3-18
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 7.2
OL-29168-01
Chapter 3 Setting Up the Sensor
Configuring Authentication and User Parameters
Note
If you change the port or enable TLS settings, you must reset the sensor to make the web server uses the
new settings.
For More Information
For the procedure for enabling SSHv1 fallback, see Enabling SSHv1 Fallback, page3-13.
For the procedure for resetting the appliance, see Resetting the Appliance, page 17-44.
For the procedure for resetting the ASA 5500-X IPS SSP, see Reloading, Shutting Down, Resetting,
and Recovering the ASA 5500-X IPS SSP, page 18-11.
For the procedure for resetting the ASA 5585-X IPS SSP, see Reloading, Shutting Down, Resetting,
and Recovering the ASA 5585-X IPS SSP, page 19-11.
Configuring Authentication and User Parameters
The following section explains how to create users, co nfigure RADIUS authentication, create the s ervice
account, configure passwords, specify privilege level, view a list of users, configure password policy,
and lock and unlock user accounts. It contains the following topics:
Adding and Removing Users, page 3-18
Configuring Authentication, page 3-20
Configuring Packet Command Restriction, page 3-26
Creating the Service Account, page 3-28
The Service Account and RADIUS Authentication, page 3-29
RADIUS Authentication Functionality and Limitations, page 3-29
Configuring Passwords, page 3-29
Changing User Privilege Levels, page 3-30
Showing User Status, page 3-31
Configuring the Password Policy, page 3-32
Locking User Accounts, page 3-33
Unlocking User Accounts, page 3-34

Adding and Removing Users

Use the username command to create users on the local system. You can add a new user, set the privilege
level—administrator, operator, viewer—and set the password for the new user. Use the no form of this
command to remove a user from the system. This removes the user from CLI and web access.
Caution
The username command provides username and password authentication for login purposes only. You
cannot use this command to remove a user who is logged in to the system. You cannot use this command
to remove yourself from the system.