<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Defining services in TACACS Server in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/defining-services-in-tacacs-server/m-p/1292089#M318224</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;To add a custom service to ACS...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Goto "Interface Configuration" then "TACACS+ (Cisco IOS)" and in the "New Services" section enter your new service "nokia-ipso" plus tick the user &amp;amp; group checkboxes. You might need to add "ip" as the protocol depending on what the  actual T+ requests look like.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When you next edit a user or group you'll see a new TACACS+ service into which you can enter your custom attributes:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Nokia-IPSO-User-Role=role_name_on_IPSO&lt;/P&gt;&lt;P&gt;Nokia-IPSO-SuperUser-Access=&amp;lt;0|1&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Note that only very basic syntax checks are applied, basically as long as eahc line has somehing=something ACS will not complain, so its up to you to make sure the values are correct.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 11 Nov 2009 11:21:29 GMT</pubDate>
    <dc:creator>darpotter</dc:creator>
    <dc:date>2009-11-11T11:21:29Z</dc:date>
    <item>
      <title>Defining services in TACACS Server</title>
      <link>https://community.cisco.com/t5/network-access-control/defining-services-in-tacacs-server/m-p/1292088#M318223</link>
      <description>&lt;P&gt;I have to define the following IPSO-specific service in your TACACS+ server:&lt;/P&gt;&lt;P&gt;service = nokia-ipso {&lt;/P&gt;&lt;P&gt;Nokia-IPSO-User-Role = "role_name_on_IPSO"&lt;/P&gt;&lt;P&gt;Nokia-IPSO-SuperUser-Access = &amp;lt;0|1&amp;gt;&lt;/P&gt;&lt;P&gt;}&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How can I do it?&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 23:47:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/defining-services-in-tacacs-server/m-p/1292088#M318223</guid>
      <dc:creator>Ahmed Shahzad</dc:creator>
      <dc:date>2019-03-10T23:47:29Z</dc:date>
    </item>
    <item>
      <title>Re: Defining services in TACACS Server</title>
      <link>https://community.cisco.com/t5/network-access-control/defining-services-in-tacacs-server/m-p/1292089#M318224</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;To add a custom service to ACS...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Goto "Interface Configuration" then "TACACS+ (Cisco IOS)" and in the "New Services" section enter your new service "nokia-ipso" plus tick the user &amp;amp; group checkboxes. You might need to add "ip" as the protocol depending on what the  actual T+ requests look like.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When you next edit a user or group you'll see a new TACACS+ service into which you can enter your custom attributes:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Nokia-IPSO-User-Role=role_name_on_IPSO&lt;/P&gt;&lt;P&gt;Nokia-IPSO-SuperUser-Access=&amp;lt;0|1&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Note that only very basic syntax checks are applied, basically as long as eahc line has somehing=something ACS will not complain, so its up to you to make sure the values are correct.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Nov 2009 11:21:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/defining-services-in-tacacs-server/m-p/1292089#M318224</guid>
      <dc:creator>darpotter</dc:creator>
      <dc:date>2009-11-11T11:21:29Z</dc:date>
    </item>
  </channel>
</rss>

