<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ACS - ASA Authorization and Accounting in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-asa-authorization-and-accounting/m-p/1981664#M181517</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; user&amp;nbsp; "fwuser1" is tacacs or local user?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check is tacacs rechable?&lt;/P&gt;&lt;P&gt;﻿&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 10 Oct 2012 11:53:25 GMT</pubDate>
    <dc:creator>Omdatta pawar</dc:creator>
    <dc:date>2012-10-10T11:53:25Z</dc:date>
    <item>
      <title>ACS - ASA Authorization and Accounting</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-asa-authorization-and-accounting/m-p/1981653#M181500</link>
      <description>&lt;P style="margin-top: px; margin-bottom: px; line-height: normal;"&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-top: px; margin-bottom: px; line-height: normal;"&gt;I have some questions regarding authorization and accounting on ASA via ACS server&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;OL&gt;&lt;OL start="1"&gt;&lt;LI style="margin-top: px; margin-bottom: px; line-height: normal;"&gt;when I enable the command "aaa authorization&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; command " to control SSH users commands&amp;nbsp; I get locked out on&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; console then i have to configure the console , telnet , and enable to be&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; authenticated via tacacs too , is there any way to authorize SSH via&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; tacacs while keeping Console and telnet authenticated locally or even no&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; authentication ?&lt;/LI&gt;&lt;LI style="margin-top: px; margin-bottom: px; line-height: normal;"&gt;i issued&amp;nbsp; accounting command "aaa accounting&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; command TAC" on ASA but i noticed that the ACS just logs commands in&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; configuration mod "privilege 15 " not any show command or&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; privilege 1 , is there any way to fix this ?&lt;/LI&gt;&lt;LI&gt;does RADIUS support SHELL authorization ?&lt;/LI&gt;&lt;/OL&gt;&lt;/OL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for your support &lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 02:14:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-asa-authorization-and-accounting/m-p/1981653#M181500</guid>
      <dc:creator>eng.malak</dc:creator>
      <dc:date>2019-03-11T02:14:16Z</dc:date>
    </item>
    <item>
      <title>ACS - ASA Authorization and Accounting</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-asa-authorization-and-accounting/m-p/1981654#M181501</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1-)&lt;/P&gt;&lt;P&gt;You allow your username (or your group) full access in authorization in ACS server. Then you can fully configure your device. After finishing the device you can restrict access back to same user or group.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do not use the comand "aaa authorization console".&lt;/P&gt;&lt;P&gt;Make sure that the configuration under the "line console 0" is no configured for AAA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2-)&lt;/P&gt;&lt;P&gt;make sure to configure all levels for accounting.&lt;/P&gt;&lt;P&gt;aaa cccounting comands 0 &lt;METHOD name=""&gt; start-stop group &lt;GROPU-NAME&gt;&lt;/GROPU-NAME&gt;&lt;/METHOD&gt;&lt;/P&gt;&lt;P&gt;aaa cccounting comands 1 &lt;METHOD name=""&gt; start-stop group &lt;GROPU-NAME&gt;&lt;/GROPU-NAME&gt;&lt;/METHOD&gt;&lt;/P&gt;&lt;P&gt;aaa cccounting comands 15 &lt;METHOD name=""&gt; start-stop group &lt;GROPU-NAME&gt;&lt;/GROPU-NAME&gt;&lt;/METHOD&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think so far you only applied level 15.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3-)&lt;/P&gt;&lt;P&gt;RADIUS does not support shell authorization. This is only supported via TACACS+.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Amjad&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Jun 2012 06:36:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-asa-authorization-and-accounting/m-p/1981654#M181501</guid>
      <dc:creator>Amjad Abdullah</dc:creator>
      <dc:date>2012-06-26T06:36:31Z</dc:date>
    </item>
    <item>
      <title>ACS - ASA Authorization and Accounting</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-asa-authorization-and-accounting/m-p/1981655#M181502</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Amjad for your reply&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regarding point 1&amp;amp;2 i meant the authorization and accounting on the ASA not the IOS , thanks for point 3&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Jun 2012 06:44:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-asa-authorization-and-accounting/m-p/1981655#M181502</guid>
      <dc:creator>eng.malak</dc:creator>
      <dc:date>2012-06-26T06:44:56Z</dc:date>
    </item>
    <item>
      <title>ACS - ASA Authorization and Accounting</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-asa-authorization-and-accounting/m-p/1981656#M181503</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yup I understand it is on ASA. I never worked with ASA but I think they are almost the same from command line and you can access console and vty lines, no?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Jun 2012 06:54:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-asa-authorization-and-accounting/m-p/1981656#M181503</guid>
      <dc:creator>Amjad Abdullah</dc:creator>
      <dc:date>2012-06-26T06:54:46Z</dc:date>
    </item>
    <item>
      <title>ACS - ASA Authorization and Accounting</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-asa-authorization-and-accounting/m-p/1981657#M181504</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Unfortunately no , authorization is totally diffrent on ASA .&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Jun 2012 06:59:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-asa-authorization-and-accounting/m-p/1981657#M181504</guid>
      <dc:creator>eng.malak</dc:creator>
      <dc:date>2012-06-26T06:59:16Z</dc:date>
    </item>
    <item>
      <title>Re: ACS - ASA Authorization and Accounting</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-asa-authorization-and-accounting/m-p/1981658#M181506</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry for that.&lt;/P&gt;&lt;P&gt;Looking for the config guides I found that you may locally in ASA apply authorization levels to the users authenticating via local DB or via radius!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the link. I hope you find it useful:&amp;nbsp; &lt;A href="http://www.cisco.com/en/US/docs/security/asa/asa81/config/guide/mgaccess.html#wp1072168" rel="nofollow"&gt;http://www.cisco.com/en/US/docs/security/asa/asa81/config/guide/mgaccess.html#wp1072168&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Provide necessary level to the user you are logging with so that enablign authorization still authorize you with the commands you need.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Amjad&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Jun 2012 07:17:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-asa-authorization-and-accounting/m-p/1981658#M181506</guid>
      <dc:creator>Amjad Abdullah</dc:creator>
      <dc:date>2012-06-26T07:17:32Z</dc:date>
    </item>
    <item>
      <title>Re: ACS - ASA Authorization and Accounting</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-asa-authorization-and-accounting/m-p/1981659#M181507</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;1.] Unfortunately, there currently isn't any way to exclude command authorization from the&amp;nbsp; serial/ console or ssh users while having it apply to other access methods in case of ASA. Once you issue this command, it would be applicable for ALL methods like ssh,telnet,enable,http and console. This can be easily achieved in IOS (routers and switches) by creating a method list.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2.] When you configure the&lt;STRONG&gt; aaa accounting command&lt;/STRONG&gt; command, each command other than&amp;nbsp; &lt;STRONG&gt;show&lt;/STRONG&gt; commands entered by an administrator is recorded and sent to the accounting server or servers. This is a default behaviour on ASA. IOS does send/record all show commands on ACS/Tacacs.&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa81/command/ref/a1.html"&gt;http://www.cisco.com/en/US/docs/security/asa/asa81/command/ref/a1.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Jatin&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do rate helpful posts-&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Jun 2012 12:07:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-asa-authorization-and-accounting/m-p/1981659#M181507</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2012-06-26T12:07:53Z</dc:date>
    </item>
    <item>
      <title>ACS - ASA Authorization and Accounting</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-asa-authorization-and-accounting/m-p/1981660#M181508</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When you login on the device using console , the console user is "enable_15", if your console is lock due to authorization. Create user "enable_15" on ACS server with level 15 access. Also create a eanable_15 as local user too. This is way u will be able to access the device through console, no matter ACS is availabel or not.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Jul 2012 06:28:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-asa-authorization-and-accounting/m-p/1981660#M181508</guid>
      <dc:creator>Omdatta pawar</dc:creator>
      <dc:date>2012-07-30T06:28:33Z</dc:date>
    </item>
    <item>
      <title>ACS - ASA Authorization and Accounting</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-asa-authorization-and-accounting/m-p/1981661#M181510</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi&lt;/P&gt;&lt;P&gt;i configure the ASA as below but still ACS doesn't log for priv.1 commands m any idea ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authentication telnet console TAC &lt;/P&gt;&lt;P&gt;aaa authentication serial console TAC &lt;/P&gt;&lt;P&gt;aaa authentication enable console TAC &lt;/P&gt;&lt;P&gt;aaa authorization command TAC &lt;/P&gt;&lt;P&gt;aaa accounting telnet console TAC&lt;/P&gt;&lt;P&gt;aaa accounting command TAC&lt;/P&gt;&lt;P&gt;aaa accounting enable console TAC&lt;/P&gt;&lt;P&gt;aaa authorization exec authentication-server&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Oct 2012 11:07:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-asa-authorization-and-accounting/m-p/1981661#M181510</guid>
      <dc:creator>eng.malak</dc:creator>
      <dc:date>2012-10-10T11:07:45Z</dc:date>
    </item>
    <item>
      <title>ACS - ASA Authorization and Accounting</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-asa-authorization-and-accounting/m-p/1981662#M181512</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; create user on ASA with level 15 access, by default ASA create user with level 7 access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And apply a below command on ASA&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa-server TAC protocol tacacs+&lt;/P&gt;&lt;P&gt;aaa-server TAC (outside) host &lt;IP addr=""&gt;&lt;/IP&gt;&lt;/P&gt;&lt;P&gt;aaa-server TAC (outside) host &lt;IP addr=""&gt;&lt;/IP&gt;&lt;/P&gt;&lt;P&gt;aaa authentication ssh console TAC LOCAL&lt;/P&gt;&lt;P&gt;aaa authentication enable console TAC LOCAL&lt;/P&gt;&lt;P&gt;aaa authentication http console TAC LOCAL&lt;/P&gt;&lt;P&gt;aaa authorization command TAC LOCAL&lt;/P&gt;&lt;P&gt;aaa accounting ssh console TAC&lt;/P&gt;&lt;P&gt;aaa accounting enable console TAC&lt;/P&gt;&lt;P&gt;aaa accounting command TAC&lt;SPAN id="mce_marker"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Oct 2012 11:31:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-asa-authorization-and-accounting/m-p/1981662#M181512</guid>
      <dc:creator>Omdatta pawar</dc:creator>
      <dc:date>2012-10-10T11:31:16Z</dc:date>
    </item>
    <item>
      <title>ACS - ASA Authorization and Accounting</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-asa-authorization-and-accounting/m-p/1981663#M181515</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;i'm sure that i'm useing priv.15 user as below&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA1# sh curpriv &lt;/P&gt;&lt;P&gt;Username : fwuser1&lt;/P&gt;&lt;P&gt;Current privilege level : 15&lt;/P&gt;&lt;P&gt;Current Mode/s : P_PRIV&lt;/P&gt;&lt;P&gt;ASA1# &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but unfortunately still not working &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Oct 2012 11:42:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-asa-authorization-and-accounting/m-p/1981663#M181515</guid>
      <dc:creator>eng.malak</dc:creator>
      <dc:date>2012-10-10T11:42:10Z</dc:date>
    </item>
    <item>
      <title>ACS - ASA Authorization and Accounting</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-asa-authorization-and-accounting/m-p/1981664#M181517</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; user&amp;nbsp; "fwuser1" is tacacs or local user?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check is tacacs rechable?&lt;/P&gt;&lt;P&gt;﻿&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Oct 2012 11:53:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-asa-authorization-and-accounting/m-p/1981664#M181517</guid>
      <dc:creator>Omdatta pawar</dc:creator>
      <dc:date>2012-10-10T11:53:25Z</dc:date>
    </item>
    <item>
      <title>hey eng.malak, </title>
      <link>https://community.cisco.com/t5/network-access-control/acs-asa-authorization-and-accounting/m-p/1981665#M181519</link>
      <description>&lt;P&gt;hey eng.malak,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;were the steps above by creating a locallly user on the asa solved the problem? I have the same problem. havent tried yet, but I will do it on Monday.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 02 Apr 2017 00:07:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-asa-authorization-and-accounting/m-p/1981665#M181519</guid>
      <dc:creator>Kn1ghtR1d3rOfD00m</dc:creator>
      <dc:date>2017-04-02T00:07:12Z</dc:date>
    </item>
  </channel>
</rss>

