CLI users
A CLI user is a user account that
-
can be added as internal users or as external users on a LDAP or RADIUS server
-
is maintained separately on each managed device, and
-
requires separate configuration for access to the Firewall Management Center versus managed devices.
User account separation
When you add a user to the Firewall Management Center, that user only has access to the Firewall Management Center; you cannot then use that username to log directly into a managed device. You must separately add a user on the managed device.
Internal and external users
Internal and external users are authentication categories that managed devices support for user access control.
-
Internal users authenticate through a local database on the device
-
External users authenticate through external LDAP or RADIUS authentication servers when not present in the local database, and
-
both user types enable secure access management to network devices.
User authentication types
Managed devices support these user authentication methods:
-
Internal user—The device checks a local database for user authentication.
-
External user—If the user is not present in the local database, the system queries an external LDAP or RADIUS authentication server.
Web interface and CLI access
The Firewall Management Center provides access through a web interface, CLI (via console or SSH to the management interface), and Linux shell. For details about management UIs, refer to System user interfaces.
-
The Firewall Management Center supports two different internal admin users: one for the web interface and another for CLI access. The system initialization process synchronizes the passwords for these two admin accounts initially. However, they are managed separately, and the passwords may diverge after configuration. Refer to the Getting Started Guide for your model for more information on system initialization. To change the password for the web interface admin, use System (
) > Users. To change the password for the CLI admin, use the Firewall Management
Center CLI command configure password .
-
Internal users added in the web interface have web interface access only.
-
External users have web interface access, and you can optionally configure CLI access.
-
SSO users have web interface access only.
Caution: linux shell access and user management
CLI users can access the Linux shell using the expert command. We strongly recommend that you do not use the Linux shell unless directed by Cisco TAC or provided with explicit
instructions in the Firewall Management
Center documentation. CLI users can obtain sudoers privileges in the Linux shell, which can present a security risk. For system security reasons, we strongly recommend that
you:
-
Restrict the list of external users with CLI access appropriately.
-
Do not add users directly in the Linux shell; only use the procedures in this chapter.
User roles
CLI User Role
CLI external users on the Firewall Management Center do not have a user role; they can use all available commands.
Web Interface User Roles
User privileges are based on the assigned user role. For example, you can grant analysts predefined roles such as Security Analyst and Discovery Admin and reserve the Administrator role for the security administrator managing the device. You can also create custom user roles with access privileges tailored to your organization’s needs.
To view the privileges assigned to predefined user roles, click Copy (
) for a role to make a custom role based on the predefined role. You can then view all of the assigned privileges.
The Firewall Management Center includes these predefined user roles:
- Access Admin
-
Provides access to access control policy and associated features in the Policies menu. Access Admins cannot deploy policies.
- Administrator
-
Administrators have access to everything in the product; their sessions present a higher security risk if compromised, therefore, you cannot make them exempt from login session timeouts.
You should limit use of the Administrator role for security reasons.
- Discovery Admin
-
Provides access to network discovery, application detection, and correlation features in the Policies menu. Discovery Admins cannot deploy policies.
- External Database User (Read Only)
-
Provides read-only access to the database using an application that supports JDBC SSL connections. For the third-party application to authenticate to the appliance, you must enable database access in the system settings. On the web interface, External Database Users have access only to online help-related options in the Help menu. This role’s function does not involve the web interface. Access is provided only for support and password changes.
- Intrusion Admin
-
Provides access to all intrusion policy, intrusion rule, and network analysis policy features in the Policies and Objects menus. Intrusion Admins cannot deploy policies.
- Maintenance User
-
Provides access to monitoring and maintenance features. Maintenance Users have access to maintenance-related options in the Health and System menus.
- Network Admin
-
Provides access to access control, SSL inspection, DNS policy, and identity policy features in the Policies menu, as well as device configuration features in the Devices menus. Network Admins can deploy configuration changes to devices.
- Security Analyst
-
Provides access to security event analysis features, and read-only access to health events, in the Overview, Analysis, Health, and System menus.
- Security Analyst (Read Only)
-
Provides read-only access to security event analysis features and health event features in the Overview, Analysis, Health, and System menus.
A user with this role can also:
-
From the health monitor pages for specific devices, generate and download troubleshooting files.
-
Under user preferences, set file download preferences.
-
Under user preferences, set the default time window for event views (with the exception of the Audit Log Time Window).
-
- Security Approver
-
Provides limited access to access control and associated policies and network discovery policies in the Policies menu. Security Approvers can view and deploy these policies, but cannot make policy changes.
- Threat Intelligence Director (TID) User
-
Provides access to Threat Intelligence Director configurations in the Intelligence menu. Threat Intelligence Director (TID) Users can view and configure TID.
User passwords
This reference describes the rules and requirements for passwords on internal user accounts for the Firewall Management Center, with Lights-Out Management (LOM) enabled or disabled. Different password requirements apply to externally authenticated accounts and to systems with security certification compliance enabled. Refer to external authentication configuration for Firewall Management Center and Security certifications compliance for more information.
During Firewall Management Center initial configuration, the system requires the admin user to set the account password to comply with strong password requirements. For physical Firewall Management Centers, the system uses the strong password requirements with LOM enabled. For virtual Firewall Management Centers, the system uses the strong password requirements with LOM not enabled. The system synchronizes the passwords for the web interface admin and CLI access admin. After initial configuration, the web interface admin can remove the strong password requirement. However, the CLI access admin must always comply with strong password requirements with LOM not enabled.
|
LOM Not Enabled |
LOM Enabled |
|
|---|---|---|
|
Password Strength Checking On |
Passwords must include:
The system checks passwords against a special dictionary containing many English words and other character strings that could be easily cracked with common password hacking techniques. |
Passwords must include:
The rules for special characters are different for each series of physical Firewall Management Centers. Choose special characters only from the list in the final bullet. Do not include the user name in the password. The system checks passwords against a special dictionary of English words and character strings that can be easily cracked with common password hacking techniques. |
|
Password Strength Checking Off |
Passwords must include the minimum number of characters configured for the user by the administrator. (Refer to Add or edit an internal user for more information.) |
Passwords must include:
The rules for special characters vary between different series of physical Firewall Management Centers. Use only the special characters from the permitted list. Do not include the user name in the password. |
Users and domains
A user account is an access entity that
-
can be created in any domain where Administrator access is assigned
-
is only visible in the domain in which it is created, and
-
can have different privileges and roles in ancestor and descendant domains.
User roles and domain management
Users can have different privileges in each domain, and user roles can be assigned in both ancestor and descendant domains.
-
Assign read-only privileges to a user in the Global domain.
-
Assign Administrator privileges in a descendant domain.
Users are only visible in the domain in which they are created. If a user is added in the current domain but assigned a user role in a subdomain, the user will only show on the current domain's Users page.
Users added from the Global domain log in with just their username, even if their roles are only in a subdomain.
When you log in, you are placed in the domain where your username was added. For example, the admin user defaults to the Global domain.
After you log in, click the down arrow to change to a subdomain.
User account examples in domains
For example, from the Global domain, you add user leaf and assign a role for Leaf1. Because the user was added from the Global domain, it is visible from the Global domain. If you change domains to Leaf1, you cannot view the user leaf, but you can view the user test, which was added directly from the Leaf1 subdomain.





Feedback