16-29
Cisco ASDM User Guide
OL-16647-01
Chapter 16 Configuring Management Access
Configuring AAA for System Administrators
Figure 16-2 Permitting Single Word Commands
To disallow some arguments, enter the arguments preceded by deny.
For example, to allow enable, but not enable password, enter enable in the commands box, and
deny password in the arguments box. Be sure to select the Permit Unmatched Args check box so
that enable alone is still allowed (see Figure 16-3).
Figure 16-3 Disallowing Arguments
When you abbreviate a command at the command line, the security appliance expands the prefix and
main command to the full text, but it sends additional arguments to the TACACS+ server as you
enter them.
For example, if you enter sh log, then the security appliance sends the entire command to the
TACAC S+ s er ver, show logging. However, if you enter sh log mess, then the security appliance
sends show logging mess to the TACACS+ server, and not the expanded command show logging
message. You can configure multiple spellings of the same argument to anticipate abbreviations (see
Figure 16-4).