<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ACS configuration for Authorization in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-configuration-for-authorization/m-p/2384374#M159117</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;kindly find the link to below for the proper configuration sample for authorization. &lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-wiki-small" href="https://community.cisco.com/docs/DOC-16027"&gt;https://supportforums.cisco.com/docs/DOC-16027&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 01 Nov 2013 22:33:41 GMT</pubDate>
    <dc:creator>blenka</dc:creator>
    <dc:date>2013-11-01T22:33:41Z</dc:date>
    <item>
      <title>ACS configuration for Authorization</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-configuration-for-authorization/m-p/2384365#M159108</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm checking if some can help me out with a specific configuration.&lt;/P&gt;&lt;P&gt;We are deploying the Cisco ACS in our network and have configured for the Authorization AAA to our AD.&lt;/P&gt;&lt;P&gt;Now what we want to do is to give the technician normal access for monitoring an troubleshooting&amp;nbsp; which is only certain commands show* and allow them to use the enabled password to gain access to the conf t and other commands.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have trying to give them:&lt;/P&gt;&lt;P&gt;Shell profiles Default Privilege: Static 10;&lt;/P&gt;&lt;P&gt;Maximum Privilege:&amp;nbsp; &lt;A&gt;&lt;/A&gt;&lt;A&gt;&lt;/A&gt;Static 10;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Command Sets:&lt;/P&gt;&lt;P&gt;Permit Show *&lt;/P&gt;&lt;P&gt;Deny Conf*&lt;/P&gt;&lt;P&gt;Deny Wr*&lt;/P&gt;&lt;P&gt;Deny Rel*&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;While do this if gives the message correctly when using conf t and give a message "Command Authorazation failed, but when typing enable not is happening.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What should be done to correctly configure this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Patrick&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 04:02:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-configuration-for-authorization/m-p/2384365#M159108</guid>
      <dc:creator>patrick.girigorie</dc:creator>
      <dc:date>2019-03-11T04:02:59Z</dc:date>
    </item>
    <item>
      <title>ACS configuration for Authorization</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-configuration-for-authorization/m-p/2384366#M159109</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Did you find this document in your research? If no then you may want to take a look at it.&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/products/ps9911/products_configuration_example09186a0080bc8514.shtml"&gt;http://www.cisco.com/en/US/products/ps9911/products_configuration_example09186a0080bc8514.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, please set the maximum privilege to 15 before you test command authorization.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;~BR &lt;BR /&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt;**Do rate helpful posts**&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Oct 2013 16:48:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-configuration-for-authorization/m-p/2384366#M159109</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-10-30T16:48:00Z</dc:date>
    </item>
    <item>
      <title>ACS configuration for Authorization</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-configuration-for-authorization/m-p/2384367#M159110</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Jatin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the reply, Yes i have tried this but the problem that I want the limited access engineer to make use of the enable password for the to gain access to the conf t.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So same user who normally has limited access will change his priv level by using the enable password (or something else) for them to gain the total access for configuration of the equipement.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Patrick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Oct 2013 18:21:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-configuration-for-authorization/m-p/2384367#M159110</guid>
      <dc:creator>patrick.girigorie</dc:creator>
      <dc:date>2013-10-30T18:21:07Z</dc:date>
    </item>
    <item>
      <title>ACS configuration for Authorization</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-configuration-for-authorization/m-p/2384368#M159111</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Could you please share the output of "show run | in aaa" in your next reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;~BR &lt;BR /&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt;**Do rate helpful posts**&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 Oct 2013 12:37:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-configuration-for-authorization/m-p/2384368#M159111</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-10-31T12:37:40Z</dc:date>
    </item>
    <item>
      <title>ACS configuration for Authorization</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-configuration-for-authorization/m-p/2384369#M159112</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jatin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes of course:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;See below.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authentication login default group tacacs+&lt;/P&gt;&lt;P&gt;aaa authentication enable default group tacacs+ enable&lt;/P&gt;&lt;P&gt;aaa authorization config-commands&lt;/P&gt;&lt;P&gt;aaa authorization exec default group tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authorization commands 15 default group tacacs+ local&lt;SPAN id="mce_marker"&gt; &lt;/SPAN&gt;aaa authentication login default group tacacs+&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Patrick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 Oct 2013 14:04:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-configuration-for-authorization/m-p/2384369#M159112</guid>
      <dc:creator>patrick.girigorie</dc:creator>
      <dc:date>2013-10-31T14:04:47Z</dc:date>
    </item>
    <item>
      <title>ACS configuration for Authorization</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-configuration-for-authorization/m-p/2384370#M159113</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would also suggest you to have complete configuration for command authorization so add these two commands as well.&lt;/P&gt;&lt;P&gt;aaa authorization commands 0 default group tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authorization commands 1 default group tacacs+ local&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In order to present enable password mode to your technician (read-pnly users) you have to configure ACS like this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/5/4/9/163945-enable.PNG" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/4/6/9/163964-show.PNG" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;let me know how it goes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;~BR &lt;BR /&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt;**Do rate helpful posts**&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 Oct 2013 15:29:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-configuration-for-authorization/m-p/2384370#M159113</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-10-31T15:29:43Z</dc:date>
    </item>
    <item>
      <title>ACS configuration for Authorization</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-configuration-for-authorization/m-p/2384371#M159114</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jatin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Ok almost there it is working but I cannot get the show run to work when in view-only and additionally the configured enable password on the router is not working anymore.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you help with this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Patrick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 Oct 2013 19:03:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-configuration-for-authorization/m-p/2384371#M159114</guid>
      <dc:creator>patrick.girigorie</dc:creator>
      <dc:date>2013-10-31T19:03:54Z</dc:date>
    </item>
    <item>
      <title>ACS configuration for Authorization</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-configuration-for-authorization/m-p/2384372#M159115</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;so you're saying when you execute "show run", it says command authorization failed. If yes then I would be interested to see the syntax that you've defined on ACS under command sets. Also why enable authentication is not going to local database i.e router because in your configuration, you've defined that it should go and check enable password tacacs server first however if it doesn't work check locally defined enable password. Since your tacacs server is up and running, we have to use enable password from tacacs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is what you have.&lt;/P&gt;&lt;P&gt;aaa authentication enable default group tacacs+ enable&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;~BR &lt;BR /&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt;**Do rate helpful posts**&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 Oct 2013 21:18:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-configuration-for-authorization/m-p/2384372#M159115</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-10-31T21:18:06Z</dc:date>
    </item>
    <item>
      <title>ACS configuration for Authorization</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-configuration-for-authorization/m-p/2384373#M159116</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jatin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope it's clear the image.&lt;/P&gt;&lt;P&gt;Just changed the enable to local only.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Patrick&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/2/1/0/164012-enable%20not%20going.jpg" class="jive-image" /&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/5/0/0/164005-conf%20ACS.jpg" class="jive-image" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 Oct 2013 22:49:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-configuration-for-authorization/m-p/2384373#M159116</guid>
      <dc:creator>patrick.girigorie</dc:creator>
      <dc:date>2013-10-31T22:49:31Z</dc:date>
    </item>
    <item>
      <title>ACS configuration for Authorization</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-configuration-for-authorization/m-p/2384374#M159117</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;kindly find the link to below for the proper configuration sample for authorization. &lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-wiki-small" href="https://community.cisco.com/docs/DOC-16027"&gt;https://supportforums.cisco.com/docs/DOC-16027&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Nov 2013 22:33:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-configuration-for-authorization/m-p/2384374#M159117</guid>
      <dc:creator>blenka</dc:creator>
      <dc:date>2013-11-01T22:33:41Z</dc:date>
    </item>
    <item>
      <title>ACS configuration for Authorization</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-configuration-for-authorization/m-p/2384375#M159118</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This didn't seem like it was design for one user to get all the priv for Show command. So we decided to use two users instead one with priv 15 with no wr mem or conf t and another with priv 15 with no restrictions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Patrick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Nov 2013 11:42:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-configuration-for-authorization/m-p/2384375#M159118</guid>
      <dc:creator>patrick.girigorie</dc:creator>
      <dc:date>2013-11-19T11:42:13Z</dc:date>
    </item>
  </channel>
</rss>

