Privilege level for Cisco FTD

Commands Required for the Scan

show running-config all

Privilege Levels (CLI User Roles)

On managed devices, user access to commands in the CLI depends on the role you assign:

User Role

Access

config

The user can access all commands, including configuration commands. Exercise caution in assigning this level of access to users.

basic

The user can access non-configuration commands only. Only internal users and FTD external RADIUS users support the Basic role.

 

The minimal privilege for a successful Cisco FTD ML scan is the Basic access level.

Create a Scan User Account on the System to Scan

- User Roles on the target

>show user
Login              UID   Auth Access  Enabled Reset   Exp     Warn    Grace MinL Str Lock Max
admin              100  Local Config  Enabled    No  10000      7   Disabled   8 Ena  No N/A
testuser          1001  Local Basic   Enabled   Yes  10000      7   Disabled   0 Dis  No   5

- User with Config Access level

([email protected]) Password: 
Last login: Wed Jan 18 02:22:35 UTC 2023 from xx.xxx.x.xxx on pts/0

Copyright 2004-2022, Cisco and/or its affiliates. All rights reserved. 
Cisco is a registered trademark of Cisco Systems, Inc. 
All other trademarks are property of their respective owners.

Cisco Firepower Extensible Operating System (FX-OS) v2.13.0 (build 198)
Cisco Firepower Threat Defense for AWS v7.3.0 (build 69)

> show running-config all
: Saved


: Serial Number: XXXXXXXX
: Hardware:   NGFWv, 7680 MB RAM, CPU Xeon 4100/6100/8100 series 3400 MHz, 1 CPU (4 cores)
:
NGFW Version 7.3.0

- User with Basic Access level

([email protected]) You are required to change your password immediately (administrator enforced).
Changing password for testuser.
Current password: 
([email protected]) New password: 
([email protected]) Retype new password: 

Copyright 2004-2022, Cisco and/or its affiliates. All rights reserved. 
Cisco is a registered trademark of Cisco Systems, Inc. 
All other trademarks are property of their respective owners.

Cisco Firepower Extensible Operating System (FX-OS) v2.13.0 (build 198)
Cisco Firepower Threat Defense for AWS v7.3.0 (build 69)

> show running-config all
: Saved


: Serial Number: XXXXXXXXXXX
: Hardware:   NGFWv, 7680 MB RAM, CPU Xeon 4100/6100/8100 series 3400 MHz, 1 CPU (4 cores)
:
NGFW Version 7.3.0