IntermediatePublished 2026-07-04
Privilege Levels for Tiered CLI Access
Bundle lab
Harden a single IOS router’s management plane and create tiered CLI access using custom privilege levels. Build two local accounts: a full admin (level 15) and a junior operator (level 5). Elevate only specific exec commands to level 5 so the operator can run them without gaining full configuration rights. Verify behavior from a Linux admin workstation over SSH.
Learning objectives
- Configure a management-only IPv4 LAN for SSH access to a Cisco IOS router
- Enable SSH-only remote access with local authentication
- Create tiered local users: a full administrator at privilege 15 and a junior operator at privilege 5
- Grant exact CLI capabilities to a mid-tier role using 'privilege exec level N <command>'
- Verify effective privilege level and command access from remote SSH sessions
- Differentiate login/authentication from authorization and command privilege control
Troubleshooting focus
- Operator logs in at level 1 instead of 5: verify 'username oper privilege 5 secret <p>'
- Operator cannot run intended commands: confirm 'privilege exec level 5 <command>' entries exist
- SSH blocked or refused: ensure non-default hostname, configured ip domain name, local users, VTY 'transport input ssh' with 'login local', and RSA keys exist
- Admin cannot enter configuration mode: verify admin account is privilege 15 and enable secret is set
- Console appears to hang or spam output: set 'logging synchronous' and reasonable 'exec-timeout' on console
Topology
Subscribe to preview this lab's topology.
See plansGrade your work
How this lab is graded
- Build it your way. Where a lab lets you choose a value — a VLAN name, an interface description — grading checks that you configured it, not which name you picked. Names that another line has to reference, like an ACL applied with
access-class, are stated in the guide and do have to match. - Addresses, modes and protocol keywords are exact. An IP address, a subnet mask,
switchport mode trunk, an encapsulation — these carry the meaning of the lab, so they are graded as written in the guide. - Grading reads your saved configuration. Export the lab from CML after you have configured it, and make sure anything you set is in the running-config — a change that only exists in a terminal session never reaches the grader.
- You can submit as many times as you like. Your best score stands, and each attempt tells you which checks passed so you can work the gaps.
- Scored something you believe is correct? Use Report an issue on this page — that is exactly how the grading fixes in the changelog got found.
Create a free account to submit your lab for grading.
Create a free accountFound a problem with this lab?
Please sign in to report a problem — tying it to your attempts lets us reproduce and fix it faster.