AAA, Local Users & Management Access

Cisco ASA Firewall EVE-NG — ASAv (CLI + ASDM)

مقصدObjectiveObjective

Privilege levels کے ساتھ local AAA users کنفیگر کریں، SSH اور HTTPS management access lock down کریں، اور command authorization set کریں۔Privilege levels ke sath local AAA users configure karo, SSH aur HTTPS management access lock down karo, aur command authorization set karo.Configure local AAA users with privilege levels, lock down SSH and HTTPS management access, and set command authorization.

آسان مثالSimple AnalogySimple Analogy

AAA گارڈ کی logbook plus key policy جیسا ہے: یہ کون ہے (authentication)، کون سے دروازے کھول سکتا ہے (authorization)، اور اس نے کیا کیا (accounting)۔ Privilege levels master keys vs room keys ہیں۔AAA guard ki logbook plus key policy jaisa hai: ye kaun hai (authentication), kaun se darwaze khol sakta hai (authorization), aur usne kya kiya (accounting). Privilege levels master keys vs room keys hain.AAA is like the guard's logbook plus key policy: who is this (authentication), which doors may they open (authorization), and what did they do (accounting). Privilege levels are master keys vs. room keys.

سیٹ اپLab SetupLab Setup

asa-01 والا ASAv جس میں management 0/0 (192.168.10.10/24) پہلے سے up ہے۔ دو admins چاہیے: ایک full admin اور ایک read-only operator۔asa-01 wala ASAv jisme management 0/0 (192.168.10.10/24) pehle se up hai. Do admins chahiye: ek full admin aur ek read-only operator.ASAv from asa-01 with management 0/0 (192.168.10.10/24) already up. Two admins needed: a full admin and a read-only operator.

اقداماتStepsSteps

Step 1

Local user database بنائیں: privilege-15 admin اور privilege-5 operator restricted command set کے ساتھ۔Local user database banao: privilege-15 admin aur privilege-5 operator restricted command set ke sath.Create the local user database: a privilege-15 admin and a privilege-5 operator with a restricted command set.

username admin password Admin123 privilege 15
username operator password Oper123 privilege 5

Step 2

ASA کو بتائیں کہ SSH، HTTPS/ASDM اور enable-mode logins LOCAL user database سے authenticate ہوں۔ASA ko batao ke SSH, HTTPS/ASDM aur enable-mode logins LOCAL user database se authenticate hon.Tell the ASA to authenticate SSH, HTTPS/ASDM, and enable-mode logins against the LOCAL user database.

aaa authentication ssh console LOCAL
aaa authentication http console LOCAL
aaa authentication enable console LOCAL

Step 3

Per-command authorization enable کریں تاکہ privilege-5 users صرف وہی commands چلا سکیں جو ان کے level کی اجازت دیتا ہے — ہر command local database سے check ہوتی ہے۔Per-command authorization enable karo taake privilege-5 users sirf wohi commands chala saken jo unke level ki ijazat deta hai — har command local database se check hoti hai.Enable per-command authorization so privilege-5 users can only run commands their level allows — every command is checked against the local database.

aaa authorization command LOCAL

Step 4

Management protocols کو صرف trusted management subnet تک restrict کریں، اور idle SSH timeout کم کریں۔ Outside interface پر SSH/HTTPS کبھی expose مت کریں۔Management protocols ko sirf trusted management subnet tak restrict karo, aur idle SSH timeout kam karo. Outside interface par SSH/HTTPS kabhi expose mat karo.Restrict management protocols to the trusted management subnet only, and shorten idle SSH timeouts. Never expose SSH/HTTPS on the outside interface.

ssh 192.168.10.0 255.255.255.0 management
ssh timeout 10
http 192.168.10.0 255.255.255.0 management

🖱️ ASDM: Configuration > Device Management > Management Access > ASDM/HTTPS/Telnet/SSH — ہر interface پر source hosts restrict کریں۔ASDM: Configuration > Device Management > Management Access > ASDM/HTTPS/Telnet/SSH — har interface par source hosts restrict karo.ASDM: Configuration > Device Management > Management Access > ASDM/HTTPS/Telnet/SSH — restrict source hosts per interface.

Step 5

Save کرنے سے پہلے AAA اور user configuration verify کریں۔Save karne se pehle AAA aur user configuration verify karo.Verify the AAA and user configuration before saving.

show run aaa
show run username

Step 6

Configuration save کریں۔Configuration save karo.Save the configuration.

write memory

تصدیقVerifyVerify

'operator' سے SSH login password مانگے اور restricted prompt پر لائے؛ 'admin' enable mode تک پہنچے؛ ASDM login صرف management subnet سے کام کرے۔'operator' se SSH login password mange aur restricted prompt par laye; 'admin' enable mode tak pahunche; ASDM login sirf management subnet se kaam kare.SSH login as 'operator' prompts for password and lands at a restricted prompt; 'admin' reaches enable mode; ASDM login works only from the management subnet.

show run aaa
show run username
show ssh sessions

خرابی دور کرناTroubleshootingTroubleshooting

⚠️ Locked out: غلط AAA commands type کر دیں اور اب کوئی login کام نہیں کر رہا۔Locked out: ghalat AAA commands type kar di aur ab koi login kaam nahi kar raha.Locked out: typed the wrong AAA commands and now no login works.

✅ Console access use کریں (EVE-NG console AAA bypass کرتا ہے)۔ غلط lines `no aaa authentication ...` سے ہٹائیں اور صحیح دوبارہ add کریں۔ اپنی working session بند کرنے سے پہلے ہمیشہ دوسری SSH session میں AAA test کریں۔Console access use karo (EVE-NG console AAA bypass karta hai). Ghalat lines `no aaa authentication ...` se hatao aur sahi dobara add karo. Apni working session band karne se pehle hamesha doosri SSH session mein AAA test karo.Use console access (EVE-NG console bypasses AAA). Remove the bad lines with `no aaa authentication ...` and re-add correct ones. Always test AAA in a second SSH session before closing your working one.

⚠️ Operator user (priv 5) `show` commands نہیں چلا سکتا۔Operator user (priv 5) `show` commands nahi chala sakta.Operator user (priv 5) cannot run `show` commands.

✅ Command authorization per-level ہوتی ہے؛ `privilege show level 5 command ...` سے specific commands grant کریں یا user کو اس level پر لائیں جس کے command set میں ضروری commands ہوں۔Command authorization per-level hoti hai; `privilege show level 5 command ...` se specific commands grant karo ya user ko us level par lao jiske command set mein zaroori commands hon.Command authorization is per-level; grant specific commands with `privilege show level 5 command ...` or raise the user to a level whose command set includes what they need.

انٹرویو سوالاتInterview Q&AInterview Q&A

❓ AAA میں تین A's کا کیا مطلب ہے؟AAA mein teen A's ka kya matlab hai?What do the three A's in AAA stand for?

Authentication identity verify کرتا ہے، authorization طے کرتا ہے user کیا کر سکتا ہے (commands, privilege level)، اور accounting log کرتا ہے کیا کیا گیا۔ ASA پر LOCAL users external server کے بغیر تینوں دیتے ہیں۔Authentication identity verify karta hai, authorization tay karta hai user kya kar sakta hai (commands, privilege level), aur accounting log karta hai kya kiya gaya. ASA par LOCAL users external server ke baghair teeno dete hain.Authentication verifies identity, authorization defines what the user may do (commands, privilege level), and accounting logs what was done. On ASA, LOCAL users give all three without an external server.

❓ Privilege level 15 اور lower levels میں کیا فرق ہے؟Privilege level 15 aur lower levels mein kya farq hai?What is the difference between privilege level 15 and lower levels?

Privilege 15 full admin ہے (directly enable mode)۔ Level 1 یا 5 جیسے lower levels users کو commands کے subset تک restrict کرتے ہیں — read-only operators یا helpdesk staff کے لیے useful۔Privilege 15 full admin hai (directly enable mode). Level 1 ya 5 jaise lower levels users ko commands ke subset tak restrict karte hain — read-only operators ya helpdesk staff ke liye useful.Privilege 15 is full admin (enable mode directly). Lower levels like 1 or 5 restrict users to a subset of commands — useful for read-only operators or helpdesk staff.