<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic need to allow single command by command set in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/need-to-allow-single-command-by-command-set/m-p/2021820#M158124</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hie Tarik&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sorry for late reply &lt;/P&gt;&lt;P&gt;below is the aaa configuration i have done &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;aaa authentication login default group tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authentication enable default enable&lt;/P&gt;&lt;P&gt;aaa authorization exec default group tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authorization commands 15 default group tacacs+ local&lt;/P&gt;&lt;P&gt;aaa accounting exec default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting commands 15 default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is a default configuration in authorization profile, I haven't changed any thing there.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have attched the command set snap, Please find it.&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/0/0/2/107200-ACS_1.JPG" class="jive-image" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 09 Oct 2012 11:59:25 GMT</pubDate>
    <dc:creator>Harshad Patil</dc:creator>
    <dc:date>2012-10-09T11:59:25Z</dc:date>
    <item>
      <title>need to allow single command by command set</title>
      <link>https://community.cisco.com/t5/network-access-control/need-to-allow-single-command-by-command-set/m-p/2021818#M158080</link>
      <description>&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;I have ACS 5.1, I have created a user with privilege 15. I need to allow a single command buy command set.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;I have configured command set. in command set setting i have unchecked "Permit any command that is not in the table below"&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;and added command as below.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;Grant&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Command&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Argument&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;Permit&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; clear&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; counters&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;its allowing me&amp;nbsp; to run clear counters, &lt;/P&gt;&lt;P&gt;good is its not allowing to &lt;SPAN style="background-color: #ffffff; font-family: Arial, verdana, sans-serif; font-size: 12px;"&gt;show run and conf t commands&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;And problem is i can run reload command also even show interface commands&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;I just want to allow clear counters command only. Am i missing anything plz help.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 02:38:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/need-to-allow-single-command-by-command-set/m-p/2021818#M158080</guid>
      <dc:creator>Harshad Patil</dc:creator>
      <dc:date>2019-03-11T02:38:07Z</dc:date>
    </item>
    <item>
      <title>need to allow single command by command set</title>
      <link>https://community.cisco.com/t5/network-access-control/need-to-allow-single-command-by-command-set/m-p/2021819#M158101</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you paste the show run | inc aaa, also can you post the results in the tacacs authenticaiton report, which shows which command set the user is being mapped. Please post a screenshot of the authorization profile. Then finally can you post a screenshot of the command set you configured.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Oct 2012 16:47:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/need-to-allow-single-command-by-command-set/m-p/2021819#M158101</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-10-04T16:47:21Z</dc:date>
    </item>
    <item>
      <title>need to allow single command by command set</title>
      <link>https://community.cisco.com/t5/network-access-control/need-to-allow-single-command-by-command-set/m-p/2021820#M158124</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hie Tarik&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sorry for late reply &lt;/P&gt;&lt;P&gt;below is the aaa configuration i have done &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;aaa authentication login default group tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authentication enable default enable&lt;/P&gt;&lt;P&gt;aaa authorization exec default group tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authorization commands 15 default group tacacs+ local&lt;/P&gt;&lt;P&gt;aaa accounting exec default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting commands 15 default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is a default configuration in authorization profile, I haven't changed any thing there.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have attched the command set snap, Please find it.&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/0/0/2/107200-ACS_1.JPG" class="jive-image" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Oct 2012 11:59:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/need-to-allow-single-command-by-command-set/m-p/2021820#M158124</guid>
      <dc:creator>Harshad Patil</dc:creator>
      <dc:date>2012-10-09T11:59:25Z</dc:date>
    </item>
  </channel>
</rss>

