FSCA - recording in privileged Mode

I configured a single client, the remote agent and ACSE. I am able to authenticate on the device via AD network. He invites me credentials, then I'm in user mode. I then issue the enable command to enter privileged mode. He invites then authenticate again. My question is how to configure ACS to make me enter directly into privileged mode, once I've authenticated? I do not want to be first in user mode then need to authenticate again to enter privileged mode. Any help would be greatly appreciated. Thank you!

Bring to users/groups at level 15

1. go to the user or to set up groups of ACS

2 down until "settings GANYMEDE +".

3. check "Shell (Exec).

4 check 'Privilege level' and enter '15' in the adjacent field

Also make sure that we have enabled exec authorization.

AAA authorization exec default group Ganymede + authenticated if

Kind regards

~ JG

Note the useful messages

Tags: Cisco Security

Similar Questions

  • No command ' configure terminal ' privilege mode

    Hi guys,.

    I'm seting up a 1250G AP Cisco via port console for the first time, something very strange, I can not find command "configure terminal" under privileged mode. Does anyone know why? Thanks in advance.

    AP0026.994C.e39c #sh privilege
    Current privilege level is 15
    AP0026.994C.e39c #?
    Exec commands:
    CD change current directory
    Disable the Reset functions
    Manage the clock system clock
    Crypto encryption related orders.
    debug debugging features (see also "undebug")
    Delete Deletes a file
    List of files on a file system dir
    disable the Turn off privileged commands
    dot1x IEEE 802. 1 X commands Exec
    turn on the turn on privileged commands
    exit from the EXEC
    fsck Fsck a file system
    help Description of the interactive help system
    led functions LED
    locking of the terminal
    Connection connect you as a particular user
    Logout Exit from the EXEC
    OfficeExtend AP lwapconfig configurations
    LWAPP lwapp exec commands
    mkdir create new directory
    monitor various system events monitoring
    more display the contents of a file
    Name the connection-name an existing network connection
    No function to disable debugging
    Send echo ping messages
    Working Directory current pwd display
    RADIUS radius exec orders
    Release to release a resource
    Stop reload and perform a restart cold
    Rename rename a file
    renew renew a resource
    rmdir remove the existing directory
    rsh to execute a remote command
    Register early to save the battery raise_interrupt_level
    Send a message to other TTY lines
    setting system Set Set (no config)
    Show Show running system information
    SSH open a secure shell client connection
    SYSTAT display information about the terminal lines
    terminal Set terminal line parameters
    Test Test subsystems, memory and interfaces
    Traceroute-Trace route to destination
    undebug disable debugging functions (see also 'debug')
    software upgrade upgrade
    Check check a file
    where the list of active connections

    AP0026.994C.e39c ter #config
    ^
    Invalid entry % detected at ' ^' marker.

    AP0026.994C.e39c #.

    AP0026.994C.e39c #sh worm
    Software Cisco IOS, C1250 Software (C1250-K9W8-M), Version 12.4 JA (21 a), RELEASE SOFTWARE (fc1)
    Technical support: http://www.cisco.com/techsupport
    Copyright (c) 1986-2009 by Cisco Systems, Inc.
    Updated Tuesday 8 June 09 16:49 by prod_rel_team

    Hello

    The reason why you do not have the config t prompt is because you have a LWAPP access point. LWAPP ap do not have a config t, as the access point's configuration of the WLC.

    If you find the useful rate please post... Thank you!

  • How to disable the old, disconnected records in offline mode in Win7?

    I installed Windows 7 (64-bit clean) in my office. Prior to that, I also upgraded my laptop, which has a connection with a shared folder on my desktop offline. Now, after update from my office, there is always a file offline (inactive/gray/disconnected) in the sync partnership, pointing to the old shared folder on my desktop that no longer exists! I can't go back and delete since this partition on my desktop disappeared.

    Is there a way to remove this connection from my laptop?

    Hello

    Welcome to the Microsoft Answers Forum!

    I suggest that allows you to delete records of online Office to follow the steps below:

    Method 1:

    The offline files cache is a folder structure in the folder % SystemRoot%\CSC, which is hidden by default. The record of the CSC and all files and subfolders it contains, should not be modified directly; doing so may result in loss of data and a complete disassembly of the offline files feature.

    1. in Folder Options, on the offline files tab, press CTRL + SHIFT, and then click delete files. The following message appears:

    Cache files offline on the local computer will be reset. Any changes that have not been synchronized with computers on the network will be lost. Any files or folders made available offline will be more available in offline mode. A restart of the computer is required.

    You want to re - initialize the cache?

    2. click Yes to restart the computer two times.

    If the problem persists, then I suggest you to change the registry settings and check if that helps you. But before you change or change the registry. I would say lets you create a restore point, and then continue with the steps.

    To create a restore point follow the steps mentioned below.

    1. open system by clicking the Start button, right click on computer and then click Properties.

    2. in the left pane, click system protection. If you are prompted for an administrator password or a confirmation, type the password or provide confirmation.

    3. click on the tab System Protection and then click on create.

    4. in the System Protection dialog box, type a description, and then click on create.

    For more information, please see the link below.

    http://Windows.Microsoft.com/en-us/Windows7/create-a-restore-point

    Method 2

    Use the registry editor

    If you cannot access the offline files tab, use this method to reset the cache offline files (CSC) on the system by editing the registry. Also use this method to reset the cache on the side of client/database files offline on multiple systems. Add the following registry subkey:

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\NetCache
    Key name: FormatDatabase
    Key type: DWORD
    Key Value: 1

    Note The actual value of the registry key is ignored. This registry change requires a restart. When the computer restarts, the shell will reset the CSC cache and then delete the registry key if the registry entry exists.

    Warning All cache files are deleted and unsynchronized data is lost.

    Use Reg.exe

    You can also automate the process of setting this registry value using the Reg.exe command line editor. To do this, type the following command in the window of Reg.exe:

    REG. EXE. REG ADD "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\NetCache' FormatDatabase /t REG_DWORD /d 1 f v

    For more information, please see an article mentioned below:

    http://support.Microsoft.com/kb/230738

    WARNING:

    Change the settings of the REGISTRY can cause serious problems that may prevent your computer from starting properly. Microsoft cannot guarantee that problems resulting from the REGISTRY settings configuration can be solved. Changes to these settings are at your own risk.

    I hope this information helps. Please get back to us if you have any other questions on this subject.

    Thanks and greetings
    Mir - Microsoft Answers Support Engineer
    Visit our http://social.answers.microsoft.com/Forums/en-US/answersfeedback/threads

  • AAA authentication and privilege-mode

    I want to configure authentication aaa with accounts of local user on the switch. The idea is to come directly into the "privilege" without the enable command mode.

    I have configured the following commands:

    AAA new-model

    AAA authentication login default local

    What other commands (permission) are necessary to obtain the command of privilege?

    Thank you

    Pascal

    Dear Sir

    For the console you must issue to order more.

    There is a hidden within IOS command you will need to apply: "authorization aaa console.

    Who should fix it

    Kind regards

    ~ JG

    Note the useful messages

  • 30 and 60 frames per second video recording

    Hi guys I have a few questions.

    (1) what is the best to use when recording video on sony xperia z3 - 30 or 60 FPS? Are there recommendations for when you use the first and the second as the sunny days, etc.?

    (2) when I save on manual mode, I can choose between 30 a 60 fps but on AUTO mode, I can't so my question is: what FPS auto mode uses while video recording? 30 or 60? Can I change somehow?

    (3) during recording, I can take quick pictures, but resolutions are? Can I check it out somehow? As for example is the mode auto or manual 8mpix or less?

    Thanks for help.

    60 FPS will make the video more fluid and better during the seizure of the objects moving quickly. However, a higher FPS will be expand the video file and if you plan to play the video on another device this device must also support playback of 60 fps.

    The auto mode uses 30 frames per seconds and there is no setting to change this.

    If you take a picture during video recording in auto mode, it will have the same resolution as the video, 1920 x 1080. You can see the resolution of an image if you open it in Album and press [menu]-> Details.

  • MOD does not play on the big screen in Windows media player.

    I have a JVC's Everio camcorder and record in the MOD file.  The file was on the big screen but when I copy it to my PC and play in Windows Media Player, it shrink.  How can I solve this problem?  It's good that if I play the file in the software provided with the package.

    Help, please. Thank you.

    Hello Qooqoo81,

    Thank you for visiting the Microsoft answers Site.

    In addition to the response of aziz, you can use your favorite search engine to search for a program that converts the mod file to a file type that supports Windows Media Player.

    In addition, you can view the below link provided by the manufacturer of the device that includes additional information to play the video files on your PC.

    The Everio/Standard definition

    I hope this information is useful.

    Thank you

    Mary
    Microsoft Answers Support Engineer
    Visit our Microsoft answers feedback Forum and let us know what you think.

  • Dell N3024 - configuration of a user with a subset of privileges

    I'm new to Dell switches.   I created a user name and assigned a profile admin to give the user a subset of the commands that the user can perform.

    I would like to configure the switch so that when the user logs on, they are automatically in enable mode.   I think that this feature is configured in the configuration of the line of the console, telnet, and ssh.  While I can find documents that contain the defined controls, I have not found a document that includes a number of examples or explains the different options.

    Thank you.

    Dean

    Hi Dean,

    You can use SSH public key authentication to create a key that will allow you to log in as your user without password from the devices that store the private SSH key and drop directly into privileged mode. Page 218 ftp://ftp.dell.com/Manuals/all-products/esuprt_ser_stor_net/esuprt_networking/esuprt_net_fxd_prt_swtchs/networking-n3000-series_Administrator%20Guide3_en-us.pdf

    You could also set up a server radius with your admin users and provide enable access of the connection by using the command Activate authentication raden

  • ULaw and alaw record and play G711

    I want to be able to capture and play directly to the a - law and u - law format.  I have read several posts on how to put the reader (capture in my case) in amr and pcm mode.

    Capture of AMR and PCM is not a problem, but the correct string of capture to capture the u - law data is unknown to me.

    for the record:

    capture://audio? Encoding = PCM works, also tried something like:

    capture://audio? Encoding = PCMU (does not), also tried to replace with pcmu, ulaw, audio/x-ulaw

    capture://audio? Encoding = AMR (works)

    When I exit the capture I get supported types:

    Device supports capture Type: audio / amr
    Device supports capture Type: audio / basic
    Device supports capture Type: audio / x - gsm
    Device supports capture Type: image / jpeg

    To play, I think that I should put the x - wav player and provide good wav header, will try later, but my first concern registers directly as G711.

    I'm running on Simulator and device (BB Torch v6) which should be able to support the u-law/a-law.

    someone at - there more information on this? It is not possible or should I put the recorder in pcm mode and convert my data on the fly?

    Hi James!

    Registration is only linear PCM.  The reading can be linear, G711 uLaw and alaw for PCM.  On a BlackBerry audio/basic = audio/pcm.

    If you are interested, GSM is GSM6.10 of recording and playback, AMR's locker AMR - NB 12.2 Kb/s (unless you specify voipMode = true in your locator, but I will not go into these details, you can search the forums if you need more information on this) and any mode of AMR - NB valid for playback (only three units I know can also playback AMR - WB and AMR - WB +).

    Finally, to save some time there is code attached to this question (if you can connect, related to this thread) who has code to generate headers wav on the Blackberry platform for you.

  • Create a privilege level which only allows access to view orders

    Hello

    I would create a level of privilege that would only give access to commands show for some users. What would be the best way to do this?

    I should use the privilege mode level level control for all available commands, or is there a better way to do this?

    Besides, could we manage this level of privilege to a Radius server.

    Thanks for your help

    Stéphane

    Well, I think that the best way to achieve this is to use GANYMEDE with command authorization feature.

    On the RADIUS server configuration (only for the command, read access only)

    http://www.Cisco.com/en/us/products/sw/secursw/ps2086/products_configuration_example09186a00808d9138.shtml#scenario2

    These commands are required on an IOS router or switch to implement permission to order via an ACS server:

    AAA new-model

    AAA authorization config-commands

    AAA authorization commands 0 default group Ganymede + local

    AAA authorization commands 1 default group Ganymede + local

    AAA authorization commands 15 default group Ganymede + local

    GANYMEDE-server host 10.1.1.1

    RADIUS-server key cisco123

    These commands are required on ASA/PIX/FWSM to implement permission to order via an ACS server:

    authserver Protocol Ganymede + AAA-server

    authserver AAA-server 10.1.1.1

    AAA authorization command authserver

    However, if you strictly want to use radius server then please try the below list attribute for a single user or group.

    Service-Type = NAS Prompt

    http://www.ietf.org/assignments/RADIUS-types/RADIUS-types.XML#RADIUS-types-4

    This may not work for ASSISTANT Deputy Ministers.

    HTH

    Kind regards

    Jousset

    The rate of useful messages-

  • ACS 5.1 - command line filters does not not in Config Mode

    Hello

    I am trying to set up filters to deny command line sniffer commands being entered. I have set up a command set and applied to an authorization policy. The command filter works great for commands in privileged mode. However, the filter does not work for any order that is entered in configuration mode.

    I have a set of commands that will deny for a test installation:

    display the clock

    terminal length

    display monitor

    duration of the distance

    the monitor session

    The first three commands are entered from the initial mode of privilege and they are omitted by the AEC. The last two commands can be entered in config mode and the ACS does not stop their entry.

    I have attached two screenshots that show configuration commands on GBA game and a Terminal session which commands are filtered and which are rented by the intermediary.

    Has anyone encountered this problem? Is there something else I should be adding to the command Set? Is this a bug?

    There is a bug on the Cisco site that relates to the command filters:

    http://Tools.Cisco.com/support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&bugId=CSCtf08567

    I don't know if this bug applies to this question because there is so little information on this subject. In addition, if it does not I don't understand workaround to apply it to this situation.

    Any advice would be greatly appreciated. -(ACS Version 5.1.0.44.2)

    Dave was soon

    You have authorization for the configuration on the router mode?

    If this isn't the case, add:

    AAA authorization config-commands

  • Problem recording movi to VCSe (VCSC work)

    Hello

    for some reason any Jabber client video are not able to log on to VCSe. If they are in the office and connect to the VCSC his work.

    Deployment:

    VCS: 7.2.2

    TMSPE: 14.2

    VCSC is joined to the domain, so people should be able to login with LDAP credentials. Since a few days we have changed an OU for users in AD. I resynced the TMS users. In VCSC my thought is that I have nothing to do, right? I do not know its function, change OR cause the customer movi is not som uch in use.

    I started track of debugging on VCSe registration go external with movi (IP addresses and names have been changed):

    SIPMSG:

    | SIP SUBSCRIBE:@domain.comSIP/2.0

    Via: SIP/2.0/TLS 192.168.100.10:3157; branch = z9hG4bK06fbfdf1d928fdea44551eb01444f279.1; received = 78.51.4.182; = 45938 rport

    Call ID: [email protected]/ * /.

    CSeq: 201 SUBSCRIBE

    Contact: <> @192.168.100.10:3157; transport = tls >

    From: <> @domain.com >; tag = ff9e0e9142437b34

    To: <> [email protected] / * />

    Max-Forwards: 70

    Directions:

    User-Agent: TANDBERG/774 (4.5.7.16762 PCS) - Windows

    Expires: 300

    Event: ua-profile;model=movi;vendor=tandberg.com;profile-type=user;version=4.5.7.16762;clientid="S-1-5-21-176747291-1711663684-1688638919";connectivity=1

    Accept: application/pidf + xml

    Content-Length: 0

    SIPMSG:

    | SIP/2.0 404 not found

    Via: SIP/2.0/TLS 192.168.100.10:3157; branch = z9hG4bK06fbfdf1d928fdea44551eb01444f279.1; received = 78.51.4.182; rport = 45938; DefaultZone = ingress-box

    Call ID: [email protected]/ * /.

    CSeq: 201 SUBSCRIBE

    From: <> @domain.com >; tag = ff9e0e9142437b34

    To: <> [email protected] / * />; tag = a9bdf7d526c0cb56

    Server: TANDBERG/4120 (X7.2.2)

    WARNING: 79.34.34.123:5061 399 'political response '.

    Content-Length: 0

    So we have a 404 not found error, but why and what is not found, the user who tried to connect? For some reason, it seems that demand is not going through VCSe VCSC, it is my feeling?

    Auth area is as follows:

    VCSe:

    DZ: do not check the credentials

    TZ: do not check the credentials, accept records submitted by proxy: refuse

    DSZ: do not check the credentials, registration: refuse

    VCSC:

    DZ: verify the credentials

    TZ: verify the credentials, accept records sent by proxy: enable

    DSZ: verify the credentials, registration: enable

    I also implemented a CPL on VCSe (not on the VCSC) but I have disabled also the policy tried it unsuccessfully with so this should not be the problem.

    I tested a few other constelattion without success. :-( Maybe someone has an idea of what I can test. What is a firewall issue?

    Concerning

    Thorsten

    Hello

    Could check you if the 'Record SIP proxy Mode' setting is on "Known Proxy" only on Hwy VCS? You will find this SIP configuration setting.

    This is a required parameter for allow VCSe work as a proxy SIP for registration. It is not enough to define 'Recording proxy Acept' control VCS. In general, you should have this record transmitted by proxy configuration:

    If you don't want to use the proxy record but jabbers on the internet for you sign up directly for VCSe, you must disable the Save proxy functionality and create the SIP domain in VCS Expressway. It would be something like this:

    Try this.

    Paulo Souza

    Please note the answers and mark it as "answered" as appropriate.

  • ACS - configure the authorization of shell commands to work under the configuration mode (conf t)

    Hello world

    I'm trying to set up a shell commnds set orders (including t conf mode) will be allowed, with the exception of administrative commands, such as writing, copy, admin, format etc.

    He worked for the commands in privileged mode (most) (such as writing and copy), but did not order t conf mode. It is important to prevent users to perform the ' write for the "and" copy run start "commands, for example.

    Here is the entry in the series of command shell (Partial_access) approval:

    Unmatched orders: permit

    List of commands:

    Admin

    copy

    delete

    do

    format

    To write

    (Relevant) group settings:

    V - shell (exec)

    Privilege level of V - 15

    Shell command authorization set

    Assign permission to command Shell Set to any device network - Partial_access (group name)

    I use CiscoSecure ACS version 4.2 (0)

    Thank you

    Lior

    Hi Lior,

    Please make sure you typed in the AAA client, the following commands: -.

    AAA authorization config-commands

    Thanks for posting your AAA client configuration via "run sh |" I have aaa "and if possible your configuration of privilege"

    HTH

  • Device driver Sony ICD-SX25 recorder Win 7 (64)

    Driver works perfectly on VISTA computer (32)

    I copied the driver Agent driver from Vista to WINDOWS 7 and bought files and asked to Sony.   .  .  no luck

    Is there something available?

    E-mail address is removed from the privacy *.

    Hello

    Thanks for posting in the Microsoft community! You have reached the right forum for your question.

    I propose to download and inatall drivers for the Sony ICD-SX25 Recorder in compatibility mode for Windows 7 from the following link:

    Recorder of CIM
    http://eSupport.Sony.com/us/p/model-home.pl?MDL=ICDSX25&template_id=1&Region_ID=1&tab=download#/downloadTab

    Make older programs in this version of Windows
    http://Windows.Microsoft.com/en-us/Windows7/make-older-programs-run-in-this-version-of-Windows

    Hope this information is helpful and let us know if you need more assistance. We will be happy to help.

  • Access to the private during authentication mode

    When I connect to a Cisco device, I'm prompeted enter name of user and password. Once authenticated, I need to enter the 'enable' command, then my password again in order to have access to privileged mode. I want to be able to go directly to the priv mode.

    My AAA configuration looks like this:

    AAA authentication login default group Ganymede + local

    AAA authentication login ciscoadmins group Ganymede + local

    the AAA authentication enable default group Ganymede +.

    AAA authorization config-commands

    AAA authorization exec ciscoadmins group Ganymede + local authenticated by FIS

    AAA authorization commands 1 default group Ganymede + local

    AAA authorization commands 15 ciscoadmins group Ganymede + local

    AAA authorization network default group Ganymede +.

    the Group ciscoadmins of network authorization Ganymede AAA +.

    On my ACS SE (ver. 4.1.4.13), I the user and group configured setting the same thing for the GANYMEDE section + with SHELL (exec) checked and controlled level PRIV and the value 15.

    I can get this working with RADIUS but failed with GANYMEDE.

    Does anyone have a solution for this?

    Thank you

    Keith

    Keith

    I believe that the question involves this line of the config:

    AAA authorization exec ciscoadmins group Ganymede + local authenticated by FIS

    It creates a list of method named for permission. IOS wants to see this list of method specified on your lines (or he wants to use the list of default method). I suggest that you include this line under the vty lines:

    authorization exec ciscoadmins

    or use this line in the section of the aaa:

    AAA authorization exec default group Ganymede + local authenticated by FIS

    HTH

    Rick

  • Configure the read-access via user-defined privilege level

    Hello everyone,

    I m looking for the best configuration to restrict a user read-only. The restriction must be configured through CLI not GANYMEDE.

    Material: 3750 (probably not interesting for that matter)

    More old IOS: 12.2 (53) SE1

    The user should be allowed to:

    • See the running configuration
    • trigger all sorts of orders-show
    • Ping and traceroute of the device

    The user should not be allowed to:

    • Download/delete/rename files on the flash memory
    • Enter the level 15 (not sure if I can avoid it)
    • all orders despite those level 1 and those specified above

    Can someone help me with this?

    Thanks in advance!

    I have won´t forgotten messages useful rates

    Hi Tobias,.

    You can

    set up multiple levels of privilege on a switch as explained below.

    By default, the Cisco IOS Software has two modes of password security: user EXEC and

    Privileged EXEC. You can configure up to 16 levels of commands for each mode.

    By configuring multiple passwords, you can allow different sets of users to have access to

    specified commands.

    For example, if you want many users to have access to the clear line command, you can

    He attributed a level 2 security and distribute the level 2 password fairly widely. But if you

    want more restricted access to the command configure, you can assign security to level 3

    and distribute the password to a more restricted group of users.

    Definition of the level of privilege for a command

    Beginning in privileged EXEC mode, follow these steps to set the privilege level for a

    control mode:

    Purpose of command

    Step 1

    Configure the terminal

    Enter global configuration mode.

    Step 2

    level privilege mode level control

    Set the level of privilege for a command.

    For mode, enter set for the global configuration mode, exec to EXEC mode, interface

    for the interface configuration mode, or the line for line configuration mode.

    For level, the range is from 0 to 15. Level 1 is normal user EXEC mode privileges.

    Level 15 is the level of access allowed by the enable password.

    For command, enter the command that you want to restrict access.

    Step 3

    activate the password level

    Specify the password to enable for the privilege level.

    . For level, the range is from 0 to 15. Level 1 is normal user EXEC mode privileges.

    Password, specify a string from 1 to 25 alphanumeric characters. The string cannot

    start with a number, is case sensitive and allows spaces but ignores leading spaces. By

    by default, no password is defined.

    Step 4

    end

    Return to privileged mode.

    Step 5

    Show running-config

    or

    Show privilege

    Check your entries.

    The first command shows the level of the password configuration and access. The second command

    Displays the privilege level configuration.

    Step 6

    copy running-config startup-config

    (Optional) Save your entries in the configuration file.

    When you set a command to a privilege level, all commands whose syntax is a subset of this

    control can also be programmed at this level. For example, if you set the show ip traffic command

    level 15 show commands and show ip commands are automatically set to privilege level

    15 unless you set them individually at different levels.

    To return to the privilege by default for a given command, use the no privilege mode level

    control of level global configuration command.

    This example shows how to set the command configures to focus on level 14 and set

    SecretPswd14 as the password users must enter to use 14 level controls:

    Switch (config) # level 14 exec privileges set up

    Switch (config) # enable password 14 SecretPswd14 level

    You can also change the default privilege for every user level.

    Change the level of privilege by default for lines beginning in privileged EXEC mode follow these steps to change the default privilege for a line level: complete order

    Step 1 Configure terminal enter global configuration mode.

    Step 2 line vty select the virtual terminal line to restrict access.

    Step 3 privilege level change the default privilege for the line level.

    For level, the range is from 0 to 15. Level 1 is normal user EXEC mode

    privileges. Level 15 is the level of access allowed by the enable password.

    End of step 4 back in privileged mode.

    Step 5 show running-config or show privilege

    Check your entries. The first command shows the level of the password configuration and access.

    The second command shows the privilege level configuration.

    Step 6 copy running-config startup-config (optional) save your entries in the configuration file.

    Users can replace the privilege level that you set by using the privilege level line configuration command

    you connect to the line and enabling a different privilege level.

    They can lower the privilege level by using the disable command.

    If users know the password to a higher privilege level, they can use this password to enable the higher privilege level. You can specify a privilege for your console line level to restrict the use of the line or high-level.

    To restore the default line privilege level, use the no privilege level line configuration command. Also I send you a document for your reference.

    http://www.Cisco.com/univercd/CC/TD/doc/product/LAN/cat3750/12225see/SCG/swauthen.htm #wp1154063

    HTH

    Concerning

    Reem

Maybe you are looking for

  • 15 mid-2010 "MACBOOKPRO renovation tips

    I got a MacBookPro brand new and don't know what to do with my old. I guess I could sell it if my drug dealer wants to be paid earlier than expected, but for now, I am now. Love having two monitors on my desk makes feel me important. In addition, I h

  • How can I change the name of my wireless network?

    I use OS X 10.11.4 and utility Airport 6.3.6. I would change the name of my network and I don't know how or where to do this. And once this is done, have what I would do with my extreme and Express to continue them to work?   Any help would be apprec

  • DeskJet d2680: printer itself settles not on computer

    I installed everything correctly the first time and seemed to have a test normal printing. However, when I tried to print a text document there skip lines. Help suggested I remove the driver and reinstall. I uninstalled all the software and uninstall

  • Safe to buy adapters CA / CC of Ebay for Satellite A30?

    Hello world I have a laptop Toshiba Satellite. It's the A30 to be exact. My power adapter fried today. I'm not surprised because I had problems with it for a long time. (eg. computer laptop do not recognize the card until I have to move)Today was the

  • can I print from my blackberry torch?

    I can't print from my flashlight? Help, please