Configuring Local User Accounts

After an initial Super User account is created, user accounts with different privileges can be configured.
On a new device, you must first create a user with Super User privileges. You must be logged in with Super User access (privilege level 0) to add or delete user accounts or configure or modify other access parameters. In the following task, various level of access are configured for users. After Step 2 is performed for a new device, all the steps are optional.
  1. Enter global configuration mode.
    device# configure terminal
  2. Create a user with privilege level.
    device(config)# username user1 privilege 0 password *******
    The privilege level of 0 is the default and allows complete read-and-write access to the system. To allow read-and-write access for specific ports, but not global parameters, the privilege level is 4. For read-only access, use privilege level 5.
  3. Create a Super User level password.
    device(config)# enable super-user-password test
    After creating a password for the Super User, you can continue to add user accounts.
  4. Create Port Configuration and Read-only passswords.
    device(config)# enable port-config-password port
    device(config)# enable read-only-password read
    You must set the Super user password before setting other types of passwords.
  5. Create a user account with read only access and an unencrypted password using the password command.
    device(config)# username user-mktg2 privilege 5 password xpassx
    Caution: User accounts with unencrypted passwords are less secure.
  6. To prevent unauthorized user account deletion enter the service local-user-protection command.
    device(config)# service local-user-protection
    The service local-user-protection command applies to all user accounts. When you try to delete a specific user you will be prompted for verification before deleting that user.
  7. Create a user account with read/write access and an encrypted password using the create-password command.
    device(config)# username user-mktg3 privilege 0 create-password xpassx
  8. Create a user account with read only access and no password.
    device(config)# username user-mktg4 privilege 5 nopassword
  9. Display user account information using the show users command.
    device(config)# show users