1-30
Cisco ASA Series CLI Configuration Guide
Chapter 1 Configuring Management Access
Configuring AAA for System Administrators
–
show pager
–
clear pager
–
quit
–
show version
Configuring Command Authorization
If you enable command authorization, and a user enters a command at the CLI, the ASA
sends the command and username to the server to determine if the command is authorized.
Before you enable command authorization, be sure that you are logged into the ASA as a user
that is defined on the server, and that you have the necessary command authorization to
continue configuring the ASA. For example, you should log in as an admin user with all commands
authorized. Otherwise, you could become unintentionally locked out.
Do not save your configuration until you are sure that it works the way you want. If you get locked out
because of a mistake, you can usually recover access by restarting the ASA. If you still get locked out,
see the
“Recovering from a Lockout” section on page 1-32
.
Be sure that your system is completely stable and reliable. The necessary level of reliability
typically requires that you have a fully redundant server system and fully redundant
connectivity to the ASA. For example, in your server pool, include one server connected to
interface 1, and another to interface 2. You can also configure local command authorization as a fallback
method if the server is unavailable. In this case, you need to configure local users and
command privilege levels according to procedures listed in the
“Configuring Command Authorization”
To configure command authorization, enter the following command:
Detailed Steps
Configuring Management Access Accounting
You can send accounting messages to the accounting server when you enter any command
other than
show
commands at the CLI. You can configure accounting when users log in, when they enter
the
enable
command, or when they issue commands.
For command accounting, you can only use servers.
Command
Purpose
aaa authorization command
_server_group
[
LOCAL
]
Example:
hostname(config)# aaa authorization
command group_1 LOCAL
Performs command authorization using a server.
You can configure the ASA to use the local database as a fallback method
if the server is unavailable. To enable fallback, specify the
server group name followed by
LOCAL
(
LOCAL
is case sensitive). We
recommend that you use the same username and password in the local
database as the server because the ASA prompt does not give
any indication which method is being used. Be sure to configure users in
the local database (see the
“Adding a User Account to the Local Database”
) and command privilege levels (see the
Summary of Contents for 5505 - ASA Firewall Edition Bundle
Page 28: ...Glossary GL 24 Cisco ASA Series CLI Configuration Guide ...
Page 61: ...P A R T 1 Getting Started with the ASA ...
Page 62: ......
Page 219: ...P A R T 2 Configuring High Availability and Scalability ...
Page 220: ......
Page 403: ...P A R T 2 Configuring Interfaces ...
Page 404: ......
Page 499: ...P A R T 2 Configuring Basic Settings ...
Page 500: ......
Page 533: ...P A R T 2 Configuring Objects and Access Lists ...
Page 534: ......
Page 601: ...P A R T 2 Configuring IP Routing ...
Page 602: ......
Page 745: ...P A R T 2 Configuring Network Address Translation ...
Page 746: ......
Page 845: ...P A R T 2 Configuring AAA Servers and the Local Database ...
Page 846: ......
Page 981: ...P A R T 2 Configuring Access Control ...
Page 982: ......
Page 1061: ...P A R T 2 Configuring Service Policies Using the Modular Policy Framework ...
Page 1062: ......
Page 1093: ...P A R T 2 Configuring Application Inspection ...
Page 1094: ......
Page 1191: ...P A R T 2 Configuring Unified Communications ...
Page 1192: ......
Page 1333: ...P A R T 2 Configuring Connection Settings and QoS ...
Page 1334: ......
Page 1379: ...P A R T 2 Configuring Advanced Network Protection ...
Page 1380: ......
Page 1475: ...P A R T 2 Configuring Modules ...
Page 1476: ......
Page 1549: ...P A R T 2 Configuring VPN ...
Page 1550: ......
Page 1965: ...P A R T 2 Configuring Logging SNMP and Smart Call Home ...
Page 1966: ......
Page 2059: ...P A R T 2 System Administration ...
Page 2060: ......
Page 2098: ...1 8 Cisco ASA Series CLI Configuration Guide Chapter 1 Troubleshooting Viewing the Coredump ...
Page 2099: ...P A R T 2 Reference ...
Page 2100: ......