Cisco PIX 525 Spezifikationen Seite 304

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 466
  • Inhaltsverzeichnis
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen
Seitenansicht 303
9-2
Cisco PIX Firewall and VPN Configuration Guide
78-15033-01
Chapter 9 Accessing and Monitoring PIX Firewall
Command Authorization and LOCAL User Authentication
SNMP
SNMP traps
Syslogs
To enable management access over a VPN tunnel, enter the following command:
management-access mgmt_if
Replace mgmt_if with the IP address assigned to the interface of the remote PIX Firewall to which you
want to connect.
Note You must enable management access for each interface that is connected to the supported management
services that you want to use.
Command Authorization and LOCAL User Authentication
This section describes the Command Authorization feature and related topics, introduced with
PIX
Firewall Version 6.2. It includes the following topics:
Privilege Levels, page 9-2
User Authentication, page 9-3
Command Authorization, page 9-5
Recovering from Lockout, page 9-9
Privilege Levels
PIX Firewall Version 6.2 and higher supports up to 16 privilege levels. This is similar to what is available
with Cisco IOS software. With this feature, you can assign PIX
Firewall commands to one of 16 levels.
Also, users logging into the PIX
Firewall are assigned privilege levels.
Note Users with a privilege level greater than or equal to 2 have access to the enable and configuration mode
and therefore the PIX
Firewall prompt changes to #. Users with a privilege level 0 or 1 see the prompt >.
When a user tries to access enable mode, if the message “T+ enable privilege too low" appears on the
AAA server, set the Max privilege of the AAA client to Level1 in the Advanced TACACS options.
To enable different privilege levels on the PIX Firewall, use the enable command in configuration mode.
To assign a password to a privilege level, enter the following command:
pix(config)# enable password [password] [level level] [encrypted]
Replace password with a character string from three to sixteen characters long, with no spaces. Replace
level with the privilege level you want to assign to the enable password.
Note The encrypted keyword indicates to the PIX Firewall that the password supplied with the enable
command is already encrypted.
Seitenansicht 303
1 2 ... 299 300 301 302 303 304 305 306 307 308 309 ... 465 466

Kommentare zu diesen Handbüchern

Keine Kommentare