<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Want to directly login to # prompt in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/want-to-directly-login-to-prompt/m-p/1973648#M188202</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Assuming Cisco ACS v5.x:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Create a new Shell Profile:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000080;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Policy Elements &amp;gt; Authorization and Permissions &amp;gt; Device Administration &amp;gt; Shell Profiles&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Click the &lt;STRONG&gt;Create &lt;/STRONG&gt;button at the bottom of the page.&lt;/P&gt;&lt;P&gt;On the &lt;STRONG&gt;General &lt;/STRONG&gt;tab, give the profile a name, then go to the &lt;STRONG&gt;Common Tasks&lt;/STRONG&gt; tab.&lt;/P&gt;&lt;P&gt;Under &lt;STRONG&gt;Privilege Level&lt;/STRONG&gt;, set both the &lt;EM&gt;Default Privilege&lt;/EM&gt; and the &lt;EM&gt;Maximum Privilege&lt;/EM&gt; to 15.&lt;/P&gt;&lt;P&gt;Click the &lt;STRONG&gt;Submit &lt;/STRONG&gt;button at the bottom of the page.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Create a new Command Set:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000080;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Policy Elements &amp;gt; Authorization and Permissions &amp;gt; Device Administration &amp;gt; Command Sets&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Click the &lt;STRONG&gt;Create &lt;/STRONG&gt;button at the bottom of the page.&lt;/P&gt;&lt;P&gt;Check the box next to "&lt;EM&gt;Permit any command that is not in the table below&lt;/EM&gt;"&lt;/P&gt;&lt;P&gt;Click the &lt;STRONG&gt;Submit &lt;/STRONG&gt;button at the bottom of the page.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Create a new Authorization policy:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000080;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Access Policies &amp;gt; Access Services &amp;gt; Default Device Admin &amp;gt; Authorization&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Click the &lt;STRONG&gt;Create &lt;/STRONG&gt;button at the bottom of the page.&lt;/P&gt;&lt;P&gt; Under &lt;STRONG&gt;Results&lt;/STRONG&gt;:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Set the &lt;EM&gt;Shell Profile&lt;/EM&gt; to the one you just created&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Set the &lt;EM&gt;Command Sets&lt;/EM&gt; to the one you just created&lt;/P&gt;&lt;P&gt;Click the &lt;STRONG&gt;OK&lt;/STRONG&gt; button at the bottom of the window.&lt;/P&gt;&lt;P&gt;Click the &lt;STRONG&gt;Save Changes &lt;/STRONG&gt;button at the bottom of the page.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope this helps,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--Chris&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 29 May 2012 13:58:45 GMT</pubDate>
    <dc:creator>spindoctor64</dc:creator>
    <dc:date>2012-05-29T13:58:45Z</dc:date>
    <item>
      <title>Want to directly login to # prompt</title>
      <link>https://community.cisco.com/t5/network-access-control/want-to-directly-login-to-prompt/m-p/1973647#M188199</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am having a ASR 1002 V 12.2(33)XND2twhich is running on Tacas&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I want when i login it shoudl directly go into the # prompt. I am not interested in typing enable on &amp;gt; prompt. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The configs are&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;aa new-model&lt;/P&gt;&lt;P&gt;aaa authentication login default group tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authentication enable default none&lt;/P&gt;&lt;P&gt;!aaa authorization console&lt;/P&gt;&lt;P&gt;!aaa authorization config-commands&lt;/P&gt;&lt;P&gt;!aaa authorization template&lt;/P&gt;&lt;P&gt;!aaa authorization exec default group tacacs+ local&lt;/P&gt;&lt;P&gt;!aaa authorization commands 15 default local none&lt;/P&gt;&lt;P&gt;aaa accounting exec default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting commands 15 default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting connection default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting system default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa session-id common&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;tacacs-server host XXXXX&lt;/P&gt;&lt;P&gt;tacacs-server host XXXXX&lt;/P&gt;&lt;P&gt;no tacacs-server directed-request&lt;SPAN id="mce_marker"&gt; &lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 02:08:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/want-to-directly-login-to-prompt/m-p/1973647#M188199</guid>
      <dc:creator>anujseth1.con</dc:creator>
      <dc:date>2019-03-11T02:08:23Z</dc:date>
    </item>
    <item>
      <title>Re: Want to directly login to # prompt</title>
      <link>https://community.cisco.com/t5/network-access-control/want-to-directly-login-to-prompt/m-p/1973648#M188202</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Assuming Cisco ACS v5.x:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Create a new Shell Profile:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000080;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Policy Elements &amp;gt; Authorization and Permissions &amp;gt; Device Administration &amp;gt; Shell Profiles&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Click the &lt;STRONG&gt;Create &lt;/STRONG&gt;button at the bottom of the page.&lt;/P&gt;&lt;P&gt;On the &lt;STRONG&gt;General &lt;/STRONG&gt;tab, give the profile a name, then go to the &lt;STRONG&gt;Common Tasks&lt;/STRONG&gt; tab.&lt;/P&gt;&lt;P&gt;Under &lt;STRONG&gt;Privilege Level&lt;/STRONG&gt;, set both the &lt;EM&gt;Default Privilege&lt;/EM&gt; and the &lt;EM&gt;Maximum Privilege&lt;/EM&gt; to 15.&lt;/P&gt;&lt;P&gt;Click the &lt;STRONG&gt;Submit &lt;/STRONG&gt;button at the bottom of the page.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Create a new Command Set:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000080;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Policy Elements &amp;gt; Authorization and Permissions &amp;gt; Device Administration &amp;gt; Command Sets&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Click the &lt;STRONG&gt;Create &lt;/STRONG&gt;button at the bottom of the page.&lt;/P&gt;&lt;P&gt;Check the box next to "&lt;EM&gt;Permit any command that is not in the table below&lt;/EM&gt;"&lt;/P&gt;&lt;P&gt;Click the &lt;STRONG&gt;Submit &lt;/STRONG&gt;button at the bottom of the page.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Create a new Authorization policy:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000080;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Access Policies &amp;gt; Access Services &amp;gt; Default Device Admin &amp;gt; Authorization&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Click the &lt;STRONG&gt;Create &lt;/STRONG&gt;button at the bottom of the page.&lt;/P&gt;&lt;P&gt; Under &lt;STRONG&gt;Results&lt;/STRONG&gt;:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Set the &lt;EM&gt;Shell Profile&lt;/EM&gt; to the one you just created&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Set the &lt;EM&gt;Command Sets&lt;/EM&gt; to the one you just created&lt;/P&gt;&lt;P&gt;Click the &lt;STRONG&gt;OK&lt;/STRONG&gt; button at the bottom of the window.&lt;/P&gt;&lt;P&gt;Click the &lt;STRONG&gt;Save Changes &lt;/STRONG&gt;button at the bottom of the page.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope this helps,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--Chris&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 May 2012 13:58:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/want-to-directly-login-to-prompt/m-p/1973648#M188202</guid>
      <dc:creator>spindoctor64</dc:creator>
      <dc:date>2012-05-29T13:58:45Z</dc:date>
    </item>
    <item>
      <title>Re: Want to directly login to # prompt</title>
      <link>https://community.cisco.com/t5/network-access-control/want-to-directly-login-to-prompt/m-p/1973649#M188210</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Chris dont have access via web. Can you suggest the CLI commands..&lt;/P&gt;&lt;P&gt;As per my understanding We are already haveing aaa accounting commands 15 default start-stop group tacacs+&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 May 2012 14:02:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/want-to-directly-login-to-prompt/m-p/1973649#M188210</guid>
      <dc:creator>anujseth1.con</dc:creator>
      <dc:date>2012-05-29T14:02:19Z</dc:date>
    </item>
    <item>
      <title>Re: Want to directly login to # prompt</title>
      <link>https://community.cisco.com/t5/network-access-control/want-to-directly-login-to-prompt/m-p/1973650#M188219</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;aaa accounting only has to do with logging the commands, not whether the commands are authorized.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You generally also want your authentication and authorization to come from the same place, such as the ACS only.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your config:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000;"&gt;&amp;nbsp; aaa new-model&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000;"&gt;&amp;nbsp; aaa authentication login default group tacacs+ local&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;EM style="color: #0000ff; "&gt;&amp;lt;--Check TACACS+ to validate users and assign priv level when logging in&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN style="color: #000000;"&gt;aaa authentication enable default none&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000;"&gt;&amp;nbsp; !aaa authorization console&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000;"&gt;&amp;nbsp; !aaa authorization config-commands&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000;"&gt;&amp;nbsp; !aaa authorization template&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000;"&gt;&amp;nbsp; !aaa authorization exec default group tacacs+ local&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000;"&gt;&amp;nbsp; !aaa authorization commands 15 default local none&lt;/SPAN&gt;&lt;SPAN style="color: #0000ff;"&gt;&lt;EM&gt;&amp;nbsp;&amp;nbsp; &amp;lt;--Check local device for command authorization&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN style="color: #000000;"&gt;aaa accounting exec default start-stop group tacacs+&lt;/SPAN&gt;&amp;nbsp;&amp;nbsp; &lt;SPAN style="color: #0000ff;"&gt;&amp;lt;----------------\&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000;"&gt;&amp;nbsp; aaa accounting commands 15 default start-stop group tacacs+&amp;nbsp;&amp;nbsp; &lt;SPAN style="color: #0000ff;"&gt;&amp;lt;----\ &lt;EM&gt;Accounting commands log everything to ACS&lt;/EM&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000;"&gt;&amp;nbsp; aaa accounting connection default start-stop group tacacs+&amp;nbsp;&amp;nbsp; &lt;SPAN style="color: #0000ff;"&gt;&amp;lt;---------/&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000;"&gt;&amp;nbsp; aaa accounting system default start-stop group tacacs+&amp;nbsp;&amp;nbsp; &lt;SPAN style="color: #0000ff;"&gt;&amp;lt;-------------/&lt;/SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000;"&gt;&amp;nbsp; aaa session-id common&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When a user logs into your device, TACACS+ validates that the user has an account, AND assigns the initial privilege level.&amp;nbsp; You would need to configure a privilege level of 15 on the ACS to be able to skip directly to the privileged exec mode (# prompt).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Once that is done, you would also want to change your command authorizations to come from the ACS instead of the local device:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; aaa authorization commands 0 default group tacacs+ local none&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; aaa authorization commands 1 default group tacacs+ local none&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; aaa authorization commands 15 default group tacacs+ local if-authenticated&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--Chris&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 May 2012 14:41:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/want-to-directly-login-to-prompt/m-p/1973650#M188219</guid>
      <dc:creator>spindoctor64</dc:creator>
      <dc:date>2012-05-29T14:41:51Z</dc:date>
    </item>
  </channel>
</rss>

