<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ACS 5.2 Command set issue in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-5-2-command-set-issue/m-p/1707285#M265242</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;it works after adding:&lt;/P&gt;&lt;P&gt;"aaa authorization config-commands"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I cannot exec any "config mode" commands anymore.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks a lot&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 26 Oct 2011 08:09:01 GMT</pubDate>
    <dc:creator>d1pol01978</dc:creator>
    <dc:date>2011-10-26T08:09:01Z</dc:date>
    <item>
      <title>ACS 5.2 Command set issue</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-2-command-set-issue/m-p/1707281#M265091</link>
      <description>&lt;P&gt;HI ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I had insatalled the ACS 5.2 on Vmware . &lt;/P&gt;&lt;P&gt;As per my requirement i need to configure a user to restricted privilege so that he should be able to execute only the below commands on the switch .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Show ver&lt;/P&gt;&lt;P&gt;Show interfaces&lt;/P&gt;&lt;P&gt;Show ip Interface Brief&lt;/P&gt;&lt;P&gt;Configure terminal&lt;/P&gt;&lt;P&gt;Interface &amp;lt;interface name &amp;gt; &lt;/P&gt;&lt;P&gt;Shutdown&lt;/P&gt;&lt;P&gt;No shutdown&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The users should not be authorized to execute any other commands than above listed one .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After the configuration i was not able to restrict the config mode commands . Once the user is&amp;nbsp; authoized for&amp;nbsp; Configure terminal access&amp;nbsp; he will have full access on the device&amp;nbsp; . &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please let me know how to configure the command set only to allow&amp;nbsp; interface access and he should be able to apply Shutdown and No shutdown command . &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please find the attached command set&amp;nbsp; screen shot . ( I tried disabling IP Routing command but the same was getting authorized )&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Angus&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 01:12:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-2-command-set-issue/m-p/1707281#M265091</guid>
      <dc:creator>Angus Bishop</dc:creator>
      <dc:date>2019-03-11T01:12:42Z</dc:date>
    </item>
    <item>
      <title>ACS 5.2 Command set issue</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-2-command-set-issue/m-p/1707282#M265135</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Did you also configure the appropriate aaa commands on the switch? Please paste the "show run | in aaa" output from the switch. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Jul 2011 12:44:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-2-command-set-issue/m-p/1707282#M265135</guid>
      <dc:creator>zhenningx</dc:creator>
      <dc:date>2011-07-08T12:44:55Z</dc:date>
    </item>
    <item>
      <title>ACS 5.2 Command set issue</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-2-command-set-issue/m-p/1707283#M265166</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm having exactly the same problem:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;my aaa conf:&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;aaa authentication attempts login 10&lt;/P&gt;&lt;P&gt;aaa authentication login default group tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authentication login LOC line local&lt;/P&gt;&lt;P&gt;aaa authentication enable default group tacacs+ enable&lt;/P&gt;&lt;P&gt;aaa authorization exec default group tacacs+ local if-authenticated &lt;/P&gt;&lt;P&gt;aaa authorization commands 1 default group tacacs+ local if-authenticated &lt;/P&gt;&lt;P&gt;aaa authorization commands 15 default group tacacs+ local if-authenticated &lt;/P&gt;&lt;P&gt;aaa accounting exec default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting commands 15 default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting network default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting connection default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting system default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa session-id common&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/3/8/3/65383-Screen%20Shot%202011-10-25%20at%205.49.05%20PM.png" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Once I add permit configure terminal, user can do "conf t" and then execute ANY commands.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Oct 2011 15:50:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-2-command-set-issue/m-p/1707283#M265166</guid>
      <dc:creator>d1pol01978</dc:creator>
      <dc:date>2011-10-25T15:50:16Z</dc:date>
    </item>
    <item>
      <title>ACS 5.2 Command set issue</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-2-command-set-issue/m-p/1707284#M265221</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;try to add command:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authorization config-commands&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Oct 2011 16:03:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-2-command-set-issue/m-p/1707284#M265221</guid>
      <dc:creator>zhenningx</dc:creator>
      <dc:date>2011-10-25T16:03:39Z</dc:date>
    </item>
    <item>
      <title>ACS 5.2 Command set issue</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-2-command-set-issue/m-p/1707285#M265242</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;it works after adding:&lt;/P&gt;&lt;P&gt;"aaa authorization config-commands"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I cannot exec any "config mode" commands anymore.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks a lot&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 26 Oct 2011 08:09:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-2-command-set-issue/m-p/1707285#M265242</guid>
      <dc:creator>d1pol01978</dc:creator>
      <dc:date>2011-10-26T08:09:01Z</dc:date>
    </item>
    <item>
      <title>ACS 5.2 Command set issue</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-2-command-set-issue/m-p/1707286#M265274</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would like to check this command set work only for telnet but not for console ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Nov 2012 05:36:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-2-command-set-issue/m-p/1707286#M265274</guid>
      <dc:creator>kapildev.bhatnagar</dc:creator>
      <dc:date>2012-11-29T05:36:35Z</dc:date>
    </item>
    <item>
      <title>ACS 5.2 Command set issue</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-2-command-set-issue/m-p/1707287#M265295</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The IOS devices are designed to not get affected by authorization in the console port, to enable authorization in the console you need:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authorization console&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Make sure that you have full access from a remote connection before trying this command or you may get locked out if it's not properly configured.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if it helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Nov 2012 13:07:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-2-command-set-issue/m-p/1707287#M265295</guid>
      <dc:creator>mauzamor</dc:creator>
      <dc:date>2012-11-29T13:07:32Z</dc:date>
    </item>
  </channel>
</rss>

