<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ACS 4.2 group settings and AAA help in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-4-2-group-settings-and-aaa-help/m-p/2298759#M108234</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I solved it. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was able to use "aaa authentication enable default group tacacs local"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now I just need to know if there's anyway to configure the enable password for a group instead of user by user.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any suggestions!!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 15 Aug 2013 18:43:00 GMT</pubDate>
    <dc:creator>ejeangilles</dc:creator>
    <dc:date>2013-08-15T18:43:00Z</dc:date>
    <item>
      <title>ACS 4.2 group settings and AAA help</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-4-2-group-settings-and-aaa-help/m-p/2298758#M108179</link>
      <description>&lt;P&gt;I 've been trying to figure this out for a few days and maybe you guys can help me out. I'm trying to get more familiar with AAA and this what I'm trying to accomplish.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-I have a cisco switch and I also have ACS 4.2 running on windows 2003 and that's authenticating with a 2003 active directory server which is working ok.&lt;/P&gt;&lt;P&gt;-Level 1 group that can only run those user level commands and they should not go into enable or configuration terminal&lt;/P&gt;&lt;P&gt;-Level 15 group has access to everything.&lt;/P&gt;&lt;P&gt;-Level 1 and Level 15 groups are expecting to login with the AD credentials at first which drops them into user mode. &lt;/P&gt;&lt;P&gt;-Only level 15 group should be able to go into enable mode.&lt;/P&gt;&lt;P&gt;-I want specify the "Enable" password within TACACS and not use the "enable password" command in the IOS. &lt;/P&gt;&lt;P&gt;-I don't want to use local usernames and passwords except for a backway to get in.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried to configure the "Max privilege for any client" to level 1 or 15 per group but that doesn't seem to work.&lt;/P&gt;&lt;P&gt;This is bascially what I have so far.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;aaa new-model&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;aaa authentication login default group tacacs+ local&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;username admin privilege 15 password 0 xxxx&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you guy tell me what I'm missing?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 03:46:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-4-2-group-settings-and-aaa-help/m-p/2298758#M108179</guid>
      <dc:creator>ejeangilles</dc:creator>
      <dc:date>2019-03-11T03:46:34Z</dc:date>
    </item>
    <item>
      <title>ACS 4.2 group settings and AAA help</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-4-2-group-settings-and-aaa-help/m-p/2298759#M108234</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I solved it. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was able to use "aaa authentication enable default group tacacs local"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now I just need to know if there's anyway to configure the enable password for a group instead of user by user.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any suggestions!!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Aug 2013 18:43:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-4-2-group-settings-and-aaa-help/m-p/2298759#M108234</guid>
      <dc:creator>ejeangilles</dc:creator>
      <dc:date>2013-08-15T18:43:00Z</dc:date>
    </item>
  </channel>
</rss>

