privilege

Configures the management privilege access level of a command.
Syntax
privilegecommand-modelevelprivilege-levelcommand-string
no privilegecommand-modelevelprivilege-levelcommand-string
Parameters
command-mode
Specifies the command mode (CLI level) of the command for which the access level is to be enhanced.

The following values are available:

  • exec - EXEC level; for example, device> or device#
  • configure - global configuration level; for example, device(config)#
  • interface - Interface level; for example, device(config-if-e1000-1/2/3)#
  • loopback-interface - Loopback interface configuration sub-mode
  • virtual-interface - Virtual-interface configuration sub-mode; for example, device(config-vif-6)#
  • dot1x - 802.1X configuration sub-mode
  • ipv6-access-list - IPv6 access list configuration sub-mode
  • rip-router - RIP router configuration sub-mode; for example, device(config-rip-router)#
  • ospf-router - OSPF router configuration sub-mode; for example, device(config-ospf-router)#
  • dvmrp-router - DVMRP router configuration sub-mode; for example, device(config-dvmrp-router)#
  • pim-router - PIM router configuration sub-mode; for example, device(config-pim-router)#
  • bgp-router - BGP4 router configuration sub-mode; for example, device(config-bgp-router)#
  • vrrp-router - VRRP configuration sub-mode
  • trunk - trunk configuration sub-mode
  • port-vlan - Port-based VLAN configuration sub-mode; for example, device(config-vlan)#
  • protocol-vlan - Protocol-based VLAN configuration sub-mode

Enter ? to check for available interface subtypes.

levelprivilege-level
Specifies the number of the management privilege level you are augmenting. Valid values are as follows:
  • 0 - Super User level (full read-write access)
  • 4 - Port Configuration level
  • 5 - Read Only level.
command-string
Specifies the command you want to assign the specified privilege level.

Enter ? at the command prompt of a CLI level to display the list of commands at that level.

Modes

Global configuration mode

Usage Guidelines

Each management privilege level provides access to specific areas of the CLI by default. You can grant additional access to a privilege level on an individual command basis. To grant the additional access, specify the privilege level you are enhancing, the CLI level that contains the command, and the individual command.

Super User management privilege provides access to all commands and displays.

Port Configuration management privilege provides access to the following levels:

  • The User EXEC
  • Privileged EXEC
  • The port-specific parts of global configuration
  • All interface configuration.

Read Only management privilege level gives access to the following levels:

  • User EXEC
  • Privileged EXEC

Note: The privilege command applies only to management privileges for the CLI.

The no form of the privilege command removes the configuration and resets default privilege levels.

Examples

The following example shows how to enhance the Port Configuration privilege level so users also can enter IP commands at the global configuration level.

All users with Port Configuration privileges receive the enhanced access after the command is entered. Executing this command will enable users who log in with valid Port Configuration level user names and passwords to execute commands that start with "ip" at the global configuration level.

device# configure terminal
device(config)# privilege configure 4 ip