<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: tacacs+ av pair, multiple roles in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/tacacs-av-pair-multiple-roles/m-p/2252664#M112310</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Where we have to configure and apply these settings. Could you please help.&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPad App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 23 Jul 2013 13:53:36 GMT</pubDate>
    <dc:creator>veer.pratap</dc:creator>
    <dc:date>2013-07-23T13:53:36Z</dc:date>
    <item>
      <title>tacacs+ av pair, multiple roles</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-av-pair-multiple-roles/m-p/2252662#M112271</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i m looking for a solution to have multiple roles for the tacacs+ config on the ACS. (4.1) so that i can have cli read-write access on Nexus switches and also read-write (admin) on the UCS manager which is webbased. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;is this possible? network-admin works on Nexus, but i m read-only if i log in to UCS manager. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ive tried somethings in an ACS test group , but it doesn t work yet.&amp;nbsp; &lt;/P&gt;&lt;P&gt;Does someone know if this is possible and what syntax is correct? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I ve tried different kinds of syntax like this, but no luck yet. Only the first entry works, in this case admin aaa&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;cisco-av-pair*shell:roles="admin&amp;nbsp; aaa" shell:roles="network-admin" &lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt; &lt;/EM&gt;&lt;/P&gt;&lt;P&gt;Like i said, not sure if this is even possible&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance!&amp;nbsp; &lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 03:33:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-av-pair-multiple-roles/m-p/2252662#M112271</guid>
      <dc:creator>Ton V Engelen</dc:creator>
      <dc:date>2019-03-11T03:33:36Z</dc:date>
    </item>
    <item>
      <title>tacacs+ av pair, multiple roles</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-av-pair-multiple-roles/m-p/2252663#M112287</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;already found the solution: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;this syntax does the trick&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;cisco-av-pair*shell:roles="network-admin&amp;nbsp; admin aaa"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_macro_emoticon" src="https://community.cisco.com/4.5.4/images/tiny_mce3/plugins/jiveemoticons/images/spacer.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Jun 2013 13:18:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-av-pair-multiple-roles/m-p/2252663#M112287</guid>
      <dc:creator>Ton V Engelen</dc:creator>
      <dc:date>2013-06-19T13:18:25Z</dc:date>
    </item>
    <item>
      <title>Re: tacacs+ av pair, multiple roles</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-av-pair-multiple-roles/m-p/2252664#M112310</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Where we have to configure and apply these settings. Could you please help.&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPad App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Jul 2013 13:53:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-av-pair-multiple-roles/m-p/2252664#M112310</guid>
      <dc:creator>veer.pratap</dc:creator>
      <dc:date>2013-07-23T13:53:36Z</dc:date>
    </item>
    <item>
      <title>Re: tacacs+ av pair, multiple roles</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-av-pair-multiple-roles/m-p/2252665#M112329</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Veer Pratap,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What ACS code are you using (ACS 4.x or ACS 5.x)?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Configuring ACS 5.x to authenticate Role Based Access Control (RBAC) users on a Nexus 5000 switch via TACACS&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-wiki-small" href="https://community.cisco.com/docs/DOC-14273"&gt;https://supportforums.cisco.com/docs/DOC-14273&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In case you're using ACS 4.x then you can configure this attribute per user or per group.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;First, go to Interface Configuration -&amp;gt; TACACS+ and enable "Display a window for each service selected in which you can enter customized TACACS+ attributes".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Next, go to the user or group where you want to grant this role and check the box next to "Shell (exec)" and in the custom attributes field below add the role assignment.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you will be authenticating on both NX-OS and UCS devices, use * instead of = to make the role optional or the UCS devices will fail authorization.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;~BR &lt;BR /&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt;**Do rate helpful posts**&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Jul 2013 14:08:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-av-pair-multiple-roles/m-p/2252665#M112329</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-07-23T14:08:48Z</dc:date>
    </item>
    <item>
      <title>Re: tacacs+ av pair, multiple roles</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-av-pair-multiple-roles/m-p/2252666#M112387</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Jatin, i have acs 4.1 ,i will just check and let you know if it works..&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPad App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Jul 2013 14:52:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-av-pair-multiple-roles/m-p/2252666#M112387</guid>
      <dc:creator>veer.pratap</dc:creator>
      <dc:date>2013-07-23T14:52:54Z</dc:date>
    </item>
    <item>
      <title>Re: tacacs+ av pair, multiple roles</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-av-pair-multiple-roles/m-p/2252667#M112400</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sure, let us know in case you need any further assistance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;~BR &lt;BR /&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt;**Do rate helpful posts**&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Jul 2013 14:57:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-av-pair-multiple-roles/m-p/2252667#M112400</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-07-23T14:57:15Z</dc:date>
    </item>
  </channel>
</rss>

