<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ACS 4.2 providing show commands only in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-acs-4-2-providing-show-commands-only/m-p/1699876#M248140</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;H3&gt;Configuring a Shell Command&amp;nbsp; Authorization Set for a User &lt;/H3&gt;&lt;P&gt; is it &lt;STRONG&gt;Group?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt; Yes it is&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The same link i followed for my config setup&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 10 Jun 2011 13:01:49 GMT</pubDate>
    <dc:creator>sridhar.gogineni</dc:creator>
    <dc:date>2011-06-10T13:01:49Z</dc:date>
    <item>
      <title>Cisco ACS 4.2 providing show commands only</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-4-2-providing-show-commands-only/m-p/1699870#M248039</link>
      <description>&lt;P&gt;I am trying to create a user so that i can provide him only to run show commands nothing else.&lt;/P&gt;&lt;P&gt;1) Created a user in ACS&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) Create Shell command Autorization Set - ReadOnly&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Unmatched Commands - Deny&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Commands Added&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;exit&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3) Created a group - HelpDesk with the following TACACS+ Settings&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Shell (exec) is checked&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Priviledge level is check with 15 as the assigned level&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Assign a Shell Command Authorization Set for any network device - selected&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ReadOnly - shell command autorization set seleted&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have configured following on my router&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authorization config-commands&lt;/P&gt;&lt;P&gt;aaa authorization commands 0 default&amp;nbsp; group tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authorization commands 1 default&amp;nbsp; group tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authorization commands 15 default group tacacs+ local&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But still user can run config t and other commands.Some one help me how to fix this&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 01:09:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-4-2-providing-show-commands-only/m-p/1699870#M248039</guid>
      <dc:creator>sridhar.gogineni</dc:creator>
      <dc:date>2019-03-11T01:09:33Z</dc:date>
    </item>
    <item>
      <title>Cisco ACS 4.2 providing show commands only</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-4-2-providing-show-commands-only/m-p/1699871#M248051</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you check the user authorization profile? is it inherited from the group?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Anisha&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;P.S.: please mark this thread as answered if you feel your query is resolved. Do rate helpful posts. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Jun 2011 11:38:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-4-2-providing-show-commands-only/m-p/1699871#M248051</guid>
      <dc:creator>andamani</dc:creator>
      <dc:date>2011-06-10T11:38:08Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ACS 4.2 providing show commands only</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-4-2-providing-show-commands-only/m-p/1699872#M248067</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry i am bit new where can i check &lt;/P&gt;&lt;P&gt;Can you check the user authorization profile?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You mean &lt;/P&gt;&lt;P&gt;Group to which the user is assigned:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If that is the case we have assigned to correct group&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Jun 2011 11:42:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-4-2-providing-show-commands-only/m-p/1699872#M248067</guid>
      <dc:creator>sridhar.gogineni</dc:creator>
      <dc:date>2011-06-10T11:42:16Z</dc:date>
    </item>
    <item>
      <title>Cisco ACS 4.2 providing show commands only</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-4-2-providing-show-commands-only/m-p/1699873#M248082</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;yes. So does the user inherit the authorization profile from the group or it does not?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Anisha&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;P.S.: please mark this thread as answered if you feel your query is&amp;nbsp; resolved. Do rate helpful posts. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Jun 2011 12:45:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-4-2-providing-show-commands-only/m-p/1699873#M248082</guid>
      <dc:creator>andamani</dc:creator>
      <dc:date>2011-06-10T12:45:07Z</dc:date>
    </item>
    <item>
      <title>Cisco ACS 4.2 providing show commands only</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-4-2-providing-show-commands-only/m-p/1699874#M248101</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your help&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So does the user inherit the authorization profile from the group or it does not?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes,But as i told before Shell command Autorization Set is not working and user can access conf t command.I only want to use them show commands which i have configured (explained in first post)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Jun 2011 12:50:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-4-2-providing-show-commands-only/m-p/1699874#M248101</guid>
      <dc:creator>sridhar.gogineni</dc:creator>
      <dc:date>2011-06-10T12:50:19Z</dc:date>
    </item>
    <item>
      <title>Cisco ACS 4.2 providing show commands only</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-4-2-providing-show-commands-only/m-p/1699875#M248121</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am trying to figure what might be the case. Hence asking you the question.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Which option is checked in the &lt;/P&gt;&lt;H3&gt;Configuring a Shell Command&amp;nbsp; Authorization Set for a User &lt;/H3&gt;&lt;P&gt; is it &lt;STRONG&gt;Group?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The configruation seems fine to me. Just for one more configuration can you please check if the configuration is as per the link:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_configuration_example09186a00808d9138.shtml"&gt;http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_configuration_example09186a00808d9138.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Anisha&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;P.S.: please mark this thread as answered if you&amp;nbsp; feel your query is&amp;nbsp; resolved. Do rate helpful posts. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Jun 2011 12:59:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-4-2-providing-show-commands-only/m-p/1699875#M248121</guid>
      <dc:creator>andamani</dc:creator>
      <dc:date>2011-06-10T12:59:18Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ACS 4.2 providing show commands only</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-4-2-providing-show-commands-only/m-p/1699876#M248140</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;H3&gt;Configuring a Shell Command&amp;nbsp; Authorization Set for a User &lt;/H3&gt;&lt;P&gt; is it &lt;STRONG&gt;Group?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt; Yes it is&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The same link i followed for my config setup&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Jun 2011 13:01:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-4-2-providing-show-commands-only/m-p/1699876#M248140</guid>
      <dc:creator>sridhar.gogineni</dc:creator>
      <dc:date>2011-06-10T13:01:49Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ACS 4.2 providing show commands only</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-4-2-providing-show-commands-only/m-p/1699877#M248158</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hmmm.. Ok. So what do the TACACS Administration logs say when you log in and try the "config t" command ? i.e. reports and activity &amp;gt; Tacacs administration &amp;gt; active.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Anisha&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;P.S.: please mark this thread as answered if you&amp;nbsp; feel your query is&amp;nbsp; resolved. Do rate helpful posts. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Jun 2011 14:04:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-4-2-providing-show-commands-only/m-p/1699877#M248158</guid>
      <dc:creator>andamani</dc:creator>
      <dc:date>2011-06-10T14:04:55Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ACS 4.2 providing show commands only</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-4-2-providing-show-commands-only/m-p/1699878#M248172</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Looks like user is not getting mapped with the respective group or user is also configured for shell command authorization set and taking precedence over group.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Run the following debugs on the IOS device&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;debug tacacs&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;debug aaa authen&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;debug aaa autho&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;term mon&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Run "config t" command, on the ACS logs look for the group you are getting mapped and match with the group name you want it to map with.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Rgds, Jatin&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Do rate helpful posts-&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 12 Jun 2011 15:38:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-4-2-providing-show-commands-only/m-p/1699878#M248172</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2011-06-12T15:38:52Z</dc:date>
    </item>
  </channel>
</rss>

