<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: command authorization for ASA in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/command-authorization-for-asa/m-p/1582607#M346065</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Dan&lt;/P&gt;&lt;P&gt;&amp;nbsp; I have alredy configured enable password using tacacs+.Please find my aaa config on ASA&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authentication telnet console TACACS-SERVER LOCAL&lt;BR /&gt;aaa authentication http console TACACS-SERVER LOCAL&lt;BR /&gt;aaa authentication ssh console TACACS-SERVER LOCAL&lt;BR /&gt;aaa authentication enable console TACACS-SERVER LOCAL&lt;BR /&gt;aaa authentication serial console LOCAL &lt;BR /&gt;aaa authorization command TACACS-SERVER LOCAL&lt;BR /&gt;aaa accounting telnet console TACACS-SERVER&lt;BR /&gt;aaa accounting command TACACS-SERVER&lt;BR /&gt;aaa accounting ssh console TACACS-SERVER&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;anvar&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 28 Dec 2010 16:25:58 GMT</pubDate>
    <dc:creator>anva12345</dc:creator>
    <dc:date>2010-12-28T16:25:58Z</dc:date>
    <item>
      <title>command authorization for ASA</title>
      <link>https://community.cisco.com/t5/network-access-control/command-authorization-for-asa/m-p/1582605#M346047</link>
      <description>&lt;P&gt;Hi all&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; I have configured ASA firewall for command authorization with ACS.For users with privilege level 15 it is working fine.But when i login with users with privilege level 0, first when i enter the username and password ,it enters into enable mode.But after that when i put the enable password ,it is not working.password is not working.I configured to use the same PAP password option in the ACS enable section for the user.Also is it possible in ASA is it possible when user enters username and password,he could directly log into the exec mode rather than enable mode and assign privilege for the user as configured in the ACS user configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;&lt;P&gt;Anvar&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 00:40:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/command-authorization-for-asa/m-p/1582605#M346047</guid>
      <dc:creator>anva12345</dc:creator>
      <dc:date>2019-03-11T00:40:36Z</dc:date>
    </item>
    <item>
      <title>Re: command authorization for ASA</title>
      <link>https://community.cisco.com/t5/network-access-control/command-authorization-for-asa/m-p/1582606#M346052</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think that you should add :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authentication enable console &lt;METHOD&gt;&lt;/METHOD&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you want to have the enable via tacacs ?&lt;/P&gt;&lt;P&gt;You can create a group privilege 15 and deny unwanted commands.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Dec 2010 16:22:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/command-authorization-for-asa/m-p/1582606#M346052</guid>
      <dc:creator>Dan-Ciprian Cicioiu</dc:creator>
      <dc:date>2010-12-28T16:22:07Z</dc:date>
    </item>
    <item>
      <title>Re: command authorization for ASA</title>
      <link>https://community.cisco.com/t5/network-access-control/command-authorization-for-asa/m-p/1582607#M346065</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Dan&lt;/P&gt;&lt;P&gt;&amp;nbsp; I have alredy configured enable password using tacacs+.Please find my aaa config on ASA&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authentication telnet console TACACS-SERVER LOCAL&lt;BR /&gt;aaa authentication http console TACACS-SERVER LOCAL&lt;BR /&gt;aaa authentication ssh console TACACS-SERVER LOCAL&lt;BR /&gt;aaa authentication enable console TACACS-SERVER LOCAL&lt;BR /&gt;aaa authentication serial console LOCAL &lt;BR /&gt;aaa authorization command TACACS-SERVER LOCAL&lt;BR /&gt;aaa accounting telnet console TACACS-SERVER&lt;BR /&gt;aaa accounting command TACACS-SERVER&lt;BR /&gt;aaa accounting ssh console TACACS-SERVER&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;anvar&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Dec 2010 16:25:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/command-authorization-for-asa/m-p/1582607#M346065</guid>
      <dc:creator>anva12345</dc:creator>
      <dc:date>2010-12-28T16:25:58Z</dc:date>
    </item>
    <item>
      <title>Re: command authorization for ASA</title>
      <link>https://community.cisco.com/t5/network-access-control/command-authorization-for-asa/m-p/1582608#M346084</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think that the problem is that you assign the privilege level to 0.&lt;/P&gt;&lt;P&gt;So the user will be able to use only level 0 commands.&lt;/P&gt;&lt;P&gt;I think that the best way will be to set the privilege to 15 , and deny/allow commands.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Dec 2010 16:32:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/command-authorization-for-asa/m-p/1582608#M346084</guid>
      <dc:creator>Dan-Ciprian Cicioiu</dc:creator>
      <dc:date>2010-12-28T16:32:24Z</dc:date>
    </item>
    <item>
      <title>Re: command authorization for ASA</title>
      <link>https://community.cisco.com/t5/network-access-control/command-authorization-for-asa/m-p/1582609#M346104</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Dan&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Thanks man .it works fine for ASA.but when i applied same configuration on FWSM,it works for user with read and write access.But for read only access users.command its showing command authorization failed .when i enter username and password it is going to enable mode.but when i enter enable&amp;nbsp; its showing command authorization failed, not&amp;nbsp; allowing me to enter exec mode.Please help to solve this.&lt;/P&gt;&lt;P&gt;Also is it possible to enter exec mode without enable mode directly like routers and switches&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;Anvar&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Dec 2010 16:57:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/command-authorization-for-asa/m-p/1582609#M346104</guid>
      <dc:creator>anva12345</dc:creator>
      <dc:date>2010-12-28T16:57:38Z</dc:date>
    </item>
    <item>
      <title>Re: command authorization for ASA</title>
      <link>https://community.cisco.com/t5/network-access-control/command-authorization-for-asa/m-p/1582610#M346117</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Anvar ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;"command &lt;EM&gt;authorization failed&lt;/EM&gt;" &lt;/EM&gt;tells you that the user has no right to enter that command.&lt;/P&gt;&lt;P&gt;Currently , as far as i know , you cannot direcly go to privilege level 15.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Dec 2010 17:49:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/command-authorization-for-asa/m-p/1582610#M346117</guid>
      <dc:creator>Dan-Ciprian Cicioiu</dc:creator>
      <dc:date>2010-12-28T17:49:17Z</dc:date>
    </item>
    <item>
      <title>Re: command authorization for ASA</title>
      <link>https://community.cisco.com/t5/network-access-control/command-authorization-for-asa/m-p/1582611#M346126</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Dan&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; But same command and user is working fine for ASA.But for fwsm when i put "enable" to get into enable mode its showing the error.i wonder how it is working for ASA and not for FWSM&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Anvar&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Dec 2010 17:56:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/command-authorization-for-asa/m-p/1582611#M346126</guid>
      <dc:creator>anva12345</dc:creator>
      <dc:date>2010-12-28T17:56:13Z</dc:date>
    </item>
    <item>
      <title>Re: command authorization for ASA</title>
      <link>https://community.cisco.com/t5/network-access-control/command-authorization-for-asa/m-p/1582612#M346137</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Anvar ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;can you add enable command , on the permit list ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Dec 2010 18:02:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/command-authorization-for-asa/m-p/1582612#M346137</guid>
      <dc:creator>Dan-Ciprian Cicioiu</dc:creator>
      <dc:date>2010-12-28T18:02:25Z</dc:date>
    </item>
    <item>
      <title>Re: command authorization for ASA</title>
      <link>https://community.cisco.com/t5/network-access-control/command-authorization-for-asa/m-p/1582613#M346152</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Dan&lt;/P&gt;&lt;P&gt;&amp;nbsp; I already added the enable command for the read-only command authorization set.Please check the attached file.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Anvar&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Dec 2010 18:06:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/command-authorization-for-asa/m-p/1582613#M346152</guid>
      <dc:creator>anva12345</dc:creator>
      <dc:date>2010-12-28T18:06:25Z</dc:date>
    </item>
    <item>
      <title>Re: command authorization for ASA</title>
      <link>https://community.cisco.com/t5/network-access-control/command-authorization-for-asa/m-p/1582614#M346172</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you try a&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;debug aaa authorization&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Dec 2010 18:38:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/command-authorization-for-asa/m-p/1582614#M346172</guid>
      <dc:creator>Dan-Ciprian Cicioiu</dc:creator>
      <dc:date>2010-12-28T18:38:00Z</dc:date>
    </item>
    <item>
      <title>Re: command authorization for ASA</title>
      <link>https://community.cisco.com/t5/network-access-control/command-authorization-for-asa/m-p/1582615#M346237</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dan&lt;/P&gt;&lt;P&gt;&amp;nbsp; Thanks very much Dan.Actually aaa requests were going to ACS2 .and I configured authorization sets on ACS1.After replication its workink fine.Thanks very much for your support&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Anvar&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Dec 2010 18:47:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/command-authorization-for-asa/m-p/1582615#M346237</guid>
      <dc:creator>anva12345</dc:creator>
      <dc:date>2010-12-28T18:47:42Z</dc:date>
    </item>
  </channel>
</rss>

