<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PIX Authorization issue in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/pix-authorization-issue/m-p/1292199#M328630</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What will this command do?, Does it make me use my own individual enable password?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 23 Oct 2009 15:07:05 GMT</pubDate>
    <dc:creator>networker99</dc:creator>
    <dc:date>2009-10-23T15:07:05Z</dc:date>
    <item>
      <title>PIX Authorization issue</title>
      <link>https://community.cisco.com/t5/network-access-control/pix-authorization-issue/m-p/1292188#M328619</link>
      <description>&lt;P&gt;Using AAA on a PIX, authentication works fine and the AAA user has full rights over PIX, but aaa authorization always fails when going into conf t&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 23:45:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pix-authorization-issue/m-p/1292188#M328619</guid>
      <dc:creator>networker99</dc:creator>
      <dc:date>2019-03-10T23:45:11Z</dc:date>
    </item>
    <item>
      <title>Re: PIX Authorization issue</title>
      <link>https://community.cisco.com/t5/network-access-control/pix-authorization-issue/m-p/1292189#M328620</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If this is a ACS user, you need to add this on ACS&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Under shared profile component &amp;gt; shell command authorization set &amp;gt; type &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"configure" under unmatched commands: and type permit terminal &lt;CR&gt; under the permit unmatched args and make sure this has been applied on the user or group and then try again.&lt;/CR&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;JK&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Plz rate helpful posts-&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Oct 2009 13:03:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pix-authorization-issue/m-p/1292189#M328620</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2009-10-23T13:03:22Z</dc:date>
    </item>
    <item>
      <title>Re: PIX Authorization issue</title>
      <link>https://community.cisco.com/t5/network-access-control/pix-authorization-issue/m-p/1292190#M328621</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Access is still denied.  The restricted group works.. (unable to get into enable mode), but the full access group can get into enable mode but not conf t&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Oct 2009 14:05:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pix-authorization-issue/m-p/1292190#M328621</guid>
      <dc:creator>networker99</dc:creator>
      <dc:date>2009-10-23T14:05:35Z</dc:date>
    </item>
    <item>
      <title>Re: PIX Authorization issue</title>
      <link>https://community.cisco.com/t5/network-access-control/pix-authorization-issue/m-p/1292191#M328622</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For the full group you just need to do this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Under shared profile component &amp;gt; shell command authorization set &amp;gt; select the radio button permit.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If that doesn't works please send the screen shots of full access command set.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;JK&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Plz rate hopeful posts.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Oct 2009 14:11:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pix-authorization-issue/m-p/1292191#M328622</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2009-10-23T14:11:53Z</dc:date>
    </item>
    <item>
      <title>Re: PIX Authorization issue</title>
      <link>https://community.cisco.com/t5/network-access-control/pix-authorization-issue/m-p/1292192#M328623</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Issues seems to be with command authorization. It would have been better if running config is included in the original post.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What message do you see on acs failed attempt? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ways , please apply command set (that allows all command) on user level instead of group level. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;or &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check the failed attempts and see which group you are a part of, then apply command set to that group.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Good luck!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;~JG&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do rate helpful posts&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Oct 2009 14:14:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pix-authorization-issue/m-p/1292192#M328623</guid>
      <dc:creator>Jagdeep Gambhir</dc:creator>
      <dc:date>2009-10-23T14:14:26Z</dc:date>
    </item>
    <item>
      <title>Re: PIX Authorization issue</title>
      <link>https://community.cisco.com/t5/network-access-control/pix-authorization-issue/m-p/1292193#M328624</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Access is still denied.  The restricted group works.. (unable to get into enable mode), but the full access group can get into enable mode but not conf t&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Oct 2009 14:16:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pix-authorization-issue/m-p/1292193#M328624</guid>
      <dc:creator>networker99</dc:creator>
      <dc:date>2009-10-23T14:16:59Z</dc:date>
    </item>
    <item>
      <title>Re: PIX Authorization issue</title>
      <link>https://community.cisco.com/t5/network-access-control/pix-authorization-issue/m-p/1292194#M328625</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Where in ACS can I see failed authorization messages?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Oct 2009 14:36:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pix-authorization-issue/m-p/1292194#M328625</guid>
      <dc:creator>networker99</dc:creator>
      <dc:date>2009-10-23T14:36:51Z</dc:date>
    </item>
    <item>
      <title>Re: PIX Authorization issue</title>
      <link>https://community.cisco.com/t5/network-access-control/pix-authorization-issue/m-p/1292195#M328626</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Reports and activities --&amp;gt;failed attempts&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Oct 2009 14:40:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pix-authorization-issue/m-p/1292195#M328626</guid>
      <dc:creator>Jagdeep Gambhir</dc:creator>
      <dc:date>2009-10-23T14:40:03Z</dc:date>
    </item>
    <item>
      <title>Re: PIX Authorization issue</title>
      <link>https://community.cisco.com/t5/network-access-control/pix-authorization-issue/m-p/1292196#M328627</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Where in ACS can I see failed authorization messages?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Oct 2009 14:57:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pix-authorization-issue/m-p/1292196#M328627</guid>
      <dc:creator>networker99</dc:creator>
      <dc:date>2009-10-23T14:57:40Z</dc:date>
    </item>
    <item>
      <title>Re: PIX Authorization issue</title>
      <link>https://community.cisco.com/t5/network-access-control/pix-authorization-issue/m-p/1292197#M328628</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In the log my username shows up as "enable_15" ?? and says user unknown?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Oct 2009 14:58:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pix-authorization-issue/m-p/1292197#M328628</guid>
      <dc:creator>networker99</dc:creator>
      <dc:date>2009-10-23T14:58:42Z</dc:date>
    </item>
    <item>
      <title>Re: PIX Authorization issue</title>
      <link>https://community.cisco.com/t5/network-access-control/pix-authorization-issue/m-p/1292198#M328629</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This happens when we have command authorization enabled on ASA&lt;/P&gt;&lt;P&gt;and try to run any level 15 command on ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please check the ASA configuration and see if you are missing this command:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authentication enable console &lt;TACACS&gt; LOCAL&lt;/TACACS&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;on the ACS make sure that enable level privilege is level 15&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;JK&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Plz rate helpful posts-&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Oct 2009 15:03:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pix-authorization-issue/m-p/1292198#M328629</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2009-10-23T15:03:30Z</dc:date>
    </item>
    <item>
      <title>Re: PIX Authorization issue</title>
      <link>https://community.cisco.com/t5/network-access-control/pix-authorization-issue/m-p/1292199#M328630</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What will this command do?, Does it make me use my own individual enable password?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Oct 2009 15:07:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pix-authorization-issue/m-p/1292199#M328630</guid>
      <dc:creator>networker99</dc:creator>
      <dc:date>2009-10-23T15:07:05Z</dc:date>
    </item>
    <item>
      <title>Re: PIX Authorization issue</title>
      <link>https://community.cisco.com/t5/network-access-control/pix-authorization-issue/m-p/1292200#M328631</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Same issue was reported sometime back aswell.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Make sure you have enable authentication ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authentication ssh console TACACS LOCAL&lt;/P&gt;&lt;P&gt;aaa authentication telnet console TACACS LOCAL&lt;/P&gt;&lt;P&gt;aaa authentication enable console TACACS LOCAL&lt;/P&gt;&lt;P&gt;aaa authorization command TACACS LOCAL&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Incase it does not work pls get aaa config&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;~JG&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do rate helpful posts&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Oct 2009 15:07:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pix-authorization-issue/m-p/1292200#M328631</guid>
      <dc:creator>Jagdeep Gambhir</dc:creator>
      <dc:date>2009-10-23T15:07:11Z</dc:date>
    </item>
    <item>
      <title>Re: PIX Authorization issue</title>
      <link>https://community.cisco.com/t5/network-access-control/pix-authorization-issue/m-p/1292201#M328632</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This command is needed to make command authorization work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, you can set your own enable password.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;~JG&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Oct 2009 15:10:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pix-authorization-issue/m-p/1292201#M328632</guid>
      <dc:creator>Jagdeep Gambhir</dc:creator>
      <dc:date>2009-10-23T15:10:23Z</dc:date>
    </item>
    <item>
      <title>Re: PIX Authorization issue</title>
      <link>https://community.cisco.com/t5/network-access-control/pix-authorization-issue/m-p/1292202#M328633</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;yes, if you have separate enable password configured on the ACS, it will let you use that. But i would also suggest you to keep your current session open and try from a duplicate session...just a back door entry.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;JK&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Plz rate helpful posts-&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Oct 2009 15:38:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pix-authorization-issue/m-p/1292202#M328633</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2009-10-23T15:38:30Z</dc:date>
    </item>
    <item>
      <title>Re: PIX Authorization issue</title>
      <link>https://community.cisco.com/t5/network-access-control/pix-authorization-issue/m-p/1292203#M328634</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;i had the same problem, i could login to the ASA using ACS and i went to enable mode using the local enable password, however, i somehow was no longer authenticated as the username i used, but my username shows enable_15, and i couldn't authorize any command, so i created a new user on the ACS (enable_15) and everything worked smoothly.&lt;/P&gt;&lt;P&gt;i don't think this is the solution, but it's working now. &lt;/P&gt;&lt;P&gt;i don't know why the username switches to enable_15, maybe because i am entering the enable secret which is local on the ASA&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Jun 2011 09:33:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pix-authorization-issue/m-p/1292203#M328634</guid>
      <dc:creator>Omar Badawi</dc:creator>
      <dc:date>2011-06-08T09:33:48Z</dc:date>
    </item>
  </channel>
</rss>

