[c-nsp] Privilege levels and Secure ACS

Jee Kay jeekay at gmail.com
Tue Jul 5 10:48:38 EDT 2005


On 7/5/05, Brett Looney <brett at looney.id.au> wrote:

> This is true (for "show running") and mentioned in the documentation
> somewhere (can't find it right now). However, (as mentioned previously by
> Serguei Bezverkhi) you can give people access to the "show config" and
> "show startup" commands at privilege levels less than 15 so it's kind of
> pointless...

Is 'show config' the same as 'show startup' ? The problem we have here
is that due to policy we don't always 'write mem' immediately, which
can obviously cause interesting troubleshooting problems when support
can't see the actual real config.

The other reason for wanting 'show run' specifically is that 'show run
int x' is just too useful to discard.



More information about the cisco-nsp mailing list