<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cisco ACS 5.2 command set in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-2-command-set/m-p/1783511#M241959</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please also take a screenshot of the authorization rule that your level 2 support team is matching so we know what you are assigning them&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 01 Sep 2011 05:46:44 GMT</pubDate>
    <dc:creator>Nicolas Darchis</dc:creator>
    <dc:date>2011-09-01T05:46:44Z</dc:date>
    <item>
      <title>Cisco ACS 5.2 command set</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-2-command-set/m-p/1783508#M241956</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In Cisco ACS 5.2 I have two groups. &lt;/P&gt;&lt;P&gt;Group1--Full access group&lt;/P&gt;&lt;P&gt;Group2--Read only group&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would like to block following commands for group 2 which is ready only users. These user group has access only till EXEC mode and they are &lt;/P&gt;&lt;P&gt;able to run all show commands.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show tech-supports&lt;/P&gt;&lt;P&gt;telnet&lt;/P&gt;&lt;P&gt;ssh&lt;/P&gt;&lt;P&gt;rlong &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can anyone help on this please ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Santosh Kotkar&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 01:21:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-2-command-set/m-p/1783508#M241956</guid>
      <dc:creator>santosh.kotkar</dc:creator>
      <dc:date>2019-03-11T01:21:25Z</dc:date>
    </item>
    <item>
      <title>Cisco ACS 5.2 command set</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-2-command-set/m-p/1783509#M241957</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Create a shell command set authorizing only what you want the users to execute.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the authorization policy screen click Customize, move "command sets" to the right column, click OK.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now create an authorization policy that triggers on group membership and assign the shell command set to it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 31 Aug 2011 13:58:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-2-command-set/m-p/1783509#M241957</guid>
      <dc:creator>Javier Henderson</dc:creator>
      <dc:date>2011-08-31T13:58:26Z</dc:date>
    </item>
    <item>
      <title>Cisco ACS 5.2 command set</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-2-command-set/m-p/1783510#M241958</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Javier&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have Level-2 support group and would like to revoke show tech-support, telnet and ssh command access only but its not working, still these user can run these commands.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have allowed clear counters which is working fine. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have attached screenshot, is there any idea or I am making any mistake in command set ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Santosh&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/3/0/8/57803-ScreenShot013.jpg" class="jive-image" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Sep 2011 00:42:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-2-command-set/m-p/1783510#M241958</guid>
      <dc:creator>santosh.kotkar</dc:creator>
      <dc:date>2011-09-01T00:42:49Z</dc:date>
    </item>
    <item>
      <title>Cisco ACS 5.2 command set</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-2-command-set/m-p/1783511#M241959</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please also take a screenshot of the authorization rule that your level 2 support team is matching so we know what you are assigning them&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Sep 2011 05:46:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-2-command-set/m-p/1783511#M241959</guid>
      <dc:creator>Nicolas Darchis</dc:creator>
      <dc:date>2011-09-01T05:46:44Z</dc:date>
    </item>
    <item>
      <title>Cisco ACS 5.2 command set</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-2-command-set/m-p/1783512#M241960</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Nicolas&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here are some screenshot of Authorization rule&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/5/0/8/57805-ScreenShot019.jpg" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/9/0/8/57809-ScreenShot020.jpg" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Santosh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Sep 2011 06:29:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-2-command-set/m-p/1783512#M241960</guid>
      <dc:creator>santosh.kotkar</dc:creator>
      <dc:date>2011-09-01T06:29:10Z</dc:date>
    </item>
    <item>
      <title>Cisco ACS 5.2 command set</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-2-command-set/m-p/1783513#M241961</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Strange. It looks good.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Maybe you can look on "monitoring and reports"-&amp;gt; aaa catalog-&amp;gt; tacacs authorization, for commands that got authorized to level2 users but that shouldn't have been authorized. If you click on the magnifying glass for details, you should see why ACS authorized.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Sep 2011 06:36:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-2-command-set/m-p/1783513#M241961</guid>
      <dc:creator>Nicolas Darchis</dc:creator>
      <dc:date>2011-09-01T06:36:07Z</dc:date>
    </item>
    <item>
      <title>Cisco ACS 5.2 command set</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-2-command-set/m-p/1783514#M241962</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Authorization is just showing allowed command set&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Still not sure what's going on&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Following are the logs, just showing allowed but not showing actaul command&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/4/1/8/57814-ScreenShot021.jpg" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/5/1/8/57815-ScreenShot022.jpg" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/6/1/8/57816-ScreenShot023.jpg" class="jive-image" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Sep 2011 07:09:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-2-command-set/m-p/1783514#M241962</guid>
      <dc:creator>santosh.kotkar</dc:creator>
      <dc:date>2011-09-01T07:09:39Z</dc:date>
    </item>
    <item>
      <title>Cisco ACS 5.2 command set</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-2-command-set/m-p/1783515#M241963</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Your first screenshot shows that show run and conf t were denied ...&lt;/P&gt;&lt;P&gt;I don't get what is the problem then ??&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Sep 2011 07:12:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-2-command-set/m-p/1783515#M241963</guid>
      <dc:creator>Nicolas Darchis</dc:creator>
      <dc:date>2011-09-01T07:12:54Z</dc:date>
    </item>
    <item>
      <title>Cisco ACS 5.2 command set</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-2-command-set/m-p/1783516#M241964</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;"Show run and config t" is already deny for level 2 users, which is correct.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem is "show tech-support, telnet and ssh" commands are allowed which we would like to revoke for level 2 users.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In my first screenshot these are the command sets I have created to stop access. Some reason they are still working.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope you got my issues. Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Santosh &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Sep 2011 23:31:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-2-command-set/m-p/1783516#M241964</guid>
      <dc:creator>santosh.kotkar</dc:creator>
      <dc:date>2011-09-01T23:31:38Z</dc:date>
    </item>
    <item>
      <title>Cisco ACS 5.2 command set</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-2-command-set/m-p/1783517#M241965</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Sorry previous screenshot was confusing, this updated/current screenshot&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/7/5/8/57857-ScreenShot024.jpg" class="jive-image" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Sep 2011 23:47:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-2-command-set/m-p/1783517#M241965</guid>
      <dc:creator>santosh.kotkar</dc:creator>
      <dc:date>2011-09-01T23:47:08Z</dc:date>
    </item>
    <item>
      <title>Cisco ACS 5.2 command set</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-2-command-set/m-p/1783518#M241966</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;fair enough. But your passed/failed authentication screenshot does not show a telnet or ssh command that should have been denied but was accepted. That's what we're interested in.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Sep 2011 05:26:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-2-command-set/m-p/1783518#M241966</guid>
      <dc:creator>Nicolas Darchis</dc:creator>
      <dc:date>2011-09-02T05:26:22Z</dc:date>
    </item>
    <item>
      <title>Cisco ACS 5.2 command set</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-2-command-set/m-p/1783519#M241967</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, Authorization logs are not showing all details. just now I have run those commands (telnet, ssh and &lt;/P&gt;&lt;P&gt;show tech-support unprivileged) but its showing status "passed" nothing more details&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/2/4/2/58242-ScreenShot025.jpg" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/0/5/2/58250-ScreenShot026.jpg" class="jive-image" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Sep 2011 06:04:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-2-command-set/m-p/1783519#M241967</guid>
      <dc:creator>santosh.kotkar</dc:creator>
      <dc:date>2011-09-02T06:04:27Z</dc:date>
    </item>
    <item>
      <title>Cisco ACS 5.2 command set</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-2-command-set/m-p/1783520#M241968</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Any suggestion guys ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Santosh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Sep 2011 01:48:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-2-command-set/m-p/1783520#M241968</guid>
      <dc:creator>santosh.kotkar</dc:creator>
      <dc:date>2011-09-06T01:48:46Z</dc:date>
    </item>
    <item>
      <title>Cisco ACS 5.2 command set</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-2-command-set/m-p/1783521#M241969</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No no, you missed something. If the user types "telnet", you should have a passed entry for command "telnet" on ACS and it seems you don't !&lt;/P&gt;&lt;P&gt;That means that the switch never asks ACS to authorize that command or not ...&lt;/P&gt;&lt;P&gt;switch config issue ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Sep 2011 06:17:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-2-command-set/m-p/1783521#M241969</guid>
      <dc:creator>Nicolas Darchis</dc:creator>
      <dc:date>2011-09-06T06:17:27Z</dc:date>
    </item>
  </channel>
</rss>

