<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: No Command Authorization for show run in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/no-command-authorization-for-show-run/m-p/3803110#M24938</link>
    <description>&lt;P&gt;You seem missing&lt;/P&gt;
&lt;PRE&gt;aaa authorization commands 1 default group tacacs+ if-authenticated 
&lt;/PRE&gt;
&lt;P&gt;and,&lt;/P&gt;
&lt;PRE&gt;aaa accounting commands 1 default start-stop group tacacs+&lt;/PRE&gt;
&lt;P&gt;Also check the AAA logs. If using ISE as the T+ server, check ISE T+ Live Logs and verify the command sets assigned to the user.&lt;/P&gt;</description>
    <pubDate>Sat, 16 Feb 2019 02:44:28 GMT</pubDate>
    <dc:creator>hslai</dc:creator>
    <dc:date>2019-02-16T02:44:28Z</dc:date>
    <item>
      <title>No Command Authorization for show run</title>
      <link>https://community.cisco.com/t5/network-access-control/no-command-authorization-for-show-run/m-p/3802480#M24936</link>
      <description>&lt;P&gt;Although Username has Privilege 15, &lt;STRONG&gt;show run&lt;/STRONG&gt; command does not have authorization&lt;/P&gt;
&lt;P&gt;All other commands works.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Below are AAA commands configured on switch.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;========&lt;/P&gt;
&lt;P&gt;username admin privilege 15 secret 5 xxx&lt;BR /&gt;username netadmin privilege 15 secret 5 xxx&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;aaa new-model&lt;BR /&gt;aaa authentication login default group tacacs+ local&lt;BR /&gt;aaa authentication login console group tacacs+ local&lt;BR /&gt;aaa authentication enable default none&lt;BR /&gt;&lt;STRONG&gt;aaa authorization console&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;aaa authorization config-commands&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;aaa authorization exec default group tacacs+ if-authenticated &lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;aaa authorization exec always if-authenticated &lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;aaa authorization commands 15 default group tacacs+ if-authenticated&lt;/STRONG&gt; &lt;BR /&gt;aaa accounting exec default start-stop group tacacs+&lt;BR /&gt;aaa accounting commands 15 default stop-only group tacacs+&lt;BR /&gt;aaa accounting system default start-stop group tacacs+&lt;BR /&gt;aaa session-id common&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;=================&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Feb 2019 05:47:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/no-command-authorization-for-show-run/m-p/3802480#M24936</guid>
      <dc:creator>Dave93</dc:creator>
      <dc:date>2019-02-15T05:47:28Z</dc:date>
    </item>
    <item>
      <title>Re: No Command Authorization for show run</title>
      <link>https://community.cisco.com/t5/network-access-control/no-command-authorization-for-show-run/m-p/3803110#M24938</link>
      <description>&lt;P&gt;You seem missing&lt;/P&gt;
&lt;PRE&gt;aaa authorization commands 1 default group tacacs+ if-authenticated 
&lt;/PRE&gt;
&lt;P&gt;and,&lt;/P&gt;
&lt;PRE&gt;aaa accounting commands 1 default start-stop group tacacs+&lt;/PRE&gt;
&lt;P&gt;Also check the AAA logs. If using ISE as the T+ server, check ISE T+ Live Logs and verify the command sets assigned to the user.&lt;/P&gt;</description>
      <pubDate>Sat, 16 Feb 2019 02:44:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/no-command-authorization-for-show-run/m-p/3803110#M24938</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2019-02-16T02:44:28Z</dc:date>
    </item>
  </channel>
</rss>

