<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Command Authorization Issue in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/command-authorization-issue/m-p/1625651#M257972</link>
    <description>&lt;P&gt;Hi There, I am trying to setup command authorization in ACS 4.2.1.15 but its partially working.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have setup three sets of shell command ... full access is working fine. another one is read only which is causing problem. in this command set I have allowed show commands and clear commands....everything is working fine but users can execute Write command from # prompt and they can also execute copy running-config startup-config....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have define command set as below:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;clear&amp;nbsp;&amp;nbsp; permit arp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show&amp;nbsp;&amp;nbsp; permit interface&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; permit version&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; permit port-security&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i hav selected unmatched command as deny and unmatched argument as deny.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I dont know why its happening. am i missing something.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please help...&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 00:45:17 GMT</pubDate>
    <dc:creator>jain.nitin</dc:creator>
    <dc:date>2019-03-11T00:45:17Z</dc:date>
    <item>
      <title>Command Authorization Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/command-authorization-issue/m-p/1625651#M257972</link>
      <description>&lt;P&gt;Hi There, I am trying to setup command authorization in ACS 4.2.1.15 but its partially working.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have setup three sets of shell command ... full access is working fine. another one is read only which is causing problem. in this command set I have allowed show commands and clear commands....everything is working fine but users can execute Write command from # prompt and they can also execute copy running-config startup-config....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have define command set as below:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;clear&amp;nbsp;&amp;nbsp; permit arp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show&amp;nbsp;&amp;nbsp; permit interface&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; permit version&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; permit port-security&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i hav selected unmatched command as deny and unmatched argument as deny.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I dont know why its happening. am i missing something.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please help...&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 00:45:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/command-authorization-issue/m-p/1625651#M257972</guid>
      <dc:creator>jain.nitin</dc:creator>
      <dc:date>2019-03-11T00:45:17Z</dc:date>
    </item>
    <item>
      <title>Re: Command Authorization Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/command-authorization-issue/m-p/1625652#M257977</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you post the AAA configuration on the router? Did you configure command authorization on it?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 30 Jan 2011 18:33:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/command-authorization-issue/m-p/1625652#M257977</guid>
      <dc:creator>Javier Henderson</dc:creator>
      <dc:date>2011-01-30T18:33:21Z</dc:date>
    </item>
  </channel>
</rss>

