<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Enable authentication through tacacs+ in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/enable-authentication-through-tacacs/m-p/1865408#M227412</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Han,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need to add the "aaa authorization exec default group tacacs if-authenticated none" command. Also, the TACACS+ server should be configured to return the privilege level 15 attribute for Shell (EXEC) as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NOTE: The feature to get directly into enable mode after typing the Username/Password applies only for IOS devices. Cisco ASA does not include this feature as it is considered a security device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 06 Jan 2012 20:18:08 GMT</pubDate>
    <dc:creator>camejia</dc:creator>
    <dc:date>2012-01-06T20:18:08Z</dc:date>
    <item>
      <title>Enable authentication through tacacs+</title>
      <link>https://community.cisco.com/t5/network-access-control/enable-authentication-through-tacacs/m-p/1865407#M227411</link>
      <description>&lt;P&gt;﻿I configured authentication for Enable to user Tacacs+. I need it to be authenticated the same time when users are logging in. That is, a user types his username and password, he is directly logged into Enable mode.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, it stops everytime at exec mode, he has to type "enable " and type his password again to get into enable mode.&lt;/P&gt;&lt;P&gt;any idea?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;﻿The aaa config is attached.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;Han&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;﻿&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 01:41:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/enable-authentication-through-tacacs/m-p/1865407#M227411</guid>
      <dc:creator>hanwu_dot</dc:creator>
      <dc:date>2019-03-11T01:41:41Z</dc:date>
    </item>
    <item>
      <title>Re: Enable authentication through tacacs+</title>
      <link>https://community.cisco.com/t5/network-access-control/enable-authentication-through-tacacs/m-p/1865408#M227412</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Han,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need to add the "aaa authorization exec default group tacacs if-authenticated none" command. Also, the TACACS+ server should be configured to return the privilege level 15 attribute for Shell (EXEC) as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NOTE: The feature to get directly into enable mode after typing the Username/Password applies only for IOS devices. Cisco ASA does not include this feature as it is considered a security device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Jan 2012 20:18:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/enable-authentication-through-tacacs/m-p/1865408#M227412</guid>
      <dc:creator>camejia</dc:creator>
      <dc:date>2012-01-06T20:18:08Z</dc:date>
    </item>
  </channel>
</rss>

