
30-12
Cisco Security Appliance Command Line Configuration Guide
OL-6721-01
Chapter 30 Managing System Access
Authenticating and Authorizing System Administrators
• You can permit all arguments of a command that you do not explicitly deny by selecting the Permit
Unmatched Args check box.
For example, you can configure just the show command, and then all the show commands are
allowed. We recommend using this method so that you do not have to anticipate every variant of a
command, including abbreviations and ?, which shows CLI usage (see Figure 30-1).
Figure 30-1 Permitting All Related Commands
• For commands that are a single word, you must permit unmatched arguments, even if there are no
arguments for the command, for example enable or help (see Figure 30-2).
Figure 30-2 Permitting Single Word Commands
•
To disallow some arguments, enter the arguments preceded by deny.
For example, to allow enable, but not enable password, enter enable in the commands box, and
deny password in the arguments box. Be sure to select the Permit Unmatched Args check box so
that enable alone is still allowed (see Figure 30-3).
Kommentare zu diesen Handbüchern