Create a privilege level that only allows access to show commands

Hi,
I would like to create a privilege level that would only give access to the show commands for certain users. What would be the best way to do this?
Would I have to use the privilege mode level level command for every available show command or is there a more efficient way of doing this?
In addition, could we manage such a privilege level from a Radius Server.
Thanks for your help
Stéphane

Well, I think the best way to achive this is to use TACACS with command authorization feature.
Configuration on the tacacs server ( only for show commands, read only access)
http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_configuration_example09186a00808d9138.shtml#scenario2
These commands are required on an IOS router or switch in order to implement command authorization through an ACS server:
    aaa new-model
    aaa authorization config-commands
    aaa authorization commands 0 default  group tacacs+ local
    aaa authorization commands 1 default  group tacacs+ local
    aaa authorization commands 15 default group tacacs+ local
     tacacs-server host 10.1.1.1
     tacacs-server key cisco123
These commands are required on ASA/PIX/FWSM in order to implement command authorization through an ACS server:
    aaa-server authserver protocol tacacs+
    aaa-server authserver host 10.1.1.1
    aaa authorization command authserver
However, if you strictly want to use radius server then please try the below listed attribute for a single user or group.
Service-Type = NAS Prompt
http://www.ietf.org/assignments/radius-types/radius-types.xml#radius-types-4
This might not work for ASDM.
HTH
Regards,
Jatin
Do rate helpful posts-

Similar Messages

  • Is there a way to make a second passcode that only allows access to making calls?

    I would like to be able to have my regular passcode for full access to everything on my phone but have a second passcode I can enter for when someone asks to borrow my phone to make a call, and this would only give them access to making a call but no access to my calendar, emails, photos, apps, etc.
    Does anyone know if this is possible to do through settings or even if there is an app for this?
    Thanks

    No, this isn't possible and there isn't an app that would be able to do this.

  • Is there a way to set firefox so it only allows access to only one website / (ip address).

    Is there a way to set firefox so it only allows access to only one website / (ip address) and block traffic from everything else (the entire web) other than the one site I want to allow? The site I want to allow is a corporate web application that will only work in firefox. We as a business run a windows server and all client desktops run Internet Explorer with security setting controlled by group policy. We have already locked down the security setting in firefox so users can’t bypass the proxy server settings.

    I have a proxy server set up (Symantec.cloud). Fire fox is “locked” so users would find it difficult to bypass it.
    I have a file: '''local-settings.js '''
    This is located in: C:\Program Files (x86)\Mozilla Firefox\defaults\pref
    The content of this file is:
    ''pref("general.config.obscure_value", 0); // only needed if you do not want to obscure the content with ROT-13
    pref("general.config.filename", "mozilla.cfg");''
    I also have the file: called: '''mozilla.cfg'''
    This is located: C:\Program Files (x86)\Mozilla Firefox
    The contents of this file is:
    lockPref("network.proxy.type", 5);
    All that is working fine, users can’t easily change the connection settings.
    So all that is good and works…
    What I would also like to do is set firefox so access is limited to 1 IP address and nothing else is allowed (the whole internet is blocked, except this one IP address).
    You suggest using a PAC file - I was unsure how I would use a PAC file, (I have never written one) and do not understand how I would implement one? Please help.

  • I have an airport extreme and express, if I use the extreme as a base station connected to my old router can I use the express to extend the signal while also creating a new network that only I can use?

    I have an airport extreme and express, if I use the extreme as a base station connected to my old router can I use the express to extend the signal while also creating a new network that only I can use? Essentially having two wifi connection off the same network? If so how do I set this up?

    Extending using a wireless connection always results in a performance compromise.
    If the Express is going to extend using a wireless connection, then the Express will need to be located about half way between the AirPort Extreme and the general area where you need more wireless coverage. The more that you have line-of-sight between the Extreme and Express, the better the network will operate.
    Remember......the Express can only "extend" the quality and signal speed that it receives, so it needs to be located where it can get a very good signal from the Extreme. Although Apple cleverly uses the term "extend", a more accurate term for the Express would be "repeater".
    If the Express will extend by connecting to the Extreme using a permanent, wired Ethernet cable connection......highly recommended for best performance.....then the Express can be located exactly where you need more wireless coverage. There is no signal loss at all through the Ethernet cable, so the Express gets a full speed signal no matter where it might be located.
    Post back to let us know which way to you want to go.

  • I need a script that only allows numerics to be keyed in

    I need a script that only allows numerics to be keyed in.

    Thank you so very much.  You kindness is appreciated.
    K Wiley
    On Thu, Oct 17, 2013 at 3:46 AM, Gilad D (try67)

  • How to create a smart folder that only selects from a specific directory?

    I am trying to create a smart folder that lists all my iPhoto original content in the last few months. I want this so that my wife can connect into the smart folder over the LAN when copying specific photos to her PC.
    I am have trouble working out how to restrict the search to only those files that exists in the iPhoto directory. When I look at info for a photo is states "Where: /Users/Shared/iPhoto Library/iPhoto Library/Data/2009/....etc etc".
    However if I add an filter for "Where from" begins with "/Users/Shared/... etc etc" it returns nothing. Is there a way to do this?

    Find the iPhoto library file.
    Right click -> Show package contents.
    Double click the Originals folder.
    Type anything in the Search box at the top of the Finder window.
    In the top of the Finder window, click "Originals".
    Click the + (plus) sign next to Save.
    Select Kind is Image.
    Click the + (plus) sign again.
    Select *Created date* is *within last 3 months* (or whatever you want).
    Go to the search box and delete what you typed. Don't hit the X to delete the search text.
    Now save the smart search.
    This is saved in ~\Library\Saved searches. Copy or move it to the desktop where your wife can get access to it.

  • I recently bought Photoshop Elements 12 and the system is saying that the Redemption Code is no longer active.  How do I get a new code that will allow access to the software ?

    I recently bought Photoshop Elements 12 and the system is telling me that the Redemption Code is no longer active.
    How do I get a new Code number that will allow met to access the software?

    you need your serial number.  you used your redemption number to redeem your serial number.
    if you don't know your serial number, check the account used to purchase or register your pse 12, Adobe ID

  • Can I create a template and that will allow me to add a region when i use i

    Is it possible to create a template that will allow me to add a region when i use the template on my pages? I have a region that allows the user to create content in the region, but now i would like to have another region next to it.
    thanks
    Angie

    You cannot add regions on a page that uses a portal template.

  • I ordered the CS5.5 Design Premium, and InDesign will not install because, although my computer is 64 bit capable, it is currently set at 32 bit. Is there a way I can create a custom installation that will allow me to install products that require a 64 bi

    Any guidance would be greatly appreciated. I am financially impaired (nice way of saying "poor"), and cannot afford to purchase any more upgrades for my system or another version of InDesign.
    I am sure there must be settings that will allow me to install the program, possibly with limited functionality due to this issue.  I am disabled and cannot work outside of my home. I was hoping to make a small income freelancing with this package, and InDesign is a crucial part of the package.
    Thank you very much for any assistance.
    Kara Bismarck
    <email removed-kglad>

    So I would have to uninstall Windows 7 Home Premium and reinstall it as 64-bit?  I'm trying to do this without having to reformat my computer.  Is there a way I could create a 64-bit partition on my secondary hard drive without reinstalling the OS?

  • How can I creat a control button that will allow the vi to run?

    Instead of pressing the run button, I want to creat my own run button that will allow my vi to run.
    Any idea?
    Thank you

    First you need to set the VI to Run When Opened (VI Properties>Execution). Then you create a front panel Boolean. On the diagram what you need to do is have some sort of idle state where nothing is done until the Boolean is pressed. It could be a separate while loop that doesn't exit until the Boolean is pressed, an Event Structure, or as part of a state machine. Look at the shippings examples Queued Message Handler, New Event Handler, Using Buttons for Options to name just a few.

  • How can I create a submit button that only saves?

    Our end users will save the completed form and later upload it to anotherg place.  I created a save button that works fine, but without a Submit button there is nothing to trigger the reminder to go back and answer required questions.  I don't want to lose that part.  Thanks in advance for any help you can offfer!

    Would something like this work for you?
    var OKToSave = true;
    if (tfSomething.isNull) {
              tfSomething.border.edge.color.value = "255,0,0";
              OKToSave = false;
    else tfSomething.border.edge.color.value = "255,255,255";
    if (!OKToSave) app.alert("Please fill in all required fields");
    else app.execMenuItem("SaveAs");

  • How do I make an iPad or iPod touch only allow access to one App? I need to create a one application device for a child.

    I need to lock the iPad or Itouch down so only one application is running or available to start.  One, for ease of use by a 3 year old and two, in order to make the use of the iPad as an AAC device allowable in a classroom setting. There is concern that the other games, etc will be a distraction.
    Thank-you!

    You can enable Restrictions, also known as Parental Controls, on an iPhone, iPad, or iPod touch to prevent access to specific features. This article provides an overview of the types of Restrictions that are available, as well as how to enable or disable Restrictions on your device.
    http://support.apple.com/kb/HT4213

  • I have an iCloud account that I can access directly (web or iPhone), but my iMac only allows access to MobileMe in System Preferences.

    If I log into MobilMe through System Preferences, I get an error stating that my password or ID is incorrect, but if I select 'Learn More' I am redirected to the MobileMe site where I can log in with my Apple ID and password. From there I can select to be directed to iCloud. How do I get the iCloud link into System Preferences?

    You don't.
    You log onto iCloud.com through Safari/web browser.

  • Can I use Acrobat 11to download pdf that only allows me to read, enter data, and print?

    I need to complete gov. forms available online as pdf.  I can review, enter data and print, but I cannot save to my computer or anywhere else.  I need to be able to save so I can return to the form and enter information as I access it.  Can this be done if I purchase Acrobat 11 and, if so, can I get the Standard edition?  I currently only have Reader.

    Yes, if you upgrade to at least Acrobat Standard you will be able to save. Since you can't save with Reader (assuming 11), the forms are probably XFA forms (created with LiveCycle Designer), which must be Reader-enabled in order to be saved with Reader. Reader 11 can save non-enabled AcroForms (forms created with Acrobat), but not non-enabled XFA forms. If you have a Reader version prior to 11, try using Reader 11 to see if it will save.
    If you can provide a link to one of the forms, I can tell you for sure what the minimum requirement for saving is.

  • Can I activate a 5S on a network that only "allows" up to an iPhone 5?

    Hello, I am looking to start service with FreedomPop using a phone. They currently only sell the iPhone 5, but say the 4 and 4s are okay to bring to the network. They even told me the 5S and 5C were not allowed due to some software concern...
    Can someone please let me know how they would be able to differentiate between phones they don't have on their person? If I were to tell them I have an iPhone 5 then give them the MEID/IMEI for a 5S, would they be able to tell? They use Sprint's networks and don't use a SIM card that I am aware of (which is the only significant difference I see between the 5 and 5s/5c - switch from micro to nano SIM). The 5s/5c is a much more capable device and compatible with Sprint's networks, so where does the issue come from, if there truly is one? Thank you ahead of time for your help.

    All iPhones, with the exception of the iPhone 4 CDMA, use and require a SIM card.
    They will be able to tell the model of phone when it connects to their network.  If they say the 5S is not supported, it's not supported.
    Only FreedomPop can ellaborate on why the device(s) are not compatible with their network.

Maybe you are looking for

  • How do i check what's taking up all of my space on the macbook air?

    Hi, I've only just got the macbook air 2012 with 64gb of space and now it seems that i have run out of space..Apparently i'm using 54gb and i just can't see how thats possible, because i've only download atleast 2 apps and got iphoto and imovie. Also

  • Podcasts disappearing from Ipod

    For some reason, a few months ago, my podcasts started disappearing off my ipod, it is an 80gig classic, so i prefer to leave them on there, i have checked in podcast settings that it is set to keep them, and i can't see any pattern emerging as to wh

  • Cancellation of excise invoice part II entry

    can anybody help me about cancellation of excise part II entry how it is done i did transaction <b>J1ih</b> for cancellation of excise invoice but it shows error <b>excise and modvat accout not defined for CEIV transaction and excise group</b>

  • Validate date (appointment) values in CRMD_ORDER

    Hi All, How can I validate the date (appointment) value entered on screen in CRMD_ORDER? I need to perform some checkings on the date value entered, at the same time, issue an error at the bottom of screen should it fails. This checking is done as so

  • Keytool.exe : does it take a predefined list of values?

    Hi: I have an installer program that installs an application. I want to run keytool.exe in order to generate a certif for my SSL application during my installer execution. I would prefer to ask the keytool questions to the user in the beginning, get