<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: acs 5.2 command sets permit all commands except... in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-5-2-command-sets-permit-all-commands-except/m-p/1610063#M261792</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If it is command in config mode, you might need to enable "authorization config-commands" on your Cisco router/switch.&lt;/P&gt;&lt;P&gt;If I remember correctly, this command is disabled by default, so the command in config mode won't be sent to ACS for authorization.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 07 Mar 2011 05:33:29 GMT</pubDate>
    <dc:creator>Yudong Wu</dc:creator>
    <dc:date>2011-03-07T05:33:29Z</dc:date>
    <item>
      <title>acs 5.2 command sets permit all commands except...</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-2-command-sets-permit-all-commands-except/m-p/1610062#M261771</link>
      <description>&lt;P&gt;I have everything working on a new 5.2 ACS but:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can only make a command set that permits things and denies all.&lt;/P&gt;&lt;P&gt;I thought with the check box "&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Permit any command that is not in the table below" one&lt;/P&gt;&lt;P&gt;could allow all and specifically deny commands.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I could add for instance:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check "&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Permit any command that is not in the table below"&lt;/P&gt;&lt;P&gt;deny conf&lt;/P&gt;&lt;P&gt;deny set&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and that would allow the user to do all commands except for conf and set.&amp;nbsp; But it&lt;/P&gt;&lt;P&gt;doesn't seem to adminstratively block it, it allows them to still "conf" for instance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yet if I :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Uncheck "&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Permit any command that is not in the table below"&lt;/P&gt;&lt;P&gt;and say&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;permit show&lt;/P&gt;&lt;P&gt;permit exit&lt;/P&gt;&lt;P&gt;...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then it works as expected, it allows the commands that are permitted and denying all unspecified commands.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I know I am in the right command set because the changes I make are reflected immediately.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can someone test the "Permit any command that is not in the table below' and tell me if it works?&amp;nbsp; I can&lt;/P&gt;&lt;P&gt;make it work with the unchecked box, sure, but it would be nice to get it to work.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 00:53:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-2-command-sets-permit-all-commands-except/m-p/1610062#M261771</guid>
      <dc:creator>eugene.tsuno</dc:creator>
      <dc:date>2019-03-11T00:53:08Z</dc:date>
    </item>
    <item>
      <title>Re: acs 5.2 command sets permit all commands except...</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-2-command-sets-permit-all-commands-except/m-p/1610063#M261792</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If it is command in config mode, you might need to enable "authorization config-commands" on your Cisco router/switch.&lt;/P&gt;&lt;P&gt;If I remember correctly, this command is disabled by default, so the command in config mode won't be sent to ACS for authorization.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Mar 2011 05:33:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-2-command-sets-permit-all-commands-except/m-p/1610063#M261792</guid>
      <dc:creator>Yudong Wu</dc:creator>
      <dc:date>2011-03-07T05:33:29Z</dc:date>
    </item>
    <item>
      <title>Re: acs 5.2 command sets permit all commands except...</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-2-command-sets-permit-all-commands-except/m-p/1610064#M261807</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The example says I should be able to put that at the end.&amp;nbsp; However when I paste it&lt;/P&gt;&lt;P&gt;in, it always goes to the top:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authorization config-commands&lt;BR /&gt;aaa authorization exec default group tacacs+ local &lt;BR /&gt;aaa authorization commands 0 default group tacacs+ if-authenticated &lt;BR /&gt;aaa authorization commands 1 default group tacacs+ if-authenticated &lt;BR /&gt;aaa authorization commands 15 default group tacacs+ &lt;BR /&gt;aaa authorization commands 15 groups group tacacs+ none&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't know if that is the problem, but right now it exhibits the same&lt;/P&gt;&lt;P&gt;behaviour, that the table should be allowing things which should be&lt;/P&gt;&lt;P&gt;blocked.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is the a trick to get it to go after "aaa authorization commands" or does it matter?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Mar 2011 18:46:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-2-command-sets-permit-all-commands-except/m-p/1610064#M261807</guid>
      <dc:creator>eugene.tsuno</dc:creator>
      <dc:date>2011-03-07T18:46:58Z</dc:date>
    </item>
    <item>
      <title>Re: acs 5.2 command sets permit all commands except...</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-2-command-sets-permit-all-commands-except/m-p/1610065#M261836</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Okay figured it out. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was using the short name like "conf" for configure.&amp;nbsp; Except the parser obviously wants&lt;/P&gt;&lt;P&gt;the whole name "configure", because that is what is returned back in tacacs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That makes sense, although a note in the docs say how the commands are matched or&lt;/P&gt;&lt;P&gt;if regular expressions can be used would be nice.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Mar 2011 16:52:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-2-command-sets-permit-all-commands-except/m-p/1610065#M261836</guid>
      <dc:creator>eugene.tsuno</dc:creator>
      <dc:date>2011-03-08T16:52:39Z</dc:date>
    </item>
  </channel>
</rss>

