULL_NAME, AGENT_MANAGER) values ('PP002","PETER PARKER","RM001");
    20. Insert into EMP_SAMPLE (AGENT_ID, FULL_NAME, AGENT_MANAGER) values ('PP003', 'PEPPA PIG', "PB001");
    21. Insert into EMP_SAMPLE (AGENT_ID, FULL_NAME, AGENT_MANAGER) values ('DB002', "daniel baker", "HM003");
    22. Insert into EMP_SAMPLE (AGENT_ID, FULL_NAME, AGENT_MANAGER) values ('TL001', "Tom Lee", "WW001");
    23. Insert into EMP_SAMPLE (AGENT_ID, FULL_NAME, AGENT_MANAGER) values ('MS001', 'Mary Smith', null);

    With the example like this data, I would like to that the result looks similar to

    Name of the Manager

    MARY BAKER - Manager of the Site

    HOWARD MONROE - Service Manager

    ROBYN MILLER - Service Manager

    WENDY WOND - Service Manager

    PETER RABBIT Site Manager

    BEN BUNNY - Service Manager

    I guess I should use the hierarchical query to achieve this. I googled to see all the solutions, I tried this under request

    1. SELECT agent_id, agent_manager, RPAD ('.) (', (level 1) * 2, '.') || full_name LIKE tree,
    2. level, agent_id CONNECT_BY_ROOT as root_id
    3. CONNECT_BY_ISLEAF AS is_leaf
    4. OF EMP_SAMPLE
    5. START WITH agent_manager IS NULL
    6. CONNECT BY PRIOR agent_id = agent_manager
    7. Brothers and SŒURS of ORDER BY agent_id;

    But it seems that the level always starts from the root at the top of the page. I wonder, is it possible to identify even just the level two above the sheet.

    Here is some basic information. We are working on our oracle APEX application. One of the reports can be filtered by the Manager. The list currently shows a little all managers, regardless of what they are 1 senior as general manager, or the first line as a Service Manager Manager. Now, users want to be able to select only Service Manager and Site Manager.

    There is a DB work for updating the table Employee of LDAP. And the LDAP structure is not tidy this (we have some staff members who have no Manager, they are not even CEO). The Administrator told us that it is too busy to store it.

    We have about 20,000 employees in total including 800 East of managers.

    Thanks in advance.

    Ann

    Here's one way:

    WITH leaves LIKE

    (

    SELECT agent_id

    Of emp_sample

    LESS

    SELECT agent_manager

    Of emp_sample

    )

    got_lvl AS

    (

    SELECT-full_name agent_id

    LEVEL AS lvl

    Of emp_sample

    START WITH agent_id IN)

    SELECT agent_id

    Sheets

    )

    CONNECTION BY agent_id = agent_manager PRIOR

    )

    SELECT full_name

    CASE

    WHEN MAX (lvl) = 3

    THEN 'Site Manager'

    ANOTHER "Service Manager"

    END AS title

    OF got_lvl

    GROUP BY full_name-, agent_id

    WITH MIN (lvl) > = 2

    AND MAX (lvl)<=>

    ORDER BY full_name

    ;

    Output:

    FULL_NAME TITLE

    -------------------- ---------------

    BEN BUNNY Service Manager

    MONROE HOWARD Service Manager

    MARY BAKER Site Manager

    PETER RABBIT Site Manager

    ROBYN MILLER Service Manager

    WENDY WONG Service Manager

    Thanks for posting the CREATE TABLE and INSERT statements; It's very useful!

    LEVEL does not always begin with the root; It starts with the lines that meet the condition to START WITH.  If you have a START WITH condition that only roots meet (as in the query you posted) then, Yes, LEVEL will start with the roots.  If you have a condition START WITH answering the criteria only the leaves (as in the query I posted), then LEVEL will start with the leaves.

    I guess just some of your needs.  If seems that a 'Site Manager' is the grandparent of a leaf, but "John Smith" (which is the grandmother of "John Doe", a sheet) is not considered to be a 'Site Manager'.  Similarly, it seems that a 'Service Manager' is the parent (but not the grand-parent) of the leaf, but "Ann Lee" (the mother of "John Doe") is not considered to be a 'Service Manager' for a reason any.

    I guess that full_name is unique.  If full_name is not unique, but agent_id is, then you will need a comment a few line above ends.  (I guess that agent_id is unique and not NULL).

  • Vs role directly privilege on the creation of the procedure

    I gave an our develpers create them all procedure/run procedures privleges and also granted him a role that has choose, update privileges, but always as insufficient privileges error when attempting to create a procedure.

    On the other hand, when I grant the same privilege directly to the user, it is able to create the procedure without error.

    What I'm doing wrong - I'd like only to all privilege granted through roles.

    Your input please.

    acquired through ROLE privileges do NOT apply within the named PL/SQL procedures

  • Cannot create high-level arrangement positions in muse 2015.1

    Weach I create a shape custom as a rectangle, square or menu on nav on the master page and select 'organize-face' when I go to see on my other pages, forms and nav menu always scrolls behind all other elements on this page. I guess that if create you something on a master page and have high level it should always show above all other elements, but it's not. Why? In addition the possibility of effects of scrolling is disable when you use a fluid response. Which causes other problems.

    Go to your master page, open the "Layers" Panel, create one new layer above all the others and drag all the elements 'top' on it. Be aware that the layers are working throughout the site, not to the scale of the page!

    Scroll effects: in sensitive pages does not effect of scrolling for now! At the same time, it should be clear to all users of Muse, because this is stated in the release notes, in the help files, and here, in this forum, we have tons of detachment about '"scrolling effects'. Simple use of the find command!

Maybe you are looking for

  • Text of the replies on Apple Watch does not match

    Hello I know how to set the default text above (App iPhone-Watch-ma watch-Message-answers by default), I updated the list already and only kept 3 responses I used most. But when I tried to answer a message by clicking 'Reply' on my Apple Watch (see I

  • No display of content pages

    When you try to browse to a Web site such as hotmail or google, there is no indication on the page.

  • Compac cq5300f: no video via usb adapter

    Unable to get the video of this ada [ter to my Exclation point error screen in Manager. device with the following equipment. Need help drivers USB\VID_1D5C & PID_2000 & REV_0200 & MI_00 USB\VID_1D5C & PID_2000 & MI_00

  • down free space after doing a windows update!

    OK, I don't know what's going on, but after I installed the updates of windows on my computer, I lost 3 GB of space free all together! (at first it was only 1 to 2 GB, and I brushed it off because I think it's the space updates have taken place, but

  • Do not open programs after installing Windows update operating system Windows Vista

    Original title: MS Office programs do not open after installation of Windows update to Windows Vista operating system After having decided to install the Windows Update my computer told me was available all my software as my programs MS Offfice is no