privilege
privilegecommand-modelevelprivilege-levelcommand-stringno privilegecommand-modelevelprivilege-levelcommand-string- command-mode
- Specifies the command mode (CLI level) of the command for which the access level is
to be enhanced.
The following values are available:
- exec - EXEC level; for example, device> or device#
- configure - global configuration level; for example, device(config)#
- interface - Interface level; for example, device(config-if-e1000-1/2/3)#
- loopback-interface - Loopback interface configuration sub-mode
- virtual-interface - Virtual-interface configuration sub-mode; for example, device(config-vif-6)#
- dot1x - 802.1X configuration sub-mode
- ipv6-access-list - IPv6 access list configuration sub-mode
- rip-router - RIP router configuration sub-mode; for example, device(config-rip-router)#
- ospf-router - OSPF router configuration sub-mode; for example, device(config-ospf-router)#
- dvmrp-router - DVMRP router configuration sub-mode; for example, device(config-dvmrp-router)#
- pim-router - PIM router configuration sub-mode; for example, device(config-pim-router)#
- bgp-router - BGP4 router configuration sub-mode; for example, device(config-bgp-router)#
- vrrp-router - VRRP configuration sub-mode
- trunk - trunk configuration sub-mode
- port-vlan - Port-based VLAN configuration sub-mode; for example, device(config-vlan)#
- protocol-vlan - Protocol-based VLAN configuration sub-mode
- levelprivilege-level
- Specifies the number of the management privilege level you are augmenting. Valid values are as follows:
Global configuration mode
Each management privilege level provides access to specific areas of the CLI by default. You can grant additional access to a privilege level on an individual command basis. To grant the additional access, specify the privilege level you are enhancing, the CLI level that contains the command, and the individual command.
Super User management privilege provides access to all commands and displays.
Port Configuration management privilege provides access to the following levels:
- The User EXEC
- Privileged EXEC
- The port-specific parts of global configuration
- All interface configuration.
Read Only management privilege level gives access to the following levels:
The
no form of the
privilege command removes the configuration and resets default privilege levels.
The following example shows how to enhance the Port Configuration privilege level so users also can enter IP commands at the global configuration level.
All users with Port Configuration privileges receive the enhanced access after the command is entered. Executing this command will enable users who log in with valid Port Configuration level user names and passwords to execute commands that start with "ip" at the global configuration level.
device# configure terminal device(config)# privilege configure 4 ip