<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Allow some show commands in AAA Authorization Set in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/allow-some-show-commands-in-aaa-authorization-set/m-p/2272469#M112253</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Changing it to 'deny running-config' does the exact same thing.&amp;nbsp; It looks like it's seeing the 'show running-config' then stoping on that before anything else.&amp;nbsp; I've tried adding 'permit run interface' in ACS and same thing.&amp;nbsp; Other AAA Authorization set commands work just fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the switch (its a 2960G-8TC-K) running 12.2(58)SE2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa group server tacacs+ SHS&lt;/P&gt;&lt;P&gt; server 10.10.11.200&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa authentication login verifyme group &lt;SPAN style="font-size: 10pt;"&gt;TACACS+ &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;local&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;aaa authorization config-commands&lt;/P&gt;&lt;P&gt;aaa authorization exec verifyme group &lt;SPAN style="font-size: 10pt;"&gt;TACACS+ &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;local&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;aaa authorization commands 0 default group TACACS+&lt;/P&gt;&lt;P&gt;aaa authorization commands 1 default group &lt;SPAN style="font-size: 10pt;"&gt;TACACS+&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;aaa authorization commands 15 default group TACACS+&lt;/P&gt;&lt;P&gt;aaa accounting send stop-record authentication failure&lt;/P&gt;&lt;P&gt;aaa accounting exec verifyme start-stop group TACACS+&lt;/P&gt;&lt;P&gt;aaa accounting commands 15 default start-stop group TACACS+&lt;/P&gt;&lt;P&gt;aaa accounting network verifyme start-stop group TACACS+&lt;/P&gt;&lt;P&gt;aaa accounting system default start-stop group TACACS+&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa session-id common&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Debugs!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jun 21 11:07:39: AAA: parse name=tty0 idb type=-1 tty=-1&lt;/P&gt;&lt;P&gt;Jun 21 11:07:39: AAA: name=tty0 flags=0x11 type=4 shelf=0 slot=0 adapter=0 port=0 channel=0&lt;/P&gt;&lt;P&gt;Jun 21 11:07:39: AAA/MEMORY: create_user (0x3A790DC) user='test' ruser='SGAVEJ01' ds0=0 port='tty0' rem_addr='async' authen_type=ASCII service=NONE priv=15 initial_task_id='0', vrf= (id=0)&lt;/P&gt;&lt;P&gt;Jun 21 11:07:39: tty0 AAA/AUTHOR/CMD (4105592267): Port='tty0' list='' service=CMD&lt;/P&gt;&lt;P&gt;Jun 21 11:07:39: AAA/AUTHOR/CMD: tty0 (4105592267) user='test'&lt;/P&gt;&lt;P&gt;Jun 21 11:07:39: tty0 AAA/AUTHOR/CMD (4105592267): send AV service=shell&lt;/P&gt;&lt;P&gt;Jun 21 11:07:39: tty0 AAA/AUTHOR/CMD (4105592267): send AV cmd=show&lt;/P&gt;&lt;P&gt;Jun 21 11:07:39: tty0 AAA/AUTHOR/CMD (4105592267): send AV cmd-arg=running-config&lt;/P&gt;&lt;P&gt;Jun 21 11:07:39: tty0 AAA/AUTHOR/CMD (4105592267): send AV cmd-arg=interface&lt;/P&gt;&lt;P&gt;Jun 21 11:07:39: tty0 AAA/AUTHOR/CMD (4105592267): send AV cmd-arg=GigabitEthernet&lt;/P&gt;&lt;P&gt;Jun 21 11:07:39: tty0 AAA/AUTHOR/CMD (4105592267): send AV cmd-arg=0/1&lt;/P&gt;&lt;P&gt;Jun 21 11:07:39: tty0 AAA/AUTHOR/CMD (4105592267): send AV cmd-arg=&lt;CR&gt;&lt;/CR&gt;&lt;/P&gt;&lt;P&gt;Jun 21 11:07:39: tty0 AAA/AUTHOR/CMD(4105592267): found list "default"&lt;/P&gt;&lt;P&gt;Jun 21 11:07:39: tty0 AAA/AUTHOR/CMD (4105592267): Method=TACACS+ (tacacs+)&lt;/P&gt;&lt;P&gt;Jun 21 11:07:39: AAA/AUTHOR/TAC+: (4105592267): user=test&lt;/P&gt;&lt;P&gt;Jun 21 11:07:39: AAA/AUTHOR/TAC+: (4105592267): send AV service=shell&lt;/P&gt;&lt;P&gt;Jun 21 11:07:39: AAA/AUTHOR/TAC+: (4105592267): send AV cmd=show&lt;/P&gt;&lt;P&gt;Jun 21 11:07:39: AAA/AUTHOR/TAC+: (4105592267): send AV cmd-arg=running-config&lt;/P&gt;&lt;P&gt;Jun 21 11:07:39: AAA/AUTHOR/TAC+: (4105592267): send AV cmd-arg=interface&lt;/P&gt;&lt;P&gt;Jun 21 11:07:39: AAA/AUTHOR/TAC+: (4105592267): send AV cmd-arg=GigabitEthernet&lt;/P&gt;&lt;P&gt;Jun 21 11:07:39: AAA/AUTHOR/TAC+: (4105592267): send AV cmd-arg=0/1&lt;/P&gt;&lt;P&gt;Jun 21 11:07:39: AAA/AUTHOR/TAC+: (4105592267): send AV cmd-arg=&lt;CR&gt;&lt;/CR&gt;&lt;/P&gt;&lt;P&gt;Jun 21 11:07:39: TAC+: Using default tacacs server-group "TACACS+" list.&lt;/P&gt;&lt;P&gt;Jun 21 11:07:39: TAC+: Opening TCP/IP to 10.10.11.200/49 timeout=5&lt;/P&gt;&lt;P&gt;Jun 21 11:07:39: TAC+: Opened TCP/IP handle 0x3A41210 to 10.10.11.200/49 using source 10.40.0.14&lt;/P&gt;&lt;P&gt;Jun 21 11:07:39: TAC+: 10.10.11.200 (4105592267) AUTHOR/START queued&lt;/P&gt;&lt;P&gt;Jun 21 11:07:39: TAC+: (4105592267) AUTHOR/START processed&lt;/P&gt;&lt;P&gt;Jun 21 11:07:39: TAC+: (-189375029): received author response status = FAIL&lt;/P&gt;&lt;P&gt;Jun 21 11:07:39: TAC+: Closing TCP/IP 0x3A41210 connection to 10.10.11.200/49&lt;/P&gt;&lt;P&gt;Jun 21 11:07:39: AAA/AUTHOR (4105592267): Post authorization status = FAIL&lt;/P&gt;&lt;P&gt;Jun 21 11:07:39: AAA/MEMORY: free_user (0x3A790DC) user='test' ruser='SGAVEJ01' port='tty0' rem_addr='async' authen_type=ASCII service=NONE priv=15 vrf= (id=0)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 21 Jun 2013 18:12:52 GMT</pubDate>
    <dc:creator>Erik</dc:creator>
    <dc:date>2013-06-21T18:12:52Z</dc:date>
    <item>
      <title>Allow some show commands in AAA Authorization Set</title>
      <link>https://community.cisco.com/t5/network-access-control/allow-some-show-commands-in-aaa-authorization-set/m-p/2272467#M112243</link>
      <description>&lt;P&gt;I'm working on creating AAA authorization sets for our environment and ran into a question!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'd like to be able to enable ALL show commands except 'show run'.&amp;nbsp; I would also like to enable 'show run interface'.&amp;nbsp; I've figured out how to enable all show commands and disable show run.&amp;nbsp; The problem I'm finding is that since 'show run interface' is a subset of 'show run' it seems to disable.&amp;nbsp; Even if I try to explicitly enable it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a way to disable 'show run' but enable all other show commands and 'show run interface' with a AAA authorization set?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACS Version 4.1.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Command set is configured:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/legacy/8/3/9/142938-AAA_Auth.jpg" alt="AAA_Auth.jpg" class="jive-image-thumbnail jive-image" width="450" /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 03:34:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/allow-some-show-commands-in-aaa-authorization-set/m-p/2272467#M112243</guid>
      <dc:creator>Erik</dc:creator>
      <dc:date>2019-03-11T03:34:25Z</dc:date>
    </item>
    <item>
      <title>Allow some show commands in AAA Authorization Set</title>
      <link>https://community.cisco.com/t5/network-access-control/allow-some-show-commands-in-aaa-authorization-set/m-p/2272468#M112248</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;try to use &lt;STRONG&gt;deny running-config&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In case it doesn't work, please get the "debug aaa authorization" and "debug tacacs"&lt;/P&gt;&lt;P&gt;what is your IOS side config?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jatin Katyal &lt;BR /&gt; - Do rate helpful posts -&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Jun 2013 17:53:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/allow-some-show-commands-in-aaa-authorization-set/m-p/2272468#M112248</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-06-21T17:53:20Z</dc:date>
    </item>
    <item>
      <title>Allow some show commands in AAA Authorization Set</title>
      <link>https://community.cisco.com/t5/network-access-control/allow-some-show-commands-in-aaa-authorization-set/m-p/2272469#M112253</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Changing it to 'deny running-config' does the exact same thing.&amp;nbsp; It looks like it's seeing the 'show running-config' then stoping on that before anything else.&amp;nbsp; I've tried adding 'permit run interface' in ACS and same thing.&amp;nbsp; Other AAA Authorization set commands work just fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the switch (its a 2960G-8TC-K) running 12.2(58)SE2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa group server tacacs+ SHS&lt;/P&gt;&lt;P&gt; server 10.10.11.200&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa authentication login verifyme group &lt;SPAN style="font-size: 10pt;"&gt;TACACS+ &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;local&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;aaa authorization config-commands&lt;/P&gt;&lt;P&gt;aaa authorization exec verifyme group &lt;SPAN style="font-size: 10pt;"&gt;TACACS+ &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;local&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;aaa authorization commands 0 default group TACACS+&lt;/P&gt;&lt;P&gt;aaa authorization commands 1 default group &lt;SPAN style="font-size: 10pt;"&gt;TACACS+&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;aaa authorization commands 15 default group TACACS+&lt;/P&gt;&lt;P&gt;aaa accounting send stop-record authentication failure&lt;/P&gt;&lt;P&gt;aaa accounting exec verifyme start-stop group TACACS+&lt;/P&gt;&lt;P&gt;aaa accounting commands 15 default start-stop group TACACS+&lt;/P&gt;&lt;P&gt;aaa accounting network verifyme start-stop group TACACS+&lt;/P&gt;&lt;P&gt;aaa accounting system default start-stop group TACACS+&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa session-id common&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Debugs!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jun 21 11:07:39: AAA: parse name=tty0 idb type=-1 tty=-1&lt;/P&gt;&lt;P&gt;Jun 21 11:07:39: AAA: name=tty0 flags=0x11 type=4 shelf=0 slot=0 adapter=0 port=0 channel=0&lt;/P&gt;&lt;P&gt;Jun 21 11:07:39: AAA/MEMORY: create_user (0x3A790DC) user='test' ruser='SGAVEJ01' ds0=0 port='tty0' rem_addr='async' authen_type=ASCII service=NONE priv=15 initial_task_id='0', vrf= (id=0)&lt;/P&gt;&lt;P&gt;Jun 21 11:07:39: tty0 AAA/AUTHOR/CMD (4105592267): Port='tty0' list='' service=CMD&lt;/P&gt;&lt;P&gt;Jun 21 11:07:39: AAA/AUTHOR/CMD: tty0 (4105592267) user='test'&lt;/P&gt;&lt;P&gt;Jun 21 11:07:39: tty0 AAA/AUTHOR/CMD (4105592267): send AV service=shell&lt;/P&gt;&lt;P&gt;Jun 21 11:07:39: tty0 AAA/AUTHOR/CMD (4105592267): send AV cmd=show&lt;/P&gt;&lt;P&gt;Jun 21 11:07:39: tty0 AAA/AUTHOR/CMD (4105592267): send AV cmd-arg=running-config&lt;/P&gt;&lt;P&gt;Jun 21 11:07:39: tty0 AAA/AUTHOR/CMD (4105592267): send AV cmd-arg=interface&lt;/P&gt;&lt;P&gt;Jun 21 11:07:39: tty0 AAA/AUTHOR/CMD (4105592267): send AV cmd-arg=GigabitEthernet&lt;/P&gt;&lt;P&gt;Jun 21 11:07:39: tty0 AAA/AUTHOR/CMD (4105592267): send AV cmd-arg=0/1&lt;/P&gt;&lt;P&gt;Jun 21 11:07:39: tty0 AAA/AUTHOR/CMD (4105592267): send AV cmd-arg=&lt;CR&gt;&lt;/CR&gt;&lt;/P&gt;&lt;P&gt;Jun 21 11:07:39: tty0 AAA/AUTHOR/CMD(4105592267): found list "default"&lt;/P&gt;&lt;P&gt;Jun 21 11:07:39: tty0 AAA/AUTHOR/CMD (4105592267): Method=TACACS+ (tacacs+)&lt;/P&gt;&lt;P&gt;Jun 21 11:07:39: AAA/AUTHOR/TAC+: (4105592267): user=test&lt;/P&gt;&lt;P&gt;Jun 21 11:07:39: AAA/AUTHOR/TAC+: (4105592267): send AV service=shell&lt;/P&gt;&lt;P&gt;Jun 21 11:07:39: AAA/AUTHOR/TAC+: (4105592267): send AV cmd=show&lt;/P&gt;&lt;P&gt;Jun 21 11:07:39: AAA/AUTHOR/TAC+: (4105592267): send AV cmd-arg=running-config&lt;/P&gt;&lt;P&gt;Jun 21 11:07:39: AAA/AUTHOR/TAC+: (4105592267): send AV cmd-arg=interface&lt;/P&gt;&lt;P&gt;Jun 21 11:07:39: AAA/AUTHOR/TAC+: (4105592267): send AV cmd-arg=GigabitEthernet&lt;/P&gt;&lt;P&gt;Jun 21 11:07:39: AAA/AUTHOR/TAC+: (4105592267): send AV cmd-arg=0/1&lt;/P&gt;&lt;P&gt;Jun 21 11:07:39: AAA/AUTHOR/TAC+: (4105592267): send AV cmd-arg=&lt;CR&gt;&lt;/CR&gt;&lt;/P&gt;&lt;P&gt;Jun 21 11:07:39: TAC+: Using default tacacs server-group "TACACS+" list.&lt;/P&gt;&lt;P&gt;Jun 21 11:07:39: TAC+: Opening TCP/IP to 10.10.11.200/49 timeout=5&lt;/P&gt;&lt;P&gt;Jun 21 11:07:39: TAC+: Opened TCP/IP handle 0x3A41210 to 10.10.11.200/49 using source 10.40.0.14&lt;/P&gt;&lt;P&gt;Jun 21 11:07:39: TAC+: 10.10.11.200 (4105592267) AUTHOR/START queued&lt;/P&gt;&lt;P&gt;Jun 21 11:07:39: TAC+: (4105592267) AUTHOR/START processed&lt;/P&gt;&lt;P&gt;Jun 21 11:07:39: TAC+: (-189375029): received author response status = FAIL&lt;/P&gt;&lt;P&gt;Jun 21 11:07:39: TAC+: Closing TCP/IP 0x3A41210 connection to 10.10.11.200/49&lt;/P&gt;&lt;P&gt;Jun 21 11:07:39: AAA/AUTHOR (4105592267): Post authorization status = FAIL&lt;/P&gt;&lt;P&gt;Jun 21 11:07:39: AAA/MEMORY: free_user (0x3A790DC) user='test' ruser='SGAVEJ01' port='tty0' rem_addr='async' authen_type=ASCII service=NONE priv=15 vrf= (id=0)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Jun 2013 18:12:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/allow-some-show-commands-in-aaa-authorization-set/m-p/2272469#M112253</guid>
      <dc:creator>Erik</dc:creator>
      <dc:date>2013-06-21T18:12:52Z</dc:date>
    </item>
    <item>
      <title>Allow some show commands in AAA Authorization Set</title>
      <link>https://community.cisco.com/t5/network-access-control/allow-some-show-commands-in-aaa-authorization-set/m-p/2272470#M112265</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;try out the following it will work definnately:-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;permit run interface&lt;/P&gt;&lt;P&gt;deny all run&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;please apply in the particular order only....&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 01 Jul 2013 03:30:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/allow-some-show-commands-in-aaa-authorization-set/m-p/2272470#M112265</guid>
      <dc:creator>harvisin</dc:creator>
      <dc:date>2013-07-01T03:30:34Z</dc:date>
    </item>
    <item>
      <title>Allow some show commands in AAA Authorization Set</title>
      <link>https://community.cisco.com/t5/network-access-control/allow-some-show-commands-in-aaa-authorization-set/m-p/2272471#M112279</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I tried setting it up this way, same issue.&amp;nbsp; If I set it up that way and test it, the interfaces still will not show (nor will anything else).&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SGAVEJ01#show run&lt;/P&gt;&lt;P&gt;Command authorization failed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SGAVEJ01#sh run interface gi0/1&lt;/P&gt;&lt;P&gt;Command authorization failed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/8/9/4/144498-ACS_Show.jpg" class="jive-image" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Jul 2013 15:43:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/allow-some-show-commands-in-aaa-authorization-set/m-p/2272471#M112279</guid>
      <dc:creator>Erik</dc:creator>
      <dc:date>2013-07-04T15:43:38Z</dc:date>
    </item>
  </channel>
</rss>

