<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Read only , and read write authorization from acs/juniper radius in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/read-only-and-read-write-authorization-from-acs-juniper-radius/m-p/1920568#M203078</link>
    <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we have a large detabase of cisco routers and swithches , we want to have a radius authentication and athorizaion level set to read only and (rd , rw) for certain users.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ie for company employees read write access and for outside auditors/consultants read only access . &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;how do i do it with Radius on ACS and juniper/radius&amp;nbsp; .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any links for cisco routers config will be highly appreciated.&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 01:59:01 GMT</pubDate>
    <dc:creator>mirehteshamali</dc:creator>
    <dc:date>2019-03-11T01:59:01Z</dc:date>
    <item>
      <title>Read only , and read write authorization from acs/juniper radius</title>
      <link>https://community.cisco.com/t5/network-access-control/read-only-and-read-write-authorization-from-acs-juniper-radius/m-p/1920568#M203078</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we have a large detabase of cisco routers and swithches , we want to have a radius authentication and athorizaion level set to read only and (rd , rw) for certain users.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ie for company employees read write access and for outside auditors/consultants read only access . &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;how do i do it with Radius on ACS and juniper/radius&amp;nbsp; .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any links for cisco routers config will be highly appreciated.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 01:59:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/read-only-and-read-write-authorization-from-acs-juniper-radius/m-p/1920568#M203078</guid>
      <dc:creator>mirehteshamali</dc:creator>
      <dc:date>2019-03-11T01:59:01Z</dc:date>
    </item>
    <item>
      <title>Read only , and read write authorization from acs/juniper radius</title>
      <link>https://community.cisco.com/t5/network-access-control/read-only-and-read-write-authorization-from-acs-juniper-radius/m-p/1920569#M203083</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would recommend to use TACACS+ instead of RADIUS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Depending on your network device, in ACS you can use "command authorization sets" (when using traditional IOS) or "shell profiles" (when using Cisco IOS XE, IOS XR, Cisco ACE, Juniper JunOS, etc).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For read only you can deny the "config terminal" command. For read write you can allow the "config terminal" command.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here's an example of allowing/denying commands by using "command authorization sets".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PLease rate if it helps. Kind regards.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/2/4/8/85842-commandset.png" class="jive-image" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Apr 2012 16:04:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/read-only-and-read-write-authorization-from-acs-juniper-radius/m-p/1920569#M203083</guid>
      <dc:creator>Eduardo Aliaga</dc:creator>
      <dc:date>2012-04-09T16:04:15Z</dc:date>
    </item>
  </channel>
</rss>

