<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic AAA Radius and Privilege levels in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/aaa-radius-and-privilege-levels/m-p/1683152#M247600</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes you can do it by using Tacacs or Radius:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;aaa authentication login default group tacacs+ enable&lt;/P&gt;&lt;P&gt;aaa authorization exec default group tacacs+ none&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need to manually define all the commands for users in privilege level 7 using "privilege" commands.&lt;/P&gt;&lt;P&gt;For ex:&lt;/P&gt;&lt;P&gt;privilege interface level 7 shutdown&lt;/P&gt;&lt;P&gt;privilege configure level 7 interface&lt;/P&gt;&lt;P&gt;privilege exec level 7 conf t&lt;/P&gt;&lt;P&gt;privilege exec level 7 write memory&lt;/P&gt;&lt;P&gt;privilege exec level 7 reload&lt;/P&gt;&lt;P&gt;privilege exec level 7 show run&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Then you need to configure Tacacs/Radius server to return privilege level 7:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/tech/tk59/technologies_tech_note09186a008009465c.shtml"&gt;http://www.cisco.com/en/US/tech/tk59/technologies_tech_note09186a008009465c.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Zhenning&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 14 Jul 2011 20:47:37 GMT</pubDate>
    <dc:creator>zhenningx</dc:creator>
    <dc:date>2011-07-14T20:47:37Z</dc:date>
    <item>
      <title>AAA Radius and Privilege levels</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-radius-and-privilege-levels/m-p/1683151#M247583</link>
      <description>&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;Is it possible to set up Exec level privleges and their associated commands in RADIUS? I am looking to set up a sub level, say 7, with limited CLI privileges. I can do this locally but want to have the person telnet to router, get authenticated by RADIUS with their normal login ID and password ( like they do everyday when logging into their desktop), and then have them be able to get on the CLI with the corresponding privilege level 7 and limited commands. Is this possible and if so how?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 01:13:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-radius-and-privilege-levels/m-p/1683151#M247583</guid>
      <dc:creator>don.mcdaniel</dc:creator>
      <dc:date>2019-03-11T01:13:25Z</dc:date>
    </item>
    <item>
      <title>AAA Radius and Privilege levels</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-radius-and-privilege-levels/m-p/1683152#M247600</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes you can do it by using Tacacs or Radius:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;aaa authentication login default group tacacs+ enable&lt;/P&gt;&lt;P&gt;aaa authorization exec default group tacacs+ none&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need to manually define all the commands for users in privilege level 7 using "privilege" commands.&lt;/P&gt;&lt;P&gt;For ex:&lt;/P&gt;&lt;P&gt;privilege interface level 7 shutdown&lt;/P&gt;&lt;P&gt;privilege configure level 7 interface&lt;/P&gt;&lt;P&gt;privilege exec level 7 conf t&lt;/P&gt;&lt;P&gt;privilege exec level 7 write memory&lt;/P&gt;&lt;P&gt;privilege exec level 7 reload&lt;/P&gt;&lt;P&gt;privilege exec level 7 show run&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Then you need to configure Tacacs/Radius server to return privilege level 7:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/tech/tk59/technologies_tech_note09186a008009465c.shtml"&gt;http://www.cisco.com/en/US/tech/tk59/technologies_tech_note09186a008009465c.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Zhenning&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Jul 2011 20:47:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-radius-and-privilege-levels/m-p/1683152#M247600</guid>
      <dc:creator>zhenningx</dc:creator>
      <dc:date>2011-07-14T20:47:37Z</dc:date>
    </item>
  </channel>
</rss>

