<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ACS 5.3  and Command Auth in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-5-3-and-command-auth/m-p/2029625#M200449</link>
    <description>&lt;P&gt;I am rolling out the Latest 5.3.0.40.6 patched ACS 1121 in a redundant pair mode.&amp;nbsp;&amp;nbsp; I have build user based auth without issue but am having an issue with Command auth.&amp;nbsp; once I add command auth to the test router and modify the shell profile and command set for privilege 1 nd 15,&amp;nbsp; none of the commands are authenticated and the report indicates the "DenyCommand" default.&amp;nbsp; I have followed the user guide and the step by step from Security Solutions. ( link below)&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I still get no joy.&amp;nbsp;&amp;nbsp; Also Cisco changed the GUI and the way command sets are built&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;(&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.security-solutions.co.za/Cisco-ACS-5.2-Role-Based-Authentication-Authorization-For-Different-Privilege-Levels-Configuration-Example.html" target="_blank"&gt;http://www.security-solutions.co.za/Cisco-ACS-5.2-Role-Based-Authentication-Authorization-For-Different-Privilege-Levels-Configuration-Example.html&lt;/A&gt;&lt;SPAN&gt; ) &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help would be appreciated &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Patrick Connor&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 02:34:15 GMT</pubDate>
    <dc:creator>Patrick Connor</dc:creator>
    <dc:date>2019-03-11T02:34:15Z</dc:date>
    <item>
      <title>ACS 5.3  and Command Auth</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-3-and-command-auth/m-p/2029625#M200449</link>
      <description>&lt;P&gt;I am rolling out the Latest 5.3.0.40.6 patched ACS 1121 in a redundant pair mode.&amp;nbsp;&amp;nbsp; I have build user based auth without issue but am having an issue with Command auth.&amp;nbsp; once I add command auth to the test router and modify the shell profile and command set for privilege 1 nd 15,&amp;nbsp; none of the commands are authenticated and the report indicates the "DenyCommand" default.&amp;nbsp; I have followed the user guide and the step by step from Security Solutions. ( link below)&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I still get no joy.&amp;nbsp;&amp;nbsp; Also Cisco changed the GUI and the way command sets are built&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;(&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.security-solutions.co.za/Cisco-ACS-5.2-Role-Based-Authentication-Authorization-For-Different-Privilege-Levels-Configuration-Example.html" target="_blank"&gt;http://www.security-solutions.co.za/Cisco-ACS-5.2-Role-Based-Authentication-Authorization-For-Different-Privilege-Levels-Configuration-Example.html&lt;/A&gt;&lt;SPAN&gt; ) &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help would be appreciated &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Patrick Connor&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 02:34:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-3-and-command-auth/m-p/2029625#M200449</guid>
      <dc:creator>Patrick Connor</dc:creator>
      <dc:date>2019-03-11T02:34:15Z</dc:date>
    </item>
    <item>
      <title>ACS 5.3  and Command Auth</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-3-and-command-auth/m-p/2029626#M200464</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Patrick,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you please post a screenshot of the authorization rule, and the command set that you configured?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Sep 2012 16:28:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-3-and-command-auth/m-p/2029626#M200464</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-09-20T16:28:37Z</dc:date>
    </item>
    <item>
      <title>ACS 5.3  and Command Auth</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-3-and-command-auth/m-p/2029627#M200474</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Tarik,&amp;nbsp; thanks for the response.&amp;nbsp; I cannot get screen shots but can define the options sets.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I created 2 command sets &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pri-15&amp;nbsp; has only the permit all command not in the table below check box checked&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pri-1&amp;nbsp; has a single permit "show"&amp;nbsp; with no arguments &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the Auth rule has 2 rules &lt;/P&gt;&lt;P&gt;rule 1&amp;nbsp; identity group "network Admin"&amp;nbsp; any any any pri-15&lt;/P&gt;&lt;P&gt;rule 2 identity group "network monitor" any any any pri-1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;service selection rule&amp;nbsp;&amp;nbsp;&amp;nbsp; rule 1&amp;nbsp; condition ( match system: protocol match TACACS)&amp;nbsp; result Default Device Admin&amp;nbsp;&amp;nbsp; hit count 98&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the report indicated the a FAIL "13025 command failed to match a Permit rule)&amp;nbsp; and the Selected Command Set = (DentAllCommands)&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So it looks like the command set is not being recognized.&amp;nbsp; but I cannot see why?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Pat&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Sep 2012 18:01:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-3-and-command-auth/m-p/2029627#M200474</guid>
      <dc:creator>Patrick Connor</dc:creator>
      <dc:date>2012-09-20T18:01:36Z</dc:date>
    </item>
    <item>
      <title>ACS 5.3  and Command Auth</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-3-and-command-auth/m-p/2029628#M200499</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Patrick,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you check this doc to see if the command set option is enabled? It is hidden by default (that is what i wanted to confirm).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-wiki-small" href="https://community.cisco.com/docs/DOC-26768"&gt;https://supportforums.cisco.com/docs/DOC-26768&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Sep 2012 18:03:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-3-and-command-auth/m-p/2029628#M200499</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-09-20T18:03:40Z</dc:date>
    </item>
    <item>
      <title>ACS 5.3  and Command Auth</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-3-and-command-auth/m-p/2029629#M200513</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It was not enabled.&amp;nbsp; Thank you very much for the assistance.&amp;nbsp; I have added the "commnad Set" to the customized Results and will test.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Sep 2012 18:08:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-3-and-command-auth/m-p/2029629#M200513</guid>
      <dc:creator>Patrick Connor</dc:creator>
      <dc:date>2012-09-20T18:08:27Z</dc:date>
    </item>
  </channel>
</rss>

