<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Configure authorization on tac_plus (Tacacs+) in Switching</title>
    <link>https://community.cisco.com/t5/switching/configure-authorization-on-tac-plus-tacacs/m-p/4076836#M485769</link>
    <description>Hi&lt;BR /&gt;&lt;BR /&gt;Can you try changing the service level to 15 instead of 0?&lt;BR /&gt;&lt;BR /&gt;</description>
    <pubDate>Thu, 30 Apr 2020 02:55:48 GMT</pubDate>
    <dc:creator>Francesco Molino</dc:creator>
    <dc:date>2020-04-30T02:55:48Z</dc:date>
    <item>
      <title>Configure authorization on tac_plus (Tacacs+)</title>
      <link>https://community.cisco.com/t5/switching/configure-authorization-on-tac-plus-tacacs/m-p/4076821#M485768</link>
      <description>&lt;P&gt;group = netsupport {&lt;BR /&gt;default service = deny&lt;BR /&gt;acl = default&lt;BR /&gt;service = exec {&lt;BR /&gt;priv-lvl = 0&lt;BR /&gt;}&lt;BR /&gt;cmd = enable {&lt;BR /&gt;permit .*&lt;BR /&gt;}&lt;BR /&gt;cmd = show {&lt;BR /&gt;permit .*&lt;BR /&gt;}&lt;BR /&gt;cmd = exit {&lt;BR /&gt;permit .*&lt;BR /&gt;}&lt;BR /&gt;&lt;STRONG&gt;cmd = configure {&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;permit .*&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;}&lt;/STRONG&gt;&lt;BR /&gt;cmd = interface {&lt;BR /&gt;permit Ethernet.*&lt;BR /&gt;permit FastEthernet.*&lt;BR /&gt;permit GigabitEthernet.*&lt;BR /&gt;}&lt;BR /&gt;cmd = switchport {&lt;BR /&gt;permit "access vlan.*"&lt;BR /&gt;permit "voice vlan.*"&lt;BR /&gt;permit "trunk allowed vlan.*"&lt;BR /&gt;}&lt;BR /&gt;cmd = description {&lt;BR /&gt;permit .*&lt;BR /&gt;}&lt;BR /&gt;&lt;BR /&gt;cmd = no {&lt;BR /&gt;permit shutdown&lt;BR /&gt;}&lt;BR /&gt;}&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;above are permission I want to assign to support team to change configure on switch.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The problem is that when I allow them to use &lt;STRONG&gt;configure terminal&lt;/STRONG&gt; command.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;cmd = configure {&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;permit .*&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;}&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Then they can do any thing on interface such as shutdwon interface, change mode on interface etc... and bellow permission is not effect.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;cmd = switchport {&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;permit "access vlan.*"&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;permit "voice vlan.*"&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;permit "trunk allowed vlan.*"&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;} &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;as I want then can change VLAN only. I don't want to change port mode to access or trunk or shutdown vlan.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;any help will be appreciate.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks and regards,&lt;/P&gt;&lt;P&gt;Ratha&lt;/P&gt;</description>
      <pubDate>Thu, 30 Apr 2020 02:32:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/switching/configure-authorization-on-tac-plus-tacacs/m-p/4076821#M485768</guid>
      <dc:creator>ratha chum</dc:creator>
      <dc:date>2020-04-30T02:32:39Z</dc:date>
    </item>
    <item>
      <title>Re: Configure authorization on tac_plus (Tacacs+)</title>
      <link>https://community.cisco.com/t5/switching/configure-authorization-on-tac-plus-tacacs/m-p/4076836#M485769</link>
      <description>Hi&lt;BR /&gt;&lt;BR /&gt;Can you try changing the service level to 15 instead of 0?&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Thu, 30 Apr 2020 02:55:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/switching/configure-authorization-on-tac-plus-tacacs/m-p/4076836#M485769</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2020-04-30T02:55:48Z</dc:date>
    </item>
  </channel>
</rss>

