一、新建用户
ciscoasa# conf t
ciscoasa(config)# username gmtest password gm200307ciscoasa(config)# username gmtest attributes
ciscoasa(config-username)# vpn-group-policy DefaultRAGroup
ciscoasa(config-username)# service-type remote-access
ciscoasa(config-username)# vpn-framed-ip-address 192.168.100.58 255.255.255.0
ciscoasa(config-username)# password-storage enable
ciscoasa(config-username)# exit
二、删除用户
ciscoasa(config)# no username e02844 attributes #删除用户属性ciscoasa(config)# no username e02844 #删除用户
ciscoasa(config)# clear config username e02844 #也是删除用户
三、其它
ciscoasa(config)# show aaa local user #查看本地AAA认证的用户ciscoasa# show curpriv #查看当前用户特权级别
定义不同级别权限的防火墙用户:
ciscoasa(config)# username cisco password cisco encrypted privilege 15
ciscoasa(config)# username giving password giving privilege 5
默认情况下,设备非特权模式的密码是cisco,等级是0。
设置非特权模式密码:
ciscoasa(config)# passwd giving
设置特权模式密码:
ciscoasa(config)# enable password giving level 15
ciscoasa(config)# enable password giving level 5
设置特权模式为无密码,恢复默认:
ciscoasa(config)# enable password