<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic AAA command authorization ASA in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/aaa-command-authorization-asa/m-p/2077858#M183904</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Douglas,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What information do you see in the ACS server when the authorization fails in your ASA? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 20 Dec 2012 16:43:38 GMT</pubDate>
    <dc:creator>mauzamor</dc:creator>
    <dc:date>2012-12-20T16:43:38Z</dc:date>
    <item>
      <title>AAA command authorization ASA</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-command-authorization-asa/m-p/2077857#M183896</link>
      <description>&lt;P&gt;I have aaa authentication working on my ASA with no problem. I have command authorization working for my account on all my IOS devices with TACACS+ and a Cisco ACS. I can not get command authorization to work on the ASA. Every time I enter the 'aaa authorization command CSACS-TACACS+' the system will not let me do anything else and gives me a user not authroized and the ACS shows no log of this request. I then have to reboot the ASA to get back in.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Current commands&lt;/P&gt;&lt;P&gt;aaa authentication ssh console CSACS-TACACS+ &lt;/P&gt;&lt;P&gt;aaa authentication http console CSACS-TACACS+ &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Entered commands&lt;/P&gt;&lt;P&gt;aaa authentication enable console CSACS-TACACS+&lt;/P&gt;&lt;P&gt;aaa authorization command CSACS-TACACS+&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 02:54:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-command-authorization-asa/m-p/2077857#M183896</guid>
      <dc:creator>gm-douglas</dc:creator>
      <dc:date>2019-03-11T02:54:33Z</dc:date>
    </item>
    <item>
      <title>AAA command authorization ASA</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-command-authorization-asa/m-p/2077858#M183904</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Douglas,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What information do you see in the ACS server when the authorization fails in your ASA? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Dec 2012 16:43:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-command-authorization-asa/m-p/2077858#M183904</guid>
      <dc:creator>mauzamor</dc:creator>
      <dc:date>2012-12-20T16:43:38Z</dc:date>
    </item>
    <item>
      <title>AAA command authorization ASA</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-command-authorization-asa/m-p/2077859#M183914</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I get nothing on the ACS. When I use this on a IOS device and do see the commands in the tacacs authorization display, but nothing from the ASA. I tried the debug aaa authorization and this did not display anything.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Dec 2012 16:58:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-command-authorization-asa/m-p/2077859#M183914</guid>
      <dc:creator>gm-douglas</dc:creator>
      <dc:date>2012-12-20T16:58:14Z</dc:date>
    </item>
    <item>
      <title>AAA command authorization ASA</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-command-authorization-asa/m-p/2077860#M183944</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Douglas,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try the following configuration:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authentication ssh console CSACS-TACACS+ &lt;/P&gt;&lt;P&gt;aaa authentication http console CSACS-TACACS+ &lt;/P&gt;&lt;P&gt;aaa authentication enable console CSACS-TACACS+&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With the previous settings the ASA should be authenticating your username/password and the enable password against the ACS server, if this part works fine then authorization should also be working fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Remember to keep another session open in privilege mode before testing "&lt;/P&gt;&lt;P&gt;aaa authentication enable console CSACS-TACACS+" command. In the ACS server you should be seeing at least the authentication passed report.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Dec 2012 17:03:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-command-authorization-asa/m-p/2077860#M183944</guid>
      <dc:creator>mauzamor</dc:creator>
      <dc:date>2012-12-20T17:03:27Z</dc:date>
    </item>
  </channel>
</rss>

