EasyManuals Logo

Cisco FirePOWER ASA 5500 series User Manual

Cisco FirePOWER ASA 5500 series
989 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #625 background imageLoading...
Page #625 background image
30-71
Cisco Security Appliance Command Line Configuration Guide
OL-10088-01
Chapter 30 Configuring Tunnel Groups, Group Policies, and Users
Configuring User Attributes
By default, VPN users that you add with this command have no attributes or group policy association.
You must explicitly configure all values.
The following example shows how to configure a user named anyuser with an encrypted password of
pw_12345678 and a privilege level of 12:
hostname(config)# username anyuser password pw_12345678 encrypted privilege 12
hostname(config)#
Configuring User Attributes
After configuring the user’s password (if any) and privilege level, you set the other attributes. These can
be in any order. To remove any attribute-value pair, enter the no form of the command.
Enter username mode by entering the username command with the attributes keyword:
hostname(config)# username name attributes
hostname(config-username)#
The prompt changes to indicate the new mode. You can now configure the attributes.
Configuring VPN User Attributes
The VPN user attributes set values specific to VPN connections, as described in the following sections.
Configuring Inheritance
You can let users inherit from the group policy the values of attributes that you have not configured at
the username level. To specify the name of the group policy from which this user inherits attributes, enter
the vpn-group-policy command. By default, VPN users have no group-policy association:
hostname(config-username)# vpn-group-policy group-policy-name
hostname(config-username)# no vpn-group-policy group-policy-name
For an attribute that is available in username mode, you can override the value of an attribute in a group
policy for a particular user by configuring it in username mode.
The following example shows how to configure a user named anyuser to use attributes from the group
policy named FirstGroup:
hostname(config)# username anyuser attributes
hostname(config-username)# vpn-group-policy FirstGroup
hostname(config-username)#
Configuring Access Hours
Associate the hours that this user is allowed to access the system by specifying the name of a configured
time-range policy:
password password Indicates that this user has a password, and provides the password.
privilege priv_level Sets a privilege level for this user. The range is from 0 to 15, with lower
numbers having less ability to use commands and administer the security
appliance. The default privilege level is 2. The typical privilege level for a
system administrator is 15.

Table of Contents

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the Cisco FirePOWER ASA 5500 series and is the answer not in the manual?

Cisco FirePOWER ASA 5500 series Specifications

General IconGeneral
BrandCisco
ModelFirePOWER ASA 5500 series
CategoryFirewall
LanguageEnglish

Related product manuals