<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ACS 5.4 drop users into enable in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-5-4-drop-users-into-enable/m-p/2198037#M234546</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;From the ACS 5.x doc I found, "&lt;/P&gt;&lt;P&gt;You can configure an additional password, stored as part of the internal user record that defines the user's TACACS+ enable password which sets the access level to device. If you do not select this option, the standard user password is also used for TACACS+ enable. If the system is not being used for TACACS+ enable operations, you should not select this option."&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 22 Apr 2013 03:56:18 GMT</pubDate>
    <dc:creator>Saurav Lodh</dc:creator>
    <dc:date>2013-04-22T03:56:18Z</dc:date>
    <item>
      <title>ACS 5.4 drop users into enable</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-4-drop-users-into-enable/m-p/2198034#M234455</link>
      <description>&lt;P&gt;I'm new to ACS 5.4 and have very limited knowledge of the previous versions. I am trying to get users in the external identity store (AD) to be dropped directly into enable mode after being authenticated, since I don't know of a way to set an enable password for users in an external identity store. I think it has something to do with shell attributes but I'm not realy sure.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So here's what I tried.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Linking identity group to external group and provide full command priviliges - enable still didn't work&lt;/P&gt;&lt;P&gt;Creating duplicate users in the internal identity store and setting the password type field to AD1 - That gives me the ability to get to the enable password prompt hit enter on the blank promt then prompts for Old and new passwords but fails everytime with an Error in Authentication. &lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 03:18:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-4-drop-users-into-enable/m-p/2198034#M234455</guid>
      <dc:creator>jeremys8137</dc:creator>
      <dc:date>2019-03-11T03:18:09Z</dc:date>
    </item>
    <item>
      <title>ACS 5.4 drop users into enable</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-4-drop-users-into-enable/m-p/2198035#M234474</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jeremy,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please share the configuration you are using on Cisco&amp;nbsp; Device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards, &lt;BR /&gt;Gurpreet S Puri &lt;BR /&gt; &lt;BR /&gt;**************************** &lt;BR /&gt;Keep Smiling, Peace &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; &lt;BR /&gt;**************************** &lt;BR /&gt; &lt;BR /&gt;(Please Rate Helpful Post)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Apr 2013 07:25:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-4-drop-users-into-enable/m-p/2198035#M234474</guid>
      <dc:creator>Gurpreet Puri</dc:creator>
      <dc:date>2013-04-18T07:25:10Z</dc:date>
    </item>
    <item>
      <title>ACS 5.4 drop users into enable</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-4-drop-users-into-enable/m-p/2198036#M234507</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jeremey: I am really interested to know the answer of this quesiton.&lt;/P&gt;&lt;P&gt;I am eagerly waiting if someone can answer this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: blue;"&gt;Rating useful replies is more useful than saying &lt;SPAN style="color: green;"&gt; "&lt;SPAN style="text-decoration: underline;"&gt;Thank you&lt;/SPAN&gt;"&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 20 Apr 2013 05:45:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-4-drop-users-into-enable/m-p/2198036#M234507</guid>
      <dc:creator>Amjad Abdullah</dc:creator>
      <dc:date>2013-04-20T05:45:02Z</dc:date>
    </item>
    <item>
      <title>ACS 5.4 drop users into enable</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-4-drop-users-into-enable/m-p/2198037#M234546</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;From the ACS 5.x doc I found, "&lt;/P&gt;&lt;P&gt;You can configure an additional password, stored as part of the internal user record that defines the user's TACACS+ enable password which sets the access level to device. If you do not select this option, the standard user password is also used for TACACS+ enable. If the system is not being used for TACACS+ enable operations, you should not select this option."&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Apr 2013 03:56:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-4-drop-users-into-enable/m-p/2198037#M234546</guid>
      <dc:creator>Saurav Lodh</dc:creator>
      <dc:date>2013-04-22T03:56:18Z</dc:date>
    </item>
    <item>
      <title>ACS 5.4 drop users into enable</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-4-drop-users-into-enable/m-p/2198038#M234564</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have found the solution to this problem I will post the screen shots and configs from my equipment in the morning.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Apr 2013 04:01:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-4-drop-users-into-enable/m-p/2198038#M234564</guid>
      <dc:creator>jeremys8137</dc:creator>
      <dc:date>2013-04-22T04:01:19Z</dc:date>
    </item>
    <item>
      <title>ACS 5.4 drop users into enable</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-4-drop-users-into-enable/m-p/2198039#M234614</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Eagerly waiting &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: blue;"&gt;Rating useful replies is more useful than saying &lt;SPAN style="color: green;"&gt; "&lt;SPAN style="text-decoration: underline;"&gt;Thank you&lt;/SPAN&gt;"&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Apr 2013 06:20:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-4-drop-users-into-enable/m-p/2198039#M234614</guid>
      <dc:creator>Amjad Abdullah</dc:creator>
      <dc:date>2013-04-22T06:20:31Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 5.4 drop users into enable</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-4-drop-users-into-enable/m-p/2198040#M234679</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;To all those eagerly awaiting the answer to this question:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This step by step guide assumes that you are using an external identity store or not requiring your internal users to have a separate enable password, and that these have already been configured. Acs is laid out in a way that guides you through the configuration if you know what you are doing. In any implementation you should configure acs in this way: add in your devices (network resources) add your users (users and identity store) configure policy conditions (policy elements) and finally configure your policies (Access Policies).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Step 1.&lt;/P&gt;&lt;TABLE border="0" cellspacing="0" id="cuesBreadcrumbTable"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD nowrap="nowrap"&gt;Policy Elements &amp;gt; &lt;/TD&gt;&lt;TD nowrap="nowrap" style="display: none;"&gt;... &amp;gt; &lt;/TD&gt;&lt;TD nowrap="nowrap" title="Authorization and Permissions "&gt;Authorization and Permissions&amp;nbsp; &amp;gt; &lt;/TD&gt;&lt;TD nowrap="nowrap" title="Device Administration"&gt;Device&amp;nbsp; Administration &amp;gt; &lt;/TD&gt;&lt;TD nowrap="nowrap"&gt;Shell Profiles&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;click the check box for the permit access shell profile then click duplicate.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/1/2/5/136521-acs-shell%20profile.jpg" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the General tab name the profile whatever you want, I chose enable. In the Common Tasks tab change the drop down menu to static and value to 15 for both Default Privilge and maximun Privilge. Hit Submit &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/2/2/5/136522-shell-%20enable.jpg" class="jive-image" /&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/9/2/5/136529-shell-common%20tasks.jpg" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;Step 2&lt;/P&gt;&lt;TABLE border="0" cellspacing="0" id="cuesBreadcrumbTable"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD nowrap="nowrap"&gt;Policy Elements &amp;gt; &lt;/TD&gt;&lt;TD nowrap="nowrap" style="display: none;"&gt;... &amp;gt; &lt;/TD&gt;&lt;TD nowrap="nowrap" title="Authorization and Permissions "&gt;Authorization and Permissions&amp;nbsp; &amp;gt; &lt;/TD&gt;&lt;TD nowrap="nowrap" title="Device Administration"&gt;Device&amp;nbsp; Administration &amp;gt; &lt;/TD&gt;&lt;TD nowrap="nowrap"&gt;Command Sets&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hit create.&lt;/P&gt;&lt;P&gt;I named my command set AllowAllCommands&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/0/3/5/136530-acs-commandset.jpg" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;Step 3.&lt;/P&gt;&lt;DIV style="width: 100%;"&gt;&lt;TABLE border="0" cellspacing="0" id="cuesBreadcrumbTable"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD nowrap="nowrap"&gt;Access Policies &amp;gt; &lt;/TD&gt;&lt;TD nowrap="nowrap" style="display: none;"&gt;... &amp;gt; &lt;/TD&gt;&lt;TD nowrap="nowrap" title="Access Services"&gt;&lt;A&gt;Access&amp;nbsp; Services&lt;/A&gt; &amp;gt; &lt;/TD&gt;&lt;TD nowrap="nowrap" title="Default"&gt;&lt;A&gt;Default Device Admin&lt;/A&gt; &amp;gt; &lt;/TD&gt;&lt;TD nowrap="nowrap"&gt;Authorization&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/4/1/5/136514-Access-policies.jpg" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;in the lower right-hand corner of the screen click customize.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/5/1/5/136515-customize-acs.jpg" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Make sure the customize conditions and result contain Shell Profile, command sets and AD:external groups (see the image below). This allows you to control under which conditions you authenticate users. Click ok&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/6/1/5/136516-customize%20conditions.jpg" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now we need to create a rule to match authentication request against. under the same page now click create in the lower left hand corner.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/1/3/5/136531-acs-rule.jpg" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;Now you are almost done.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The only thing that needs to be updated on the device config is the AAA/tacacs and vty line config.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;here's what i use&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authentication login default group tacacs+ line&lt;/P&gt;&lt;P&gt;aaa authentication login no_tacacs none&lt;/P&gt;&lt;P&gt;aaa authentication enable default group tacacs+ enable&lt;/P&gt;&lt;P&gt;aaa authorization exec default group tacacs+ local&amp;nbsp; &amp;lt; - drops uers into enable&lt;/P&gt;&lt;P&gt;aaa authorization commands 0 default group tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authorization commands 1 default group tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authorization commands 15 default group tacacs+ local&lt;/P&gt;&lt;P&gt;aaa accounting exec default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting commands 15 default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting connection default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting system default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;tacacs-server host 10.125.1.4&lt;/P&gt;&lt;P&gt;tacacs-server host 192.168.36.4&amp;nbsp;&amp;nbsp; &amp;lt;- High availability backup acs&lt;/P&gt;&lt;P&gt;tacacs-server directed-request&lt;/P&gt;&lt;P&gt;tacacs-sefver key 7 xxxxxxxxxxxxxxx&lt;/P&gt;&lt;P&gt;line vty 0 15&lt;/P&gt;&lt;P&gt;login authentication default&lt;/P&gt;&lt;P&gt;username user1 privilge 15 secret sUp3rs3cr3t&amp;nbsp; &amp;lt; fallback local authentication&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Apr 2013 17:02:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-4-drop-users-into-enable/m-p/2198040#M234679</guid>
      <dc:creator>jeremys8137</dc:creator>
      <dc:date>2013-04-22T17:02:24Z</dc:date>
    </item>
    <item>
      <title>ACS 5.4 drop users into enable</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-4-drop-users-into-enable/m-p/2198041#M234800</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;that was my config but i found one from cisco as well.&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/products/ps9911/products_configuration_example09186a0080bc8514.shtml"&gt;&lt;BR /&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/products/ps9911/products_configuration_example09186a0080bc8514.shtml"&gt;http://www.cisco.com/en/US/products/ps9911/products_configuration_example09186a0080bc8514.shtml&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Apr 2013 19:05:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-4-drop-users-into-enable/m-p/2198041#M234800</guid>
      <dc:creator>jeremys8137</dc:creator>
      <dc:date>2013-04-25T19:05:10Z</dc:date>
    </item>
    <item>
      <title>ACS 5.4 drop users into enable</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-4-drop-users-into-enable/m-p/2198042#M234911</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jeremy:&lt;/P&gt;&lt;P&gt;Thank you very much.&lt;/P&gt;&lt;P&gt;To be honest, I thought you want to inforce using a separate enable password than the user password when using external identity. That's why I was interested to see how that is being done.&lt;/P&gt;&lt;P&gt;But as long as you solved your issue, The +5s are really deserved. &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Thank you for sharing back the knowledge. I appreciate if you mark this discussion as "Resolved" so that people find the way easily if they have same issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Greetings,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Amjad&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: blue;"&gt;Rating useful replies is more useful than saying &lt;SPAN style="color: green;"&gt; "&lt;SPAN style="text-decoration: underline;"&gt;Thank you&lt;/SPAN&gt;"&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 28 Apr 2013 05:03:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-4-drop-users-into-enable/m-p/2198042#M234911</guid>
      <dc:creator>Amjad Abdullah</dc:creator>
      <dc:date>2013-04-28T05:03:17Z</dc:date>
    </item>
  </channel>
</rss>

