<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AAA Role Based in Nexus in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/aaa-role-based-in-nexus/m-p/1644359#M266341</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I seem to have it working yet it is not exactly what I call intuitive.&amp;nbsp; In ACS I had to configure the Custom Attributes as&lt;/P&gt;&lt;P&gt;Attribute: cisco-av-pair*shell:roles&lt;/P&gt;&lt;P&gt;Value: network-admin&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any insights would be appreciative.&amp;nbsp; Looks like this is not a bug.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 08 Feb 2011 15:24:06 GMT</pubDate>
    <dc:creator>matthew.huber</dc:creator>
    <dc:date>2011-02-08T15:24:06Z</dc:date>
    <item>
      <title>AAA Role Based in Nexus</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-role-based-in-nexus/m-p/1644358#M266335</link>
      <description>&lt;P&gt;I am using ACS 5.2 and attempting to authorize users through TACACS to Nexus 5.1 code.&amp;nbsp; I seem to have ACS setup correctly based on documentation I received through here.&amp;nbsp; The problem is that the NX/OS doesnt seem to be operating as expected.&amp;nbsp; I performed a debug on the Nexus and received the following output:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;!--[if gte mso 10]&gt;
&lt;style&gt;
 /* Style Definitions */
 table.MsoNormalTable
	{mso-style-name:"Table Normal";
	mso-tstyle-rowband-size:0;
	mso-tstyle-colband-size:0;
	mso-style-noshow:yes;
	mso-style-priority:99;
	mso-style-qformat:yes;
	mso-style-parent:"";
	mso-padding-alt:0in 5.4pt 0in 5.4pt;
	mso-para-margin:0in;
	mso-para-margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	font-size:11.0pt;
	font-family:"Calibri","sans-serif";
	mso-ascii-font-family:Calibri;
	mso-ascii-theme-font:minor-latin;
	mso-fareast-font-family:"Times New Roman";
	mso-fareast-theme-font:minor-fareast;
	mso-hansi-font-family:Calibri;
	mso-hansi-theme-font:minor-latin;}
&lt;/style&gt;
&lt;![endif]--&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 10pt; font-family: &amp;amp;quot;Tahoma&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;2011 Feb&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;8 07:04:23.227576 tacacs: tplus_decode_author_response: Attributes count 3 &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 10pt; font-family: &amp;amp;quot;Tahoma&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;2011 Feb&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;8 07:04:23.227585 tacacs: tplus_decode_author_response: attribute 0 idletime=15 &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 10pt; font-family: &amp;amp;quot;Tahoma&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;2011 Feb&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;8 07:04:23.227596 tacacs: tplus_decode_author_response: attribute 1 priv-lvl=15 &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 10pt; font-family: &amp;amp;quot;Tahoma&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;2011 Feb&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;8 07:04:23.227606 tacacs: tplus_decode_author_response: attribute 2 roles=Network-Admin&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 10pt; font-family: &amp;amp;quot;Tahoma&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;2011 Feb&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;8 07:04:23.227931 tacacs: tplus_getroles(1937)Feature privilege: Disabled &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 10pt; font-family: &amp;amp;quot;Tahoma&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;2011 Feb&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;8 07:04:23.227959 tacacs: tplus_getroles(1957): privilege level 15, corresponding role is: network-admin&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 10pt; font-family: &amp;amp;quot;Tahoma&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;2011 Feb&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;8 07:04:23.227971 tacacs: tplus_decode_author_response: privilege level 15 is specified and corresponding role is network-admin&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 10pt; font-family: &amp;amp;quot;Tahoma&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;2011 Feb&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;8 07:04:23.228007 tacacs: AAA_RESP: status=2, av_count=2, ctx_len=294, server_msg_len=0, server_data_len=0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 10pt; font-family: &amp;amp;quot;Tahoma&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;2011 Feb&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;8 07:04:23.228020 tacacs: AAA_RESP: 0 th attribute network-admin&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 10pt; font-family: &amp;amp;quot;Tahoma&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;2011 Feb&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;8 07:04:23.228029 tacacs: AAA_RESP: 1 th attribute XX.XXX.XX.XX&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 10pt; font-family: &amp;amp;quot;Tahoma&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;2011 Feb&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;8 07:04:23.228039 tacacs: tplus_decode_author_response: exiting for aaa session: 0&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;Yes - in this scenario I do get put into Network-Admin role but that is based on priv and not the roles AV setting.&amp;nbsp; This is important because I have other roles that need assigning (ie VDC-Admin and "READ_CONFIG" which is adding through the CLI)&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;So I figured that setting the Privilege level was causing my problem and reran the same test:&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;!--[if gte mso 10]&gt;
&lt;style&gt;
 /* Style Definitions */
 table.MsoNormalTable
	{mso-style-name:"Table Normal";
	mso-tstyle-rowband-size:0;
	mso-tstyle-colband-size:0;
	mso-style-noshow:yes;
	mso-style-priority:99;
	mso-style-qformat:yes;
	mso-style-parent:"";
	mso-padding-alt:0in 5.4pt 0in 5.4pt;
	mso-para-margin:0in;
	mso-para-margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	font-size:11.0pt;
	font-family:"Calibri","sans-serif";
	mso-ascii-font-family:Calibri;
	mso-ascii-theme-font:minor-latin;
	mso-fareast-font-family:"Times New Roman";
	mso-fareast-theme-font:minor-fareast;
	mso-hansi-font-family:Calibri;
	mso-hansi-theme-font:minor-latin;}
&lt;/style&gt;
&lt;![endif]--&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 10pt; font-family: &amp;amp;quot;Tahoma&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;2011 Feb&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;8 07:10:24.052767 tacacs: tplus_decode_author_response: entering for aaa session: 0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 10pt; font-family: &amp;amp;quot;Tahoma&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;2011 Feb&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;8 07:10:24.052788 tacacs: tplus_decode_author_response: Attributes count 2 &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 10pt; font-family: &amp;amp;quot;Tahoma&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;2011 Feb&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;8 07:10:24.052797 tacacs: tplus_decode_author_response: attribute 0 idletime=15 &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 10pt; font-family: &amp;amp;quot;Tahoma&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;2011 Feb&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;8 07:10:24.052808 tacacs: tplus_decode_author_response: attribute 1 roles=Network-Admin&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 10pt; font-family: &amp;amp;quot;Tahoma&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;2011 Feb&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;8 07:10:24.052825 tacacs: tplus_decode_author_response: privilege level is not specifiedor if specified, roles has been given priority&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 10pt; font-family: &amp;amp;quot;Tahoma&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;2011 Feb&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;8 07:10:24.052855 tacacs: AAA_RESP: status=2, av_count=1, ctx_len=294, server_msg_len=0, server_data_len=0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 10pt; font-family: &amp;amp;quot;Tahoma&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;2011 Feb&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;8 07:10:24.052867 tacacs: AAA_RESP: 0 th attribute XX.XXX.XX.XX&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 10pt; font-family: &amp;amp;quot;Tahoma&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;2011 Feb&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;8 07:10:24.052876 tacacs: tplus_decode_author_response: exiting for aaa session: 0&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;But as you can see in the debugs neither works as expected.&amp;nbsp; I am trying to determine if this is a simple config that I am missing or do I need to open a TAC case to be looked at as a bug?&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;AAA/TACACS config:&lt;/P&gt;&lt;P class="MsoNormal"&gt;aaa authentication login default group TACACS-Servers &lt;BR /&gt;aaa accounting default group TACACS-Servers &lt;BR /&gt;aaa authentication login error-enable&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;feature tacacs+&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;tacacs-server host XX.XXX.XX.XX key REMOVED&lt;BR /&gt;aaa group server tacacs+ tacacs &lt;BR /&gt;aaa group server tacacs+ TACACS-Servers &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; server XX.XXX.XX.XX&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; use-vrf management&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help would be appreciated.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 00:48:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-role-based-in-nexus/m-p/1644358#M266335</guid>
      <dc:creator>matthew.huber</dc:creator>
      <dc:date>2019-03-11T00:48:19Z</dc:date>
    </item>
    <item>
      <title>Re: AAA Role Based in Nexus</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-role-based-in-nexus/m-p/1644359#M266341</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I seem to have it working yet it is not exactly what I call intuitive.&amp;nbsp; In ACS I had to configure the Custom Attributes as&lt;/P&gt;&lt;P&gt;Attribute: cisco-av-pair*shell:roles&lt;/P&gt;&lt;P&gt;Value: network-admin&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any insights would be appreciative.&amp;nbsp; Looks like this is not a bug.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Feb 2011 15:24:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-role-based-in-nexus/m-p/1644359#M266341</guid>
      <dc:creator>matthew.huber</dc:creator>
      <dc:date>2011-02-08T15:24:06Z</dc:date>
    </item>
    <item>
      <title>Re: AAA Role Based in Nexus</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-role-based-in-nexus/m-p/1644360#M266345</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Matthew,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm also blocked by this kind of custom attributes.&lt;/P&gt;&lt;P&gt;We are migrating from TACACS 4.1 to 5.2, but the fields Custom Attributes Shell Exec have disapeared.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In attachment, I've put 2 screenshot.&lt;/P&gt;&lt;P&gt;The config for v4.1 is running, but it's impossible for me to have this config well working on the v5.2.&lt;/P&gt;&lt;P&gt;In 4.1, in user creation/edition, we check the "Shell (exec)" checkbox, then the "Custom attributes" checkbox, and put one or several lines of parameters.&lt;BR /&gt;In my exemple, for Nexus, the working line for v4.1 is the following :&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;BR /&gt;&lt;STRONG&gt;shell:roles*network-admin&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On TACACS 5.2, I've add a new field in User attributes by going into :&lt;/P&gt;&lt;P&gt;System Administration -&amp;gt; Configuration -&amp;gt; Dictionaries -&amp;gt; Identity -&amp;gt; Internal Users&lt;/P&gt;&lt;P&gt;Create =&amp;gt; and I've tried several configurations of Attribute names and values, but without success.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;Parameter name (Attribute)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Value&lt;BR /&gt;==========================================================&lt;BR /&gt;shell:roles&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; network-admin&lt;BR /&gt;shell:roles&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; *network-admin&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;Custom attributes&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; shell:roles*network-admin&lt;BR /&gt;shell&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; shell:roles*network-admin&lt;BR /&gt;shell&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; roles*network-admin&lt;BR /&gt;roles&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; network-admin&lt;BR /&gt;cisco-av-pair*shell:roles&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; network-admin&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Courier New;"&gt;cisco-av-pair*shell&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; roles*network-admin&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Courier New;"&gt;cisco-av-pair&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; shell:roles*network-admin&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Whatever the parameter I set, result is always the same when I perform a &lt;SPAN style="font-family: courier new,courier;"&gt;&lt;STRONG&gt;sh user-account&lt;/STRONG&gt;&lt;/SPAN&gt; on Nexus ...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;Nexus# sh user-account&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;user:em739&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; roles:&lt;/SPAN&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&lt;SPAN style="color: #ff0000;"&gt;vdc-operator&lt;BR /&gt;&lt;/SPAN&gt;account created through REMOTE authentication&lt;BR /&gt;Credentials such as ssh server key will be cached temporarily only for this user account&lt;BR /&gt;Local login not possible&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The good results (like with v4.1) should be :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;Nexus# sh user-account&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;user:em739&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; roles:&lt;/SPAN&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&lt;SPAN style="color: #339966;"&gt;&lt;STRONG&gt;network-admin&lt;BR /&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;account created through REMOTE authentication&lt;BR /&gt;Credentials such as ssh server key will be cached temporarily only for this user account&lt;BR /&gt;Local login not possible&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you find a solution for your problem ?&lt;/P&gt;&lt;P&gt;Thank you very much.&lt;/P&gt;&lt;P&gt;Fred.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Apr 2011 08:59:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-role-based-in-nexus/m-p/1644360#M266345</guid>
      <dc:creator>networkservicesdexia</dc:creator>
      <dc:date>2011-04-04T08:59:47Z</dc:date>
    </item>
  </channel>
</rss>

