<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ACE Virtual context -TACACS authentication issue in Application Networking</title>
    <link>https://community.cisco.com/t5/application-networking/ace-virtual-context-tacacs-authentication-issue/m-p/1606793#M32697</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Parvees,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I also encounterd this when when configuring multiple contexts via ACS.&lt;/P&gt;&lt;P&gt;The solution is to use an asterik in the syntax after the context.&lt;/P&gt;&lt;P&gt;Without it you will receive network admin permissions as you have described below.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;shell:Admin*Admin default-domain &lt;BR /&gt;shell:Web*Admin default-domain&lt;BR /&gt;shell:Parties*Admin default-domain&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this solves your problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jack.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 29 Mar 2011 11:45:58 GMT</pubDate>
    <dc:creator>jackwikinski</dc:creator>
    <dc:date>2011-03-29T11:45:58Z</dc:date>
    <item>
      <title>ACE Virtual context -TACACS authentication issue</title>
      <link>https://community.cisco.com/t5/application-networking/ace-virtual-context-tacacs-authentication-issue/m-p/1606790#M32694</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have configured four context in ACE module.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am trying to authenticate individual context through ACS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Admin context authentication is working perfectly fine , and it is assigning the role of Admin for all the ACS users.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But when i am trying to authenticate other context , authentication part is working fine. but the user is not able to do any action other than show commands.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;when i checked the user-account ( show user-account), it is given the role of Network-Admin .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Admin Context Output:&lt;/P&gt;&lt;P&gt;---------------------------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;user:parvees.m&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; roles: Admin &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; domain: default-domain &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Context: Admin&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Context ABC output&lt;/P&gt;&lt;P&gt;-----------------------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;user:parvees.m&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; roles: Network-Admin&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; domain: default-domain &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Context: ABC&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help is highly appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;P&gt;Parvees M&lt;/P&gt;</description>
      <pubDate>Mon, 28 Mar 2011 10:26:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-virtual-context-tacacs-authentication-issue/m-p/1606790#M32694</guid>
      <dc:creator>parveesm123</dc:creator>
      <dc:date>2011-03-28T10:26:13Z</dc:date>
    </item>
    <item>
      <title>Re: ACE Virtual context -TACACS authentication issue</title>
      <link>https://community.cisco.com/t5/application-networking/ace-virtual-context-tacacs-authentication-issue/m-p/1606791#M32695</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Parvees,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What value did you set to shell attrribute on your ACS? It should be like:&lt;SPAN class="content"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="content"&gt;shell:&lt;/SPAN&gt;ABC&lt;SPAN class="content"&gt;=Admin&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you take a capture (wireshark with your tacas secret), do you see this attribute-value being sent?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Olivier&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Mar 2011 12:26:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-virtual-context-tacacs-authentication-issue/m-p/1606791#M32695</guid>
      <dc:creator>ohynderi</dc:creator>
      <dc:date>2011-03-28T12:26:26Z</dc:date>
    </item>
    <item>
      <title>Re: ACE Virtual context -TACACS authentication issue</title>
      <link>https://community.cisco.com/t5/application-networking/ace-virtual-context-tacacs-authentication-issue/m-p/1606792#M32696</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Oliver,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACS shell following command has been added and it worked for me&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;shell:ABC ="Admin default-domain"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;this has been repeated for all the domains... and it worked fine&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Parvees&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Mar 2011 13:34:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-virtual-context-tacacs-authentication-issue/m-p/1606792#M32696</guid>
      <dc:creator>parveesm123</dc:creator>
      <dc:date>2011-03-28T13:34:39Z</dc:date>
    </item>
    <item>
      <title>Re: ACE Virtual context -TACACS authentication issue</title>
      <link>https://community.cisco.com/t5/application-networking/ace-virtual-context-tacacs-authentication-issue/m-p/1606793#M32697</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Parvees,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I also encounterd this when when configuring multiple contexts via ACS.&lt;/P&gt;&lt;P&gt;The solution is to use an asterik in the syntax after the context.&lt;/P&gt;&lt;P&gt;Without it you will receive network admin permissions as you have described below.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;shell:Admin*Admin default-domain &lt;BR /&gt;shell:Web*Admin default-domain&lt;BR /&gt;shell:Parties*Admin default-domain&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this solves your problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jack.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Mar 2011 11:45:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-virtual-context-tacacs-authentication-issue/m-p/1606793#M32697</guid>
      <dc:creator>jackwikinski</dc:creator>
      <dc:date>2011-03-29T11:45:58Z</dc:date>
    </item>
  </channel>
</rss>

