<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ACS 4.2 tacacs custom attribute for Nexus1000V in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-4-2-tacacs-custom-attribute-for-nexus1000v/m-p/1706937#M232492</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You should not have to add the shell tacacs service. Here is where you add the custom attributes:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.2/user/guide/GrpMgt.html#wp479948"&gt;http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.2/user/guide/GrpMgt.html#wp479948&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There should be a custom attributes box under the shell (exec) service, enter it there. You only need network-admin for the value.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Tarik&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 19 Jul 2011 13:22:28 GMT</pubDate>
    <dc:creator>Tarik Admani</dc:creator>
    <dc:date>2011-07-19T13:22:28Z</dc:date>
    <item>
      <title>ACS 4.2 tacacs custom attribute for Nexus1000V</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-4-2-tacacs-custom-attribute-for-nexus1000v/m-p/1706936#M232491</link>
      <description>&lt;P&gt;Dear All! Please, explain how to add tacacs custom attribute to ACS 4.2 for Nexus 1000V:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE&gt;shell:roles="network-admin admin-vdc"&lt;BR /&gt;&lt;BR /&gt;In the interface configuration I've added new service, service - shell, protocol - tacacs+.&lt;BR /&gt;In the group settings I've enabled this attribute configuration. &lt;BR /&gt;And it is not works. Default privilege level is assigned to any user with access allowed. &lt;BR /&gt;Screenshot is attached.&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/legacy/2/9/6/53692-ACS_Nexus.jpg" alt="ACS_Nexus.jpg" class="jive-image-thumbnail jive-image" onclick="" width="450" /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 01:13:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-4-2-tacacs-custom-attribute-for-nexus1000v/m-p/1706936#M232491</guid>
      <dc:creator>Eugene Khabarov</dc:creator>
      <dc:date>2019-03-11T01:13:55Z</dc:date>
    </item>
    <item>
      <title>ACS 4.2 tacacs custom attribute for Nexus1000V</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-4-2-tacacs-custom-attribute-for-nexus1000v/m-p/1706937#M232492</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You should not have to add the shell tacacs service. Here is where you add the custom attributes:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.2/user/guide/GrpMgt.html#wp479948"&gt;http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.2/user/guide/GrpMgt.html#wp479948&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There should be a custom attributes box under the shell (exec) service, enter it there. You only need network-admin for the value.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Tarik&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Jul 2011 13:22:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-4-2-tacacs-custom-attribute-for-nexus1000v/m-p/1706937#M232492</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2011-07-19T13:22:28Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 4.2 tacacs custom attribute for Nexus1000V</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-4-2-tacacs-custom-attribute-for-nexus1000v/m-p/1706938#M232493</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you, but it was not helpful.&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/5/7/7/53775-ACS_Nexus.png" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;User recieves network-operator role:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;Nexus1000V# conf t&lt;/P&gt;&lt;P&gt;Enter configuration commands, one per line.&amp;nbsp; End with CNTL/Z.&lt;/P&gt;&lt;P&gt;Nexus1000V(config)# ?&lt;/P&gt;&lt;P&gt;&amp;nbsp; no&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Negate a command or set its defaults&lt;/P&gt;&lt;P&gt;&amp;nbsp; username&amp;nbsp; Configure user information.&lt;/P&gt;&lt;P&gt;&amp;nbsp; end&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Go to exec mode&lt;/P&gt;&lt;P&gt;&amp;nbsp; exit&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Exit from command interpreter&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Nexus1000V(config)#&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa configured on Nexus like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;aaa group server tacacs+ ACS &lt;/P&gt;&lt;P&gt;aaa authentication login default group ACS &lt;/P&gt;&lt;P&gt;aaa authentication login console local &lt;/P&gt;&lt;P&gt;aaa accounting default group ACS&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;in the debug I can see that correct attributes are recieved by Nexus:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;2011 Jul 19 14:12:37.052510 tacacs: tplus_decode_author_response: attribute 0 service=shell &lt;BR /&gt;2011 Jul 19 14:12:37.052649 tacacs: tplus_decode_author_response: attribute 1 cmd= &lt;BR /&gt;2011 Jul 19 14:12:37.052789 tacacs: tplus_decode_author_response: attribute 2 shell:roles=network-admin &lt;BR /&gt;2011 Jul 19 14:12:37.052927 tacacs: tplus_process_vsa: got VSA attribute:shell:roles=network-admin&lt;BR /&gt;2011 Jul 19 14:12:37.053076 tacacs: tplus_process_vsa: got shell: home-dir: roles:network-admin uid:&lt;BR /&gt;2011 Jul 19 14:12:37.053223 tacacs: create_tacacs_user_profile: groups network-admin &lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks in advance for help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;UPDATE:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;another interesting notification is that correct role is assigned to user, but configuration is not allowed:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;sh user-account khabarov.evgeniy&lt;BR /&gt;user:khabarov.evgeniy&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; roles:network-admin &lt;BR /&gt;account created through REMOTE authentication&lt;BR /&gt;Credentials such as ssh server key will be cached temporarily only for this user account&lt;BR /&gt;Local login not possible&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nexus1kv-01# where&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; khabarov@core-nexus1kv-01&lt;BR /&gt;core-nexus1kv# conf t&lt;BR /&gt;Enter configuration commands, one per line.&amp;nbsp; End with CNTL/Z.&lt;BR /&gt;core-nexus1kv-01(config)# ?&lt;BR /&gt;&amp;nbsp; no&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Negate a command or set its defaults&lt;BR /&gt;&amp;nbsp; username&amp;nbsp; Configure user information.&lt;BR /&gt;&amp;nbsp; end&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Go to exec mode&lt;BR /&gt;&amp;nbsp; exit&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Exit from command interpreter&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nexus1kv(config)# &lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV class="mcePaste" id="_mcePaste" style="position: absolute; width: 1px; height: 1px; overflow: hidden; top: 0px; left: -10000px;"&gt;﻿&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Jul 2011 13:44:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-4-2-tacacs-custom-attribute-for-nexus1000v/m-p/1706938#M232493</guid>
      <dc:creator>Eugene Khabarov</dc:creator>
      <dc:date>2011-07-19T13:44:39Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 4.2 tacacs custom attribute for Nexus1000V</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-4-2-tacacs-custom-attribute-for-nexus1000v/m-p/1706939#M232494</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you know if someone tampered with the user roles on your nexus? Also do you have the feature privilege enabled? try issueing a show feature to see if it is enabled and remove it and try authenticating again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks,&lt;/P&gt;&lt;P&gt;Tarik&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Jul 2011 06:54:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-4-2-tacacs-custom-attribute-for-nexus1000v/m-p/1706939#M232494</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2011-07-20T06:54:24Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 4.2 tacacs custom attribute for Nexus1000V</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-4-2-tacacs-custom-attribute-for-nexus1000v/m-p/1706940#M232495</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi! There is no such feature:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt; sh feature &lt;/P&gt;&lt;P&gt;Feature Name&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Instance&amp;nbsp; State&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;--------------------&amp;nbsp; --------&amp;nbsp; --------&lt;/P&gt;&lt;P&gt;dhcp-snooping&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; disabled&lt;/P&gt;&lt;P&gt;http-server&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; enabled &lt;/P&gt;&lt;P&gt;lacp&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; disabled&lt;/P&gt;&lt;P&gt;netflow&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; disabled&lt;/P&gt;&lt;P&gt;port-profile-roles&amp;nbsp;&amp;nbsp;&amp;nbsp; 1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; disabled&lt;/P&gt;&lt;P&gt;private-vlan&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; disabled&lt;/P&gt;&lt;P&gt;sshServer&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; enabled &lt;/P&gt;&lt;P&gt;tacacs&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; enabled &lt;/P&gt;&lt;P&gt;telnetServer&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; disabled&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I attempted to remove user from both Nexus and ACS and relogin againt and it was not helpful.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Jul 2011 07:34:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-4-2-tacacs-custom-attribute-for-nexus1000v/m-p/1706940#M232495</guid>
      <dc:creator>Eugene Khabarov</dc:creator>
      <dc:date>2011-07-20T07:34:31Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 4.2 tacacs custom attribute for Nexus1000V</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-4-2-tacacs-custom-attribute-for-nexus1000v/m-p/1706941#M232496</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you send the output of the show roles?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Tarik &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Jul 2011 19:58:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-4-2-tacacs-custom-attribute-for-nexus1000v/m-p/1706941#M232496</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2011-07-20T19:58:34Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 4.2 tacacs custom attribute for Nexus1000V</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-4-2-tacacs-custom-attribute-for-nexus1000v/m-p/1706942#M232497</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi! &lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;core-nexus1kv-01# sh role &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Role: network-admin&lt;/P&gt;&lt;P&gt;&amp;nbsp; Description: Predefined network admin role has access to all commands&lt;/P&gt;&lt;P&gt;&amp;nbsp; on the switch&lt;/P&gt;&lt;P&gt;&amp;nbsp; -------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;&amp;nbsp; Rule&amp;nbsp;&amp;nbsp;&amp;nbsp; Perm&amp;nbsp;&amp;nbsp;&amp;nbsp; Type&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Scope&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Entity&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp; -------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;&amp;nbsp; 1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; permit&amp;nbsp; read-write&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Role: network-operator&lt;/P&gt;&lt;P&gt;&amp;nbsp; Description: Predefined network operator role has access to all read&lt;/P&gt;&lt;P&gt;&amp;nbsp; commands on the switch&lt;/P&gt;&lt;P&gt;&amp;nbsp; -------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;&amp;nbsp; Rule&amp;nbsp;&amp;nbsp;&amp;nbsp; Perm&amp;nbsp;&amp;nbsp;&amp;nbsp; Type&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Scope&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Entity&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp; -------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;&amp;nbsp; 1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; permit&amp;nbsp; read&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;/PRE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Jul 2011 05:19:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-4-2-tacacs-custom-attribute-for-nexus1000v/m-p/1706942#M232497</guid>
      <dc:creator>Eugene Khabarov</dc:creator>
      <dc:date>2011-07-21T05:19:18Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 4.2 tacacs custom attribute for Nexus1000V</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-4-2-tacacs-custom-attribute-for-nexus1000v/m-p/1706943#M232498</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Eugene,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please open a tac case to have this issue looked at further, we will need to do more analysis.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Tarik &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Jul 2011 04:27:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-4-2-tacacs-custom-attribute-for-nexus1000v/m-p/1706943#M232498</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2011-07-22T04:27:37Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 4.2 tacacs custom attribute for Nexus1000V</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-4-2-tacacs-custom-attribute-for-nexus1000v/m-p/1706944#M232499</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have exactly the same problem with an ACS 5.2 returning the role attribute to Nexus 1000v. Remote user is authenticated but I can't run any privileged command even if the "show user" is good :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show user-account&lt;/P&gt;&lt;P&gt;user:admin&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; this user account has no expiry date&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; roles:network-admin&lt;/P&gt;&lt;P&gt;user:remoteadm&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; roles:network-admin&lt;/P&gt;&lt;P&gt;account created through REMOTE authentication&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Did you manage to make it work ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Vincent&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Aug 2012 17:26:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-4-2-tacacs-custom-attribute-for-nexus1000v/m-p/1706944#M232499</guid>
      <dc:creator>Vincent Fortrat</dc:creator>
      <dc:date>2012-08-21T17:26:41Z</dc:date>
    </item>
  </channel>
</rss>

