<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ACS 5.1 Device Admin privilege assignment in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-5-1-device-admin-privilege-assignment/m-p/1864051#M227895</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Indeed, a device must have the "&lt;STRONG&gt;aaa authorization exec&lt;/STRONG&gt;" command for privilege assignment from ACS to work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In my device, running IOS 12.2(53)SG3, the configuration should be:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;STRONG&gt;aaa authorization exec default local group tacacs+&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That allows the device to try the local enable secret and then TACACS+ authorization.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 02 Dec 2011 15:14:19 GMT</pubDate>
    <dc:creator>ww9rivers</dc:creator>
    <dc:date>2011-12-02T15:14:19Z</dc:date>
    <item>
      <title>ACS 5.1 Device Admin privilege assignment</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-1-device-admin-privilege-assignment/m-p/1864050#M227894</link>
      <description>&lt;P&gt;&lt;SPAN&gt;I think I am doing the same thing as described in this document: &lt;/SPAN&gt;&lt;A href="https://community.cisco.com/document/61691/how-configure-tacacs-authentication-and-authorization-admin-and-non-admin-users-acs" target="_blank"&gt;https://supportforums.cisco.com/docs/DOC-16027&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, my admin user is still being assigned privilege level 1, as shown in &lt;STRONG&gt;AAA Protocol &amp;gt; TACACS+ Authentication Details&lt;/STRONG&gt; report.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The report seems to show that the user is getting the right shell profile (Selected Shell Profile: Net-Admin -- is the one I setup for this user's group with both Default Privilege and Maximum Privilege set to Static 15). But still not the right privilege (Privilege Level: 1).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, I found this document via Google:&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/tech/tk59/technologies_tech_note09186a008009465c.shtml#t2" target="_blank"&gt;http://www.cisco.com/en/US/tech/tk59/technologies_tech_note09186a008009465c.shtml#t2&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The router configuration examples all show this "&lt;STRONG&gt;aaa authorization exec tacacs+|radius local&lt;/STRONG&gt;" command, which my device does not have.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So I am wondering if I am not reading the ACS report right, or the device actually was assigned the correct privilge but that does not work without the "&lt;STRONG&gt;aaa authorization exec&lt;/STRONG&gt;" command in the configuration?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help would be great! Thanks!&lt;/P&gt;&lt;P&gt;-- &lt;/P&gt;&lt;P&gt;Wei&lt;/P&gt;</description>
      <pubDate>Tue, 26 Mar 2019 00:28:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-1-device-admin-privilege-assignment/m-p/1864050#M227894</guid>
      <dc:creator>ww9rivers</dc:creator>
      <dc:date>2019-03-26T00:28:30Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 5.1 Device Admin privilege assignment</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-1-device-admin-privilege-assignment/m-p/1864051#M227895</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Indeed, a device must have the "&lt;STRONG&gt;aaa authorization exec&lt;/STRONG&gt;" command for privilege assignment from ACS to work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In my device, running IOS 12.2(53)SG3, the configuration should be:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;STRONG&gt;aaa authorization exec default local group tacacs+&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That allows the device to try the local enable secret and then TACACS+ authorization.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Dec 2011 15:14:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-1-device-admin-privilege-assignment/m-p/1864051#M227895</guid>
      <dc:creator>ww9rivers</dc:creator>
      <dc:date>2011-12-02T15:14:19Z</dc:date>
    </item>
  </channel>
</rss>

