<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Privilege Level for Tacacs Account in Nexus 7000 in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/privilege-level-for-tacacs-account-in-nexus-7000/m-p/2344926#M110885</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have configured the Tacacs (ACS 4.2v) on Nexus 7000 (as mentioned below) and works fine but unlike IOS (6509) It's doesn't prompt that you are in userexec mode (&amp;gt;) and then need to type enable and password for full privilege.&lt;/P&gt;&lt;P&gt;In n7k when I entered into "configure terminal" It won't allow me to access other commands.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How to login into level 15 privilege mode after authenticating from tacacs&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(config)# show running-config tacacs+&lt;/P&gt;&lt;P&gt;tacacs-server key 7 "xxxxx"&lt;/P&gt;&lt;P&gt;tacacs-server host x.x.x.x key 7 "xxxx" &lt;/P&gt;&lt;P&gt;aaa group server tacacs+ TacServer &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; server x.x.x.x (same ip as tacacs-server host)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; use-vrf management&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; source-interface Vlan2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(config)# show running-config aaa&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authentication login default group TacServer &lt;/P&gt;&lt;P&gt;aaa authentication login console local &lt;/P&gt;&lt;P&gt;aaa user default-role&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here below are the commands accessible in "Terminal" currently&lt;/P&gt;&lt;P&gt;(config)# ?&lt;/P&gt;&lt;P&gt;&amp;nbsp; no&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Negate a command or set its defaults&lt;/P&gt;&lt;P&gt;&amp;nbsp; username&amp;nbsp; Configure user information.&lt;/P&gt;&lt;P&gt;&amp;nbsp; end&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Go to exec mode&lt;/P&gt;&lt;P&gt;&amp;nbsp; exit&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Exit from command interpreter&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;isb.n7k-dcn-agg-1-sw(config)# &lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 03:50:11 GMT</pubDate>
    <dc:creator>qasey_shiz</dc:creator>
    <dc:date>2019-03-11T03:50:11Z</dc:date>
    <item>
      <title>Privilege Level for Tacacs Account in Nexus 7000</title>
      <link>https://community.cisco.com/t5/network-access-control/privilege-level-for-tacacs-account-in-nexus-7000/m-p/2344926#M110885</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have configured the Tacacs (ACS 4.2v) on Nexus 7000 (as mentioned below) and works fine but unlike IOS (6509) It's doesn't prompt that you are in userexec mode (&amp;gt;) and then need to type enable and password for full privilege.&lt;/P&gt;&lt;P&gt;In n7k when I entered into "configure terminal" It won't allow me to access other commands.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How to login into level 15 privilege mode after authenticating from tacacs&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(config)# show running-config tacacs+&lt;/P&gt;&lt;P&gt;tacacs-server key 7 "xxxxx"&lt;/P&gt;&lt;P&gt;tacacs-server host x.x.x.x key 7 "xxxx" &lt;/P&gt;&lt;P&gt;aaa group server tacacs+ TacServer &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; server x.x.x.x (same ip as tacacs-server host)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; use-vrf management&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; source-interface Vlan2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(config)# show running-config aaa&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authentication login default group TacServer &lt;/P&gt;&lt;P&gt;aaa authentication login console local &lt;/P&gt;&lt;P&gt;aaa user default-role&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here below are the commands accessible in "Terminal" currently&lt;/P&gt;&lt;P&gt;(config)# ?&lt;/P&gt;&lt;P&gt;&amp;nbsp; no&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Negate a command or set its defaults&lt;/P&gt;&lt;P&gt;&amp;nbsp; username&amp;nbsp; Configure user information.&lt;/P&gt;&lt;P&gt;&amp;nbsp; end&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Go to exec mode&lt;/P&gt;&lt;P&gt;&amp;nbsp; exit&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Exit from command interpreter&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;isb.n7k-dcn-agg-1-sw(config)# &lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 03:50:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/privilege-level-for-tacacs-account-in-nexus-7000/m-p/2344926#M110885</guid>
      <dc:creator>qasey_shiz</dc:creator>
      <dc:date>2019-03-11T03:50:11Z</dc:date>
    </item>
    <item>
      <title>Privilege Level for Tacacs Account in Nexus 7000</title>
      <link>https://community.cisco.com/t5/network-access-control/privilege-level-for-tacacs-account-in-nexus-7000/m-p/2344927#M110947</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm not 100% sure about ACS 4.2, as i have only tried this in ACS 5.x, but there you needed to send a shell profile back to the nexus, with this line for exec mode :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;CODE&gt;&lt;/CODE&gt;&lt;CODE&gt;shell:roles=&lt;/CODE&gt;&lt;CODE&gt;"network-admin"&lt;/CODE&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Sep 2013 18:24:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/privilege-level-for-tacacs-account-in-nexus-7000/m-p/2344927#M110947</guid>
      <dc:creator>jan.nielsen</dc:creator>
      <dc:date>2013-09-03T18:24:28Z</dc:date>
    </item>
    <item>
      <title>Re: Privilege Level for Tacacs Account in Nexus 7000</title>
      <link>https://community.cisco.com/t5/network-access-control/privilege-level-for-tacacs-account-in-nexus-7000/m-p/2344928#M110975</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jan.nielsen&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Issue is resolved but by another way.&lt;/P&gt;&lt;P&gt;I have found the same resolution too of custom attirbute command but the Custom attribute Option for shell command wasn't available in ACS v4.2, so after enabling shell for users and by clicking exec--&amp;gt; Shell Exec and enabling priviledge level 15 in the same box of Shell options, It start working without any command&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Sep 2013 03:06:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/privilege-level-for-tacacs-account-in-nexus-7000/m-p/2344928#M110975</guid>
      <dc:creator>qasey_shiz</dc:creator>
      <dc:date>2013-09-04T03:06:47Z</dc:date>
    </item>
  </channel>
</rss>

