How to disable all the commands that run on privilege exec mode [ router# ] and only enable basic t-shoot commands like extended Ping & traceroute while a user PC has a remote telnet connection of a router?
I am not sure but as we do to assign access to L1 and L2 in ASA must be something near about be available in routers also .
We create privileged level and assign the required commands and allocate ...