Anyone play around with creating cli-views? I'm having a problem getting started.
I've tried both my router and switch and both lock me out when trying to enable views.
Both devices have "aaa new-model" enable. With local authentication.
"aaa authentication login default local"
I've created a user account with priv 15 like so:
username brandon privilege 15 secret cisco
When I to EXEC mode and type this:
"enable view"
I get prompted for a password, well, what other password can there possibly be? So I put in "cisco".
I then get this error:
% Authentication Failed
So I've checked out Cisco's doc and it seems a bit confusing, here's what they say:
[B] Prerequisites [/B]
Before you create a view, you must perform the following tasks:
•[IMG]http://www.cisco.com/en/US/i/templates/blank.gif[/IMG]Enable AAA via the [B]aaa new-model [/B]command.
•[IMG]http://www.cisco.com/en/US/i/templates/blank.gif[/IMG]Ensure that your system is in root view—[COLOR=Red]not privilege level 15. [/COLOR]
So here's my DUH! question of the day, how do you get INTO ROOT VIEW in the first place? If privilege 15 isn't enough, then how do you do it? It seems like a catch 22?
Then Cisco's documentation says this for step #1:
enable view
Example:
Router> enable view
Enables root view.
•
Enter your privilege level 15 password (for example, root password) if prompted.
UMM WHAT??
Here's the link to the doc. Can anyone help me out here? Thanks!
Cisco IOS Security Configuration Guide: Securing User Services, Release 15.0 - Role-Based CLI Access [Cisco IOS Software Releases 15.0] - Cisco Systems