Sat 30 Aug 2008
GNS3 : How to lockdown Cisco Router’s Configuration Access
Posted by Tariq Ahmad under Cisco IOS tips and tweaks , GNS3 , GNS3 video tutorials[4] Comments
Email This Post
This tutorial will help you lock down your Cisco gear’s configuration access.This feature comes in very handy for making day-to-day configuration changes.The “Configuration Lock” feature also known as “Exclusive Configuration Change Access ” allows you to have exclusive change access to the Cisco IOS running configuration, preventing multiple users from making concurrent configuration changes to Cisco devices.
In addition, this tutorial will also demonstrate use of “Access Session Locking feature” which takes you a step further in restricting access to device while a configuration change is being made.Together, these features help your configurations to be less error-prone.
The “Access Session Locking feature” extends the “Configuration Lock feature” such that show and debug commands entered by the user holding the configuration lock always have execution priority; show and debug commands entered by other users are only allowed to run after the processes initiated by the configuration lock owner have finished.
The Configuration Lock feature can be set to work in either of following two modes:
- Auto Mode :This mode locks the Cisco IOS configuration mode whenever anyone uses the configure terminal command to make changes.
- Manual Mode :This mode sets to lock the Cisco IOS configuration mode only when the configure terminal lock command is issued.
Enjoy !
If you liked this tutorial ,don't hesitate to buy me a Cup of Coffee today !
(5 votes, average: 4.80 out of 5)
September 3rd, 2008 at 8:20 am
Thanks.
September 15th, 2008 at 8:23 am
You are welcome!
December 3rd, 2008 at 10:36 am
What would be nice is if there was a way that you could lock changes to a device during a specific time of day. This would allow for a lockdown outside of a Change window.
May 8th, 2009 at 3:06 am
Nice Works Admin, Thanks
Can u plz tell me how can i add PC in my topology .