<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: couldn't get command set working on acs5.3 in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/couldn-t-get-command-set-working-on-acs5-3/m-p/2121712#M188753</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/8/1/3/116318-aaa.jpg" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;this is the command set:&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/0/2/3/116320-command_set.jpg" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Authorization: the last one&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/4/2/3/116324-authorization.jpg" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Authorization profile (shell profile):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/5/2/3/116325-shell_profile.jpg" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if you need more info.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 29 Nov 2012 17:02:33 GMT</pubDate>
    <dc:creator>kerim mohammed</dc:creator>
    <dc:date>2012-11-29T17:02:33Z</dc:date>
    <item>
      <title>couldn't get command set working on acs5.3</title>
      <link>https://community.cisco.com/t5/network-access-control/couldn-t-get-command-set-working-on-acs5-3/m-p/2121710#M188636</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I configured, command set on ACS5.3 so that it allows to run the show command only. The corresponding shell profile is set to privelege level 15. I couldn't get it working. users are still able to run any command. how do i get this working.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kerim&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 02:50:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/couldn-t-get-command-set-working-on-acs5-3/m-p/2121710#M188636</guid>
      <dc:creator>kerim mohammed</dc:creator>
      <dc:date>2019-03-11T02:50:42Z</dc:date>
    </item>
    <item>
      <title>couldn't get command set working on acs5.3</title>
      <link>https://community.cisco.com/t5/network-access-control/couldn-t-get-command-set-working-on-acs5-3/m-p/2121711#M188718</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Which is your current AAA configuration in the client? Type "show runn | i aaa" and paste here the output. Also share with us a screenshot of your Command Set and Authorization rule.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Nov 2012 16:03:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/couldn-t-get-command-set-working-on-acs5-3/m-p/2121711#M188718</guid>
      <dc:creator>mauzamor</dc:creator>
      <dc:date>2012-11-29T16:03:28Z</dc:date>
    </item>
    <item>
      <title>Re: couldn't get command set working on acs5.3</title>
      <link>https://community.cisco.com/t5/network-access-control/couldn-t-get-command-set-working-on-acs5-3/m-p/2121712#M188753</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/8/1/3/116318-aaa.jpg" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;this is the command set:&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/0/2/3/116320-command_set.jpg" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Authorization: the last one&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/4/2/3/116324-authorization.jpg" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Authorization profile (shell profile):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/5/2/3/116325-shell_profile.jpg" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if you need more info.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Nov 2012 17:02:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/couldn-t-get-command-set-working-on-acs5-3/m-p/2121712#M188753</guid>
      <dc:creator>kerim mohammed</dc:creator>
      <dc:date>2012-11-29T17:02:33Z</dc:date>
    </item>
    <item>
      <title>Re: couldn't get command set working on acs5.3</title>
      <link>https://community.cisco.com/t5/network-access-control/couldn-t-get-command-set-working-on-acs5-3/m-p/2121713#M188831</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You are missing the "authorization" commands.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example depending on what you need to check with ACS you will have to use:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authorization command 15 default group tacacs+ if-authenticated&lt;/P&gt;&lt;P&gt;aaa authorization command 1 default group tacacs+ if-authenticated&lt;/P&gt;&lt;P&gt;aaa authorization command 0 default group tacacs+ if-authenticated&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The previous commands means that every time a user enters a command level 15/1/0 the client will check with the ACS if these commands are permitted or not.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, in the Command Set you don't need to use "*" in the Argument section, just "show" under the Command section.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Remember to have a back door configured, this will avoid you getting locked out, e.g. console access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know how it goes.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Nov 2012 17:25:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/couldn-t-get-command-set-working-on-acs5-3/m-p/2121713#M188831</guid>
      <dc:creator>mauzamor</dc:creator>
      <dc:date>2012-11-29T17:25:49Z</dc:date>
    </item>
    <item>
      <title>Re: couldn't get command set working on acs5.3</title>
      <link>https://community.cisco.com/t5/network-access-control/couldn-t-get-command-set-working-on-acs5-3/m-p/2121714#M188930</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks! that took care of it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Nov 2012 18:19:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/couldn-t-get-command-set-working-on-acs5-3/m-p/2121714#M188930</guid>
      <dc:creator>kerim mohammed</dc:creator>
      <dc:date>2012-11-29T18:19:50Z</dc:date>
    </item>
    <item>
      <title>Re: couldn't get command set working on acs5.3</title>
      <link>https://community.cisco.com/t5/network-access-control/couldn-t-get-command-set-working-on-acs5-3/m-p/2121715#M189007</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Glad to hear the good news.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have a nice day.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Nov 2012 18:29:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/couldn-t-get-command-set-working-on-acs5-3/m-p/2121715#M189007</guid>
      <dc:creator>mauzamor</dc:creator>
      <dc:date>2012-11-29T18:29:04Z</dc:date>
    </item>
  </channel>
</rss>

