6-8
Catalyst 3550 Multilayer Switch Software Configuration Guide
78-11194-03
Chapter6 Administering the Switch
Protecting Access to Privileged EXEC Commands
To disable username authentication for a specific user, use the no username name global configuration
command. To disable password checking and allow connections without a password, use the no login
line configuration command.
Configuring Multiple Privilege Levels
By default, the IOS software has two modes of password security: user EXEC and privileged EXEC.
You can configure up to 16 hierarchical levels of commands for each mode. By configuring multiple
passwords, you can allow different sets of users to have access t o spec ified c om mands.
For example, if you want many users to have access to the c lear l in e comm and , you c an assi gn i t
level 2 security and distribute the level 2 password fairly widely. But if you w ant m o re r estr ict ed a cce ss
to the configure command, you can assign it level 3 security and distribute that password to a more
restricted group of users.
This section includes this configuration information:
Setting the Privilege Level for a Command, page 6-8
Changing the Default Privilege Level for Lines, page 6-9
Logging into and Exiting a Privilege Level, page 6-10

Setting the Privilege Level for a Command

Beginning in privileged EXEC mode, follow these steps to set the privilege level for a command mode:
Command Purpose
Step1 configure terminal Enter global configuration mode.
Step2 privilege mode level level command Set the privilege level for a command.
For mode, enter configure for global configuration mode, exec for
EXEC mode, interface for interface configuration mode, or line for
line configuration mode.
For level, the range is from 0 to 15. Level 1 is for normal user EXEC
mode privileges. Level 15 is the level of access permitted by the
enable password.
For command, specify the command to which you wa nt to re stri ct
access.
Step3 enable password level level password Specify the enable password for the privilege level.
For level, the range is from 0 to 15. Level 1 is for normal user EXEC
mode privileges.
For password, specify a string from 1 to 25 alphanumeric characters.
The string cannot start with a number, is case sensitive, and allows
spaces but ignores leading spaces. By default, no password is
defined.
Step4 end Return to privileged EXEC mode.