Cisco ASA 5505 Configuration Manual page 696

Asa 5500 series
Hide thumbs Also See for ASA 5505:
Table of Contents

Advertisement

Configuring AAA for System Administrators
Table 32-1
Field
Current privilege level Level from 0 to 15. Unless you configure local command authorization and
Current Mode/s
Recovering from a Lockout
In some circumstances, when you turn on command authorization or CLI authentication, you can be
locked out of the adaptive security appliance CLI. You can usually recover access by restarting the
adaptive security appliance. However, if you already saved your configuration, you might be locked out.
Table 32-2
Table 32-2
CLI Authentication and Command Authorization Lockout Scenarios
Feature
Lockout Condition Description
Local CLI
No users in the
authentication
local database
TACACS+
Server down or
command
unreachable and
authorization
you do not have
the fallback
TACACS+ CLI
method
authentication
configured
RADIUS CLI
authentication
Cisco ASA 5500 Series Configuration Guide using ASDM
32-24
show curpriv Command Output Description
Description
assign commands to intermediate privilege levels, levels 0 and 15 are the only
levels that are used.
Shows the access modes:
P_UNPR—User EXEC mode (levels 0 and 1)
P_PRIV—Privileged EXEC mode (levels 2 to 15)
P_CONF—Configuration mode
lists the common lockout conditions and how you might recover from them.
If you have no users in
the local database, you
cannot log in, and you
cannot add any users.
If the server is
unreachable, then you
cannot log in or enter
any commands.
Chapter 32
Workaround: Single Mode
Log in and reset the
passwords and aaa
commands.
1.
Log in and reset the
passwords and AAA
commands.
Configure the local
2.
database as a fallback
method so you do not
get locked out when the
server is down.
Configuring Management Access
Workaround: Multiple Mode
Session into the adaptive
security appliance from the
switch. From the system
execution space, you can
change to the context and
add a user.
1.
If the server is
unreachable because the
network configuration
is incorrect on the
adaptive security
appliance, session into
the adaptive security
appliance from the
switch. From the system
execution space, you
can change to the
context and reconfigure
your network settings.
2.
Configure the local
database as a fallback
method so you do not
get locked out when the
server is down.
OL-20339-01

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Asa 5510Asa 5540Asa 5520Asa 5550Asa 5580

Table of Contents