<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ACS 5.1 Command sets, Shells and other stuff. in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-5-1-command-sets-shells-and-other-stuff/m-p/1628762#M266366</link>
    <description>&lt;P&gt;I'm a complete noob to ACS, and not strong in the AAA department.&amp;nbsp; I'm trying to implement command sets for helpdesk trouble shooting.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I didn't setup the ACS server so I'm assuming that it was setup correctly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As it stands, the people that need ro login into remote devices, can and have access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have two problems.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) No matter what I do, my test user always logs in with the privilege 15 shell.&amp;nbsp; It doesn't matter what I do to the group in the authorization area of the Access Policies, level 15 privilege.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2)&amp;nbsp; When I apply the aaa authorization command 1 default group tacacs+ to my test AP, every account fails with commands at that privilege level.&amp;nbsp; Same for level 0 and level 15.&amp;nbsp; The command sets I have configured never even enter the picture.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My test authorization policy for my test user is setup correctly, mapped to the correct AD group, and has the command set applied.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If anyone has a clue, let me know and I'll supply more information.&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 00:48:00 GMT</pubDate>
    <dc:creator>lkqciscotech</dc:creator>
    <dc:date>2019-03-11T00:48:00Z</dc:date>
    <item>
      <title>ACS 5.1 Command sets, Shells and other stuff.</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-1-command-sets-shells-and-other-stuff/m-p/1628762#M266366</link>
      <description>&lt;P&gt;I'm a complete noob to ACS, and not strong in the AAA department.&amp;nbsp; I'm trying to implement command sets for helpdesk trouble shooting.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I didn't setup the ACS server so I'm assuming that it was setup correctly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As it stands, the people that need ro login into remote devices, can and have access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have two problems.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) No matter what I do, my test user always logs in with the privilege 15 shell.&amp;nbsp; It doesn't matter what I do to the group in the authorization area of the Access Policies, level 15 privilege.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2)&amp;nbsp; When I apply the aaa authorization command 1 default group tacacs+ to my test AP, every account fails with commands at that privilege level.&amp;nbsp; Same for level 0 and level 15.&amp;nbsp; The command sets I have configured never even enter the picture.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My test authorization policy for my test user is setup correctly, mapped to the correct AD group, and has the command set applied.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If anyone has a clue, let me know and I'll supply more information.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 00:48:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-1-command-sets-shells-and-other-stuff/m-p/1628762#M266366</guid>
      <dc:creator>lkqciscotech</dc:creator>
      <dc:date>2019-03-11T00:48:00Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 5.1 Command sets, Shells and other stuff.</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-1-command-sets-shells-and-other-stuff/m-p/1628763#M266367</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;have checked the privilege level of the user in your ACS? If it has level 15 that will explain things. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 04 Feb 2011 21:17:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-1-command-sets-shells-and-other-stuff/m-p/1628763#M266367</guid>
      <dc:creator>PAUL GILBERT ARIAS</dc:creator>
      <dc:date>2011-02-04T21:17:33Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 5.1 Command sets, Shells and other stuff.</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-1-command-sets-shells-and-other-stuff/m-p/1628764#M266368</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Not sure how.&amp;nbsp; ACS is AD integrated.&amp;nbsp; There are no internal users setup.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 04 Feb 2011 21:26:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-1-command-sets-shells-and-other-stuff/m-p/1628764#M266368</guid>
      <dc:creator>lkqciscotech</dc:creator>
      <dc:date>2011-02-04T21:26:54Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 5.1 Command sets, Shells and other stuff.</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-1-command-sets-shells-and-other-stuff/m-p/1628765#M266369</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think on this version there is a tab where the users are created. There you might also see the dynamically added users when there is a AD. I don't remember well on this version.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 04 Feb 2011 21:39:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-1-command-sets-shells-and-other-stuff/m-p/1628765#M266369</guid>
      <dc:creator>PAUL GILBERT ARIAS</dc:creator>
      <dc:date>2011-02-04T21:39:05Z</dc:date>
    </item>
  </channel>
</rss>

