How can you deny the command enable.

On our current setup, we have this...

AAA new-model

AAA authentication login default group Ganymede + local

AAA authorization config-commands

AAA authorization exec default group Ganymede + local

AAA authorization commands 15 default group Ganymede + authenticated if

In Ganymede, we have each user in a group. Each group requires a set of permission controls. In the entire order, we refused enable, but we are still able to run to turn them on. Other commands that we test work fine. Any suggestions? Are able to deny we allow at all?

Thank you

Andrew

Hi André,.

Add the following commands on the device:

AAA authorization commands 0 default group Ganymede + authenticated if

AAA authorization commands 1 default group Ganymede + authenticated if

Rgds

somishra

Tags: Cisco Security

Similar Questions

Maybe you are looking for