<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA 8.2(3): can't &amp;quot;enable&amp;quot; TACACS ACS4.2 user with privilege in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/asa-8-2-3-can-t-quot-enable-quot-tacacs-acs4-2-user-with/m-p/1673975#M238530</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Set the Enable Options in the grp to&lt;/P&gt;&lt;P&gt;Max Priv for any AAA Client&lt;/P&gt;&lt;P&gt;to&lt;/P&gt;&lt;P&gt;Level 15&lt;/P&gt;&lt;P&gt;this will allow enable and also limit your shell options to 10 and the command set you created&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 02 May 2011 12:05:16 GMT</pubDate>
    <dc:creator>Calvin Ryver</dc:creator>
    <dc:date>2011-05-02T12:05:16Z</dc:date>
    <item>
      <title>ASA 8.2(3): can't "enable" TACACS ACS4.2 user with privilege level 10</title>
      <link>https://community.cisco.com/t5/network-access-control/asa-8-2-3-can-t-quot-enable-quot-tacacs-acs4-2-user-with/m-p/1673974#M238528</link>
      <description>&lt;P&gt;I can't seem to enable in ASA with a non-15 privilege level user configured in ACS 4.2 (tacacs).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I enable in IOS device, it enables and "show privilege" shows level 10 as expected. ACS should be configured correctly as it works fine with IOS. User is not set with explicit settings. Group is set with "max enable level" 15 and "shell exec priv level" 15. The enable password is set to the internal ACS PAP password. Works fine in IOS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I enable in ASA, it fails to enable, and ACS log says "Tacacs+ enable privilege too low". I suspect that ASA tries to enable into level 15 explicitely. If I try to issue "enable 10" command in ASA it says: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Enabling to privilege levels is not allowed when configured for&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;AAA authentication. Use 'enable' only.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My config (only showing relevant commands):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;aaa authentication telnet console mmsacs01 LOCAL&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;aaa authentication enable console mmsacs01 LOCAL&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;aaa authorization command mmsacs01 LOCAL&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;aaa authorization exec authentication-server&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 01:02:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/asa-8-2-3-can-t-quot-enable-quot-tacacs-acs4-2-user-with/m-p/1673974#M238528</guid>
      <dc:creator>Roman Rodichev</dc:creator>
      <dc:date>2019-03-11T01:02:39Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 8.2(3): can't "enable" TACACS ACS4.2 user with privilege</title>
      <link>https://community.cisco.com/t5/network-access-control/asa-8-2-3-can-t-quot-enable-quot-tacacs-acs4-2-user-with/m-p/1673975#M238530</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Set the Enable Options in the grp to&lt;/P&gt;&lt;P&gt;Max Priv for any AAA Client&lt;/P&gt;&lt;P&gt;to&lt;/P&gt;&lt;P&gt;Level 15&lt;/P&gt;&lt;P&gt;this will allow enable and also limit your shell options to 10 and the command set you created&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 May 2011 12:05:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/asa-8-2-3-can-t-quot-enable-quot-tacacs-acs4-2-user-with/m-p/1673975#M238530</guid>
      <dc:creator>Calvin Ryver</dc:creator>
      <dc:date>2011-05-02T12:05:16Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 8.2(3): can't "enable" TACACS ACS4.2 user with privilege</title>
      <link>https://community.cisco.com/t5/network-access-control/asa-8-2-3-can-t-quot-enable-quot-tacacs-acs4-2-user-with/m-p/1673976#M238532</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That was it! Thanks a lot!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Roman&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 May 2011 03:00:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/asa-8-2-3-can-t-quot-enable-quot-tacacs-acs4-2-user-with/m-p/1673976#M238532</guid>
      <dc:creator>Roman Rodichev</dc:creator>
      <dc:date>2011-05-03T03:00:17Z</dc:date>
    </item>
  </channel>
</rss>

