3-23
Software Configuration Guide—Release 15.0(2)SG
OL-23818-01
Chapter 3 Configuring the Switch for the First Time Controlling Access to Privileged EXEC Commands
For information on how to display the password or access level configuration, see the “Displaying the
Password, Access Level, and Privilege Level Configuration” section on page 3-24.
Configuring Multiple Privilege Levels
By default, Cisco IOS software has two modes of password security: user EXEC mode and privileged
EXEC mode. You can configure up to 16 hierarchical levels of commands for each mode. By
configuring multiple passwords, you can allow different sets of users to have access to specified
commands.
For example, if you want many users to have access to the clear line command, you can assign it level 2
security and distribute the level 2 password to more users.. If you want more restricted access to the
configure command, you can assign it level 3 security and distribute that password to fewer users.
The procedures in the following sections describe how to configure additional levels of security:
Setting the Privilege Level for a Command, page 3-23
Changing the Default Privilege Level for Lines, page 3-23
Logging In to a Privilege Level, page 3-24
Exiting a Privilege Level, page 3-24
Displaying the Password, Access Level, and Privilege Level Configuration, page 3-24

Setting the Privilege Level for a Command

To set the privilege level for a command, perform this task:
For information on how to display the password or access level configuration, see the “Displaying the
Password, Access Level, and Privilege Level Configuration” section on page 3-24.

Changing the Default Privilege Level for Lines

To change the default privilege level for a given line or a group of lines, perform this task:
For information on how to display the password or access level configuration, see the “Displaying the
Password, Access Level, and Privilege Level Configuration” section on page 3-24.
Command Purpose
Step 1 Switch(config)# privilege mode level level
command Sets the privilege level for a command.
Step 2 Switch(config)# enable password level level
[encryption-type] password Specifies the enable password for a privilege level.
Command Purpose
Switch(config-line)# privilege level level Changes the default privilege level for the line.