[c-nsp] Setting up a RO user in IOS-XR and IOS-XE

Hank Nussbacher via cisco-nsp <[email protected]> Mon, 16 Feb 2026 17:40:21 +0200
Newsgroups gmane.network.nsp.cisco
Message-ID <[email protected]>
--===============4985941281442906395==
Content-Language: en-US
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 8bit

Under IOS-XE if we do:

username <username> privilege 1 secret <password>

the user has no ability to do any show commands.

Elevating to priv=5 doesn't help.  Only priv=15 helps - but then the 
user has RW access.

So how does one set up a user in IOS-XE so they can do any and all 
"show" commands?


Same question for IOS-XR.  Tried:

taskgroup read-only

   task read

!

usergroup read-only-group

   taskgroup read-only

!

username <username>

   group read-only-group

   secret <password>


but "task read" requires many additional parameters such as “task read 
ospf”, “task read acl”, “task read bgp”, “task read ipv4” , etc.


Can anyone provide the exact IOS-XE and IOS-XR commands to create a RO user?


Thanks,

Hank




--===============4985941281442906395==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18KY2lzY28tbnNw
IG1haWxpbmcgbGlzdCAgY2lzY28tbnNwQHB1Y2submV0aGVyLm5ldApodHRwczovL3B1Y2submV0
aGVyLm5ldC9tYWlsbWFuL2xpc3RpbmZvL2Npc2NvLW5zcAphcmNoaXZlIGF0IGh0dHA6Ly9wdWNr
Lm5ldGhlci5uZXQvcGlwZXJtYWlsL2Npc2NvLW5zcC8K

--===============4985941281442906395==--