For small businesses, using an external user database such as Cisco ACS is not always feasible. Fortunately, Cisco ASA software includes the ability to use a local user database for authenticating administrators and remote access users.

The commands are pretty straight forward: to add a user, enter the username command. For example:

Firewall(config)# username bgeorge password b3lucky

By default, the ASA assigns users a privilege level of 2. On a scale of 0 to 15, this sounds harmless. However, this is enough to allow access to all commands within privileged EXEC mode! Those coming from an IOS background assume the enable password will prevent users from gaining access to privileged mode - not the case. By default, a user can enter the login command from user EXEC mode which allows them privileged EXEC access with their assigned level. For example, the user bgeorge accesses the ASA user EXEC mode:

Firewall> login
Username: bgeorge
Password: b3lucky
Firewall# show curpriv
Username : bgeorge
Current privilege level : 2
Current Mode/s : P_PRIV
Firewall#

The user bgeorge now has full access to the ASA!

The simple way to prevent this is make sure you assign a privilege level to each user. If bgeorge is a remote-access user, assign a privilege of 0. Also, enabling local command authorization will mean even users with a default privilege level of 2 won’t have access to practically any command from within privileged EXEC mode. To activate local command authorization, enter the following:

Firewall(config)# aaa authorization command LOCAL

You can view the commands and their default privilege level as follows:

Firewall# sh run all privilege all

Administrators may wish to keep the enable password different from the user password (similar to IOS). If you wish to do this, ensure all user accounts are set to privilege level 0. To access privileged mode, use the enable command followed by the enable password. This places you at level 15 as user ‘enable_15′. The recommended method is to configure authentication for the enable command as follows:

Firewall(config)# aaa authentication enable console LOCAL

This forces users into their assigned privileged level by requiring their own password instead of the enable one. For example, typing the enable command from user EXEC mode now requires the user’s password, not the enable password. There is no indication of this to the user as the prompt is the same. Used in conjunction with local command authorization, this provides a basic level of security to the administration of your ASA.

Finally, if you do add users to the local database for remote-access, you can restrict them access to a specific group using the group-lock command. By default, the users are allowed to access any group as they inherit this from the default group policy. The following is an example of how to configure this:

Firewall(config)# username johnd password c1sc0 privilege 0
Firewall(config)# username johnd attributes
Firewall(config-username)# group-lock value vpn-admin

This will limit user johnd to the vpn-admin group.

3 Responses to “ASA 7.x Local Users”

  1. Simon says:

    John,

    I noticed you mentioned in the Title ASA v7.x I take it these commands and findings also relate to the ASA v8.x software?

  2. John says:

    Hi Simon,

    Yes, you can also apply this to version 8 as well. There is even the option to assign a user a ‘type’ such as remote-access or admin using the service-type command within the username attributes:

    http://www.cisco.com/en/US/docs/security/asa/asa80/configuration/guide/aaa.html#wpxref64390

  3. Simon says:

    Thanks I have noticed there are more aaa commands added in 8.0(2) command line reference guide aswell, however I’m unable to find 8.0(3) commandline ref guide as yet on the cisco site.

Leave a Reply

Add to Technorati Favorites Add to Google
  • treatment for dry skin
  • weight loss doctor online
  • heart pain chest
  • clomid dosage
  • cymbalta dosages
  • my drug store
  • about levitra
  • flu vaccines
  • treating high cholesterol
  • drug phenergan
  • post pregnancy weight loss
  • free dog products
  • help with weight loss
  • cheapest levitra
  • breast cancer products
  • small dog products
  • online drug stores
  • stop smoking tablets
  • about levitra
  • sleep disorders drugs
  • fast weight loss tips
  • hydrochlorothiazide generic
  • cures for lung cancer
  • back pain
  • natural help sleeping
  • ulcers stomach
  • prostate cancer treatment
  • irritable bowel syndrome treatments
  • cymbalta anxiety
  • asthma treatment drugs
  • healthy pets
  • finasteride dosage
  • weight loss solutions
  • body building nutrition
  • perfect pet products
  • buy viagra internet
  • pneumonia vs bronchitis
  • latest diet pill
  • ordering meds without a prescription
  • increased heart rate drugs
  • face skin care
  • pain meds without prescription
  • celecoxib 200mg
  • obtaining pain killers
  • pain meds without prescriptions
  • hair loss treatment uk
  • cat health care
  • fat weight loss products
  • high blood pressure elderly
  • cancer drugs
  • dental antibiotics
  • strattera generic
  • removing dark spots from face
  • medicine drugs
  • new cancer drug
  • buy plan b
  • drug price
  • improve skin
  • diabetes type 2
  • buy pain pills on line
  • anti anxiety meds
  • dog products uk
  • weight loss how to
  • dogs health problems
  • high blood pressure medicines
  • drugs no prescription
  • online drugs without prescription
  • the new flu
  • buy meds no prescription
  • medications celebrex
  • no prescription online pharmacies
  • skin cell
  • controlling blood pressure
  • how does osteoporosis occur
  • quitting smoking
  • liver infection treatment
  • health med
  • cat care
  • buy viagra internet
  • body building product
  • blood pressure support
  • health vitamins
  • buy omega 3
  • smoking stop
  • viagra with out prescription
  • right side back pain
  • symptoms of congestive heart failure
  • celexa buy
  • over weight dog
  • diabetes drugs
  • build muscle
  • flu shot
  • depression therapy
  • dog health in mexico
  • best hair loss treatment
  • self help weight loss
  • buy cialis on line
  • high blood pressure cause
  • muscle spasm relief
  • drug stores
  • buy meds no prescription
  • discount anti-biotics
  • alcoholism information treatment
  • list of cancer treating drugs
  • lower leg pain
  • weight loss nutrition
  • dog health problems
  • drugs for energy
  • viagra and buy
  • drugs for sale
  • where to buy stop pain
  • medication for depression
  • pharmacies without prescriptions
  • cholesterol and health
  • alzheimers disease drugs
  • natures antibiotic
  • medicine for blood pressure
  • stopping smoking
  • diabetes treatment
  • reduce blood pressure
  • cat health info
  • treatments for throat infection
  • nolvadex dosage
  • dog health help
  • tamiflu flu
  • natural back pain relief
  • new heart attack drugs
  • dogs health problems
  • tips to help loss weight
  • vitamins store
  • wrinkle skin care
  • what causes throat infection
  • cialis 30
  • reason for high blood pressure
  • pet health care
  • blood pressure pills
  • how to stop the pain
  • newest approved drugs
  • hair loss treatments
  • hair loss remedy
  • treatment of breast cancer
  • us online pharmacy
  • medical treatment for diabetes
  • acomplia online
  • osteoporosis treating
  • claritin dose
  • free help to stop smoking
  • vitamin store
  • treatment for hypertension
  • bust increase
  • dog site health
  • buy tadalafil online
  • buy pain medicine online
  • health problems cats
  • cure for high blood pressure
  • low back pain
  • on-line pharmacies
  • treatment of asthma
  • on-line drugs
  • lower back pain
  • treating prostate cancer
  • cheap impotence drug generic cialis delivery
  • risperdal depression
  • best weight loss programs
  • medicine drugs
  • malaria medicines
  • plan b pregnancy
  • tips for weight loss
  • buy drugs prescription online
  • reducing high blood pressure
  • high blood pressure medicines
  • international pharmacy
  • anti smoking
  • anti depression
  • weight loss for women over 50
  • stop pain
  • chronic pain management
  • help to give up smoking
  • hair loss products for women
  • cold flu
  • online alcoholism treatment
  • medicine for dogs
  • breast cancer drugs
  • claritin 10mg
  • sleep disorders treatment
  • treatment of heart attacks
  • products diet
  • cheap drug pharmacies
  • reasons for high blood pressure
  • weight loss solution
  • blood pressure high
  • life after a heart attack
  • fda avandia
  • causes for high blood pressure
  • aspirin and pregnancy
  • natural breast enhancer
  • pharmacy zolpidem
  • how to get teeth white
  • back pain relief product
  • discount weight loss pill