<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Authorization Failed in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/authorization-failed/m-p/1444620#M298414</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear jkatyal&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I m confuse can you help me to authorize some command&amp;nbsp; to a group of ACS. The above 4 steps in my previous mail what i have&amp;nbsp; done what i will achieve from those steps????? what command access i&amp;nbsp; will be authorize??? I have added the above command from ur mail in my&amp;nbsp; routers,but what actually these commands will do????&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I&amp;nbsp; have enabled a privilege level 1 in exec (shell) section of group and in&amp;nbsp; shell authorization set i have done exactly &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE border="0" class="docText"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD valign="top" width="70"&gt;&lt;DIV class="docText"&gt;&lt;STRONG&gt;Step 1. &lt;/STRONG&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="docText"&gt;Go to &lt;SPAN class="docEmphStrong"&gt;Shell Command Authorization&amp;nbsp; Set&lt;/SPAN&gt;, check the &lt;SPAN class="docEmphStrong"&gt;Command&lt;/SPAN&gt; button, and enter&amp;nbsp; &lt;SPAN class="docEmphStrong"&gt;login&lt;/SPAN&gt;.&lt;BR /&gt;&lt;BR /&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD valign="top" width="70"&gt;&lt;DIV class="docText"&gt;&lt;STRONG&gt;Step 2. &lt;/STRONG&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="docText"&gt;Select &lt;SPAN class="docEmphStrong"&gt;Permit&lt;/SPAN&gt; under &lt;SPAN class="docEmphStrong"&gt;Unlisted Arguments&lt;/SPAN&gt;. Repeat this process for the &lt;SPAN class="docEmphStrong"&gt;logout, enable&lt;/SPAN&gt;, and &lt;SPAN class="docEmphStrong"&gt;disable&lt;/SPAN&gt; commands. This is creating a set of commands&amp;nbsp; that is authorized.&lt;BR /&gt;&lt;BR /&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD valign="top" width="70"&gt;&lt;DIV class="docText"&gt;&lt;STRONG&gt;Step 3. &lt;/STRONG&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="docText"&gt;Go to &lt;SPAN class="docEmphStrong"&gt;Shell Command Authorization&amp;nbsp; Set&lt;/SPAN&gt;, check the &lt;SPAN class="docEmphStrong"&gt;Command&lt;/SPAN&gt; button, and enter&amp;nbsp; &lt;SPAN class="docEmphStrong"&gt;show&lt;/SPAN&gt;. Under &lt;SPAN class="docEmphStrong"&gt;Arguments&lt;/SPAN&gt;, enter &lt;SPAN class="docEmphStrong"&gt;permit&amp;nbsp; clock&lt;/SPAN&gt;, and select &lt;SPAN class="docEmphStrong"&gt;deny&lt;/SPAN&gt; for &lt;SPAN class="docEmphStrong"&gt;Unlisted Arguments&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;also i have configured a privilege level 1 user in the&amp;nbsp; router, when i try to telnet to a router i get a prompt of username and&amp;nbsp; password and then when i type a "en"&amp;nbsp; it again propmt&amp;nbsp; me " router&amp;nbsp; &amp;gt;".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Below is the output from console when a&amp;nbsp; privilege level 1 user telent to a router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACS_Router#&lt;/P&gt;&lt;P&gt;*May 26 12:28:18.331: AAA/BIND(0000000D): Bind i/f&lt;BR /&gt; *May 26 12:28:18.331: AAA/AUTHEN/LOGIN (0000000D): Pick method list&amp;nbsp; '123'&lt;BR /&gt; *May 26 12:28:31.331: AAA/AUTHOR (0000000D): Method list id=0 not&amp;nbsp; configured. Skip author&lt;BR /&gt; *May 26 12:28:41.115: AAA/AUTHOR: auth_need : user= 'test' ruser=&amp;nbsp; 'ACS_Router'rem_addr= '192.168.10.4' priv= 0 list= '' AUTHOR-TYPE=&amp;nbsp; 'command'&lt;BR /&gt; *May 26 12:28:41.115: AAA: parse name=tty514 idb type=-1 tty=-1&lt;BR /&gt; *May 26 12:28:41.115: AAA: name=tty514 flags=0x11 type=5 shelf=0 slot=0&amp;nbsp; adapter=0 port=514 channel=0&lt;BR /&gt; *May 26 12:28:41.115: AAA/MEMORY: create_user (0x467487F0) user='test'&amp;nbsp; ruser='ACS_Router' ds0=0 port='tty514' rem_addr='192.168.10.4'&amp;nbsp; authen_type=ASCII service=NONE priv=0 initial_task_id='0', vrf= (id=0)&lt;BR /&gt; *May 26 12:28:41.115: tty514 AAA/AUTHOR/CMD(1324718254): Port='tty514'&amp;nbsp; list='' service=CMD&lt;BR /&gt; *May 26 12:28:41.115: AAA/AUTHOR/CMD: tty514(1324718254) user='test'&lt;BR /&gt; *May 26 12:28:41.115: tty514 AAA/AUTHOR/CMD(1324718254): send AV&amp;nbsp; service=shell&lt;BR /&gt; *May 26 12:28:41.119: tty514 AAA/AUTHOR/CMD(1324718254): send AV&amp;nbsp; cmd=enable&lt;BR /&gt; *May 26 12:28:41.119: tty514 AAA/AUTHOR/CMD(1324718254): send AV&amp;nbsp; cmd-arg=1&lt;BR /&gt; *May 26 12:28:41.119: tty514 AAA/AUTHOR/CMD(1324718254): send AV&amp;nbsp; cmd-arg=&lt;CR&gt;&lt;BR /&gt; *May 26 12:28:41.119: tty514 AAA/AUTHOR/CMD(1324718254): found list&amp;nbsp; "default"&lt;BR /&gt; *May 26 12:28:41.119: tty514 AAA/AUTHOR/CMD(1324718254): Method=tacacs+&amp;nbsp; (tacacs+)&lt;BR /&gt; *May 26 12:28:41.119: AAA/AUTHOR/TAC+: (1324718254): user=test&lt;BR /&gt; *May 26 12:28:41.119: AAA/AUTHOR/TAC+: (1324718254): send AV&amp;nbsp; service=shell&lt;BR /&gt; *May 26 12:28:41.119: AAA/AUTHOR/TAC+: (1324718254): send AV cmd=enable&lt;BR /&gt; *May 26 12:28:41.119: AAA/AUTHOR/TAC+: (1324718254): send AV cmd-arg=1&lt;BR /&gt; *May 26 12:28:41.119: AAA/AUTHOR/TAC+: (1324718254): send AV&amp;nbsp; cmd-arg=&lt;CR&gt;&lt;BR /&gt; *May 26 12:28:41.319: TAC+: (1324718254): received author response&amp;nbsp; status = PASS_ADD&lt;BR /&gt; *May 26 12:28:41.319: AAA/AUTHOR (1324718254): Post authorization status&amp;nbsp; = PASS_ADD&lt;BR /&gt; *May 26 12:28:41.319: AAA/MEMORY: free_user (0x467487F0) user='test'&amp;nbsp; ruser='ACS_Router' port='tty514' rem_addr='192.168.10.4'&amp;nbsp; authen_type=ASCII service=NONE priv=0 vrf= (id=0)&lt;/CR&gt;&lt;/CR&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 26 May 2010 12:52:36 GMT</pubDate>
    <dc:creator>thomasandy32</dc:creator>
    <dc:date>2010-05-26T12:52:36Z</dc:date>
    <item>
      <title>Authorization Failed</title>
      <link>https://community.cisco.com/t5/network-access-control/authorization-failed/m-p/1444617#M298396</link>
      <description>&lt;P&gt;Hello Friends,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I m configuring Shell Command Authorization set for a group of users, After entering username and after that entering password it gives me error" Authorization Failed", I m using evaluation version ACS for windows 4.2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For authorization i have configured as follows:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Step 1.&amp;nbsp; Go to Shell Command Authorization Set, check the Command button, and enter login.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Step 2.&amp;nbsp; Select Permit under Unlisted Arguments. Repeat this process for the logout, enable, and disable commands. This is creating a set of commands that is authorized.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Step 3.&amp;nbsp; Go to Shell Command Authorization Set, check the Command button, and enter show. Under Arguments, enter permit clock, and select deny for Unlisted Arguments.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Step 4.&amp;nbsp; When you are finished, click Submit. This enables some basic command authorization at the Group level.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; I m doing this by cisco press book what command i m authorize to execute. Have anybody face such type of error before.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 00:09:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authorization-failed/m-p/1444617#M298396</guid>
      <dc:creator>thomasandy32</dc:creator>
      <dc:date>2019-03-11T00:09:15Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization Failed</title>
      <link>https://community.cisco.com/t5/network-access-control/authorization-failed/m-p/1444618#M298397</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What product are you trying to authenticate to? A router, an ASA?&lt;/P&gt;&lt;P&gt;Are you also doing authenticaion? Please make sure you do so.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Here you can find a could of examples &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.ciscosystems.com/en/US/docs/ios/sec_user_services/configuration/guide/sec_cfg_authorizatn_ps6350_TSD_Products_Configuration_Guide_Chapter.html#wp1057693"&gt;http://www.ciscosystems.com/en/US/docs/ios/sec_user_services/configuration/guide/sec_cfg_authorizatn_ps6350_TSD_Products_Configuration_Guide_Chapter.html#wp1057693&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Of course the ACS needs to be configured to do command (exec) authorization for specific commands and users.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 May 2010 22:04:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authorization-failed/m-p/1444618#M298397</guid>
      <dc:creator>Panos Kampanakis</dc:creator>
      <dc:date>2010-05-24T22:04:47Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization Failed</title>
      <link>https://community.cisco.com/t5/network-access-control/authorization-failed/m-p/1444619#M298402</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Have you configured command authorization on the Network access device like router or switch because the error message you are gettings is because of exec authorization so for that you need to give privilege 15 on the ACS, if you have group configured then go to that group &amp;gt;&amp;gt; jump to tacacs+ and check the option shell(exec) define the privilege level 15.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;STRONG&gt;Command authorization configuration examole:&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_configuration_example09186a00808d9138.shtml#backinfo"&gt;http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_configuration_example09186a00808d9138.shtml#backinfo&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;In order to configure command authrization on IOS you need the below listed command:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;STRONG&gt;&lt;EM&gt;aaa new-model&lt;BR /&gt;aaa authorization config-commands&lt;BR /&gt;aaa authorization commands 0 default&amp;nbsp; group tacacs+ local&lt;BR /&gt;aaa authorization commands 1 default&amp;nbsp; group tacacs+ local&lt;BR /&gt;aaa authorization commands 15 default group tacacs+ local&lt;BR /&gt;&lt;/EM&gt;&lt;/STRONG&gt;&lt;BR /&gt;On ASA you only need one command&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;STRONG&gt;&lt;EM&gt;aaa authorization command tacacs LOCAL&lt;/EM&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;If you still face any issues then do attach the sh run from the device and faiked attempt logs from the ACS&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;HTH&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;JK&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Do rate helpful&amp;nbsp; posts&lt;/SPAN&gt;-&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 May 2010 23:11:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authorization-failed/m-p/1444619#M298402</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2010-05-24T23:11:02Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization Failed</title>
      <link>https://community.cisco.com/t5/network-access-control/authorization-failed/m-p/1444620#M298414</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear jkatyal&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I m confuse can you help me to authorize some command&amp;nbsp; to a group of ACS. The above 4 steps in my previous mail what i have&amp;nbsp; done what i will achieve from those steps????? what command access i&amp;nbsp; will be authorize??? I have added the above command from ur mail in my&amp;nbsp; routers,but what actually these commands will do????&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I&amp;nbsp; have enabled a privilege level 1 in exec (shell) section of group and in&amp;nbsp; shell authorization set i have done exactly &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE border="0" class="docText"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD valign="top" width="70"&gt;&lt;DIV class="docText"&gt;&lt;STRONG&gt;Step 1. &lt;/STRONG&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="docText"&gt;Go to &lt;SPAN class="docEmphStrong"&gt;Shell Command Authorization&amp;nbsp; Set&lt;/SPAN&gt;, check the &lt;SPAN class="docEmphStrong"&gt;Command&lt;/SPAN&gt; button, and enter&amp;nbsp; &lt;SPAN class="docEmphStrong"&gt;login&lt;/SPAN&gt;.&lt;BR /&gt;&lt;BR /&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD valign="top" width="70"&gt;&lt;DIV class="docText"&gt;&lt;STRONG&gt;Step 2. &lt;/STRONG&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="docText"&gt;Select &lt;SPAN class="docEmphStrong"&gt;Permit&lt;/SPAN&gt; under &lt;SPAN class="docEmphStrong"&gt;Unlisted Arguments&lt;/SPAN&gt;. Repeat this process for the &lt;SPAN class="docEmphStrong"&gt;logout, enable&lt;/SPAN&gt;, and &lt;SPAN class="docEmphStrong"&gt;disable&lt;/SPAN&gt; commands. This is creating a set of commands&amp;nbsp; that is authorized.&lt;BR /&gt;&lt;BR /&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD valign="top" width="70"&gt;&lt;DIV class="docText"&gt;&lt;STRONG&gt;Step 3. &lt;/STRONG&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="docText"&gt;Go to &lt;SPAN class="docEmphStrong"&gt;Shell Command Authorization&amp;nbsp; Set&lt;/SPAN&gt;, check the &lt;SPAN class="docEmphStrong"&gt;Command&lt;/SPAN&gt; button, and enter&amp;nbsp; &lt;SPAN class="docEmphStrong"&gt;show&lt;/SPAN&gt;. Under &lt;SPAN class="docEmphStrong"&gt;Arguments&lt;/SPAN&gt;, enter &lt;SPAN class="docEmphStrong"&gt;permit&amp;nbsp; clock&lt;/SPAN&gt;, and select &lt;SPAN class="docEmphStrong"&gt;deny&lt;/SPAN&gt; for &lt;SPAN class="docEmphStrong"&gt;Unlisted Arguments&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;also i have configured a privilege level 1 user in the&amp;nbsp; router, when i try to telnet to a router i get a prompt of username and&amp;nbsp; password and then when i type a "en"&amp;nbsp; it again propmt&amp;nbsp; me " router&amp;nbsp; &amp;gt;".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Below is the output from console when a&amp;nbsp; privilege level 1 user telent to a router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACS_Router#&lt;/P&gt;&lt;P&gt;*May 26 12:28:18.331: AAA/BIND(0000000D): Bind i/f&lt;BR /&gt; *May 26 12:28:18.331: AAA/AUTHEN/LOGIN (0000000D): Pick method list&amp;nbsp; '123'&lt;BR /&gt; *May 26 12:28:31.331: AAA/AUTHOR (0000000D): Method list id=0 not&amp;nbsp; configured. Skip author&lt;BR /&gt; *May 26 12:28:41.115: AAA/AUTHOR: auth_need : user= 'test' ruser=&amp;nbsp; 'ACS_Router'rem_addr= '192.168.10.4' priv= 0 list= '' AUTHOR-TYPE=&amp;nbsp; 'command'&lt;BR /&gt; *May 26 12:28:41.115: AAA: parse name=tty514 idb type=-1 tty=-1&lt;BR /&gt; *May 26 12:28:41.115: AAA: name=tty514 flags=0x11 type=5 shelf=0 slot=0&amp;nbsp; adapter=0 port=514 channel=0&lt;BR /&gt; *May 26 12:28:41.115: AAA/MEMORY: create_user (0x467487F0) user='test'&amp;nbsp; ruser='ACS_Router' ds0=0 port='tty514' rem_addr='192.168.10.4'&amp;nbsp; authen_type=ASCII service=NONE priv=0 initial_task_id='0', vrf= (id=0)&lt;BR /&gt; *May 26 12:28:41.115: tty514 AAA/AUTHOR/CMD(1324718254): Port='tty514'&amp;nbsp; list='' service=CMD&lt;BR /&gt; *May 26 12:28:41.115: AAA/AUTHOR/CMD: tty514(1324718254) user='test'&lt;BR /&gt; *May 26 12:28:41.115: tty514 AAA/AUTHOR/CMD(1324718254): send AV&amp;nbsp; service=shell&lt;BR /&gt; *May 26 12:28:41.119: tty514 AAA/AUTHOR/CMD(1324718254): send AV&amp;nbsp; cmd=enable&lt;BR /&gt; *May 26 12:28:41.119: tty514 AAA/AUTHOR/CMD(1324718254): send AV&amp;nbsp; cmd-arg=1&lt;BR /&gt; *May 26 12:28:41.119: tty514 AAA/AUTHOR/CMD(1324718254): send AV&amp;nbsp; cmd-arg=&lt;CR&gt;&lt;BR /&gt; *May 26 12:28:41.119: tty514 AAA/AUTHOR/CMD(1324718254): found list&amp;nbsp; "default"&lt;BR /&gt; *May 26 12:28:41.119: tty514 AAA/AUTHOR/CMD(1324718254): Method=tacacs+&amp;nbsp; (tacacs+)&lt;BR /&gt; *May 26 12:28:41.119: AAA/AUTHOR/TAC+: (1324718254): user=test&lt;BR /&gt; *May 26 12:28:41.119: AAA/AUTHOR/TAC+: (1324718254): send AV&amp;nbsp; service=shell&lt;BR /&gt; *May 26 12:28:41.119: AAA/AUTHOR/TAC+: (1324718254): send AV cmd=enable&lt;BR /&gt; *May 26 12:28:41.119: AAA/AUTHOR/TAC+: (1324718254): send AV cmd-arg=1&lt;BR /&gt; *May 26 12:28:41.119: AAA/AUTHOR/TAC+: (1324718254): send AV&amp;nbsp; cmd-arg=&lt;CR&gt;&lt;BR /&gt; *May 26 12:28:41.319: TAC+: (1324718254): received author response&amp;nbsp; status = PASS_ADD&lt;BR /&gt; *May 26 12:28:41.319: AAA/AUTHOR (1324718254): Post authorization status&amp;nbsp; = PASS_ADD&lt;BR /&gt; *May 26 12:28:41.319: AAA/MEMORY: free_user (0x467487F0) user='test'&amp;nbsp; ruser='ACS_Router' port='tty514' rem_addr='192.168.10.4'&amp;nbsp; authen_type=ASCII service=NONE priv=0 vrf= (id=0)&lt;/CR&gt;&lt;/CR&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 26 May 2010 12:52:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authorization-failed/m-p/1444620#M298414</guid>
      <dc:creator>thomasandy32</dc:creator>
      <dc:date>2010-05-26T12:52:36Z</dc:date>
    </item>
  </channel>
</rss>

