<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Shell Command Authorization in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/shell-command-authorization/m-p/1309440#M348502</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Look at the authentication/authorization logs in the ACS and it will give you a better idea of what the issues is.  You are definently on the right track.  Per Group Level is the best idea.  Not sure if you are mapping back to an AD Group or using seperate ID's on the ACS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The other option is to give them access to a network management system that will show them the current status of the device, errors in the last 5 minutes through the last x days,months, years, events, snmp traps etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Solarwinds is a good product for this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let us know what the ACS logs show, what shell commands you have set, NDG, Shared Resources and group settings you have set.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Aaron Magruder&lt;/P&gt;&lt;P&gt;NonStop Networks, LLC&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.nonstopnetworks.net" target="_blank"&gt;http://www.nonstopnetworks.net&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 03 Sep 2009 01:29:54 GMT</pubDate>
    <dc:creator>nsn-amagruder</dc:creator>
    <dc:date>2009-09-03T01:29:54Z</dc:date>
    <item>
      <title>Shell Command Authorization</title>
      <link>https://community.cisco.com/t5/network-access-control/shell-command-authorization/m-p/1309438#M348500</link>
      <description>&lt;P&gt;Recently, a couple of our help desk people were asking for access to some of our branch network equipment so that they can look at interface counters, etc. for troubleshooting without escalating to the engineers.  I agreed that it would be okay to give access to commands such as, Â&amp;#147;show ip interface briefÂ&amp;#148;, Â&amp;#147;show interfaceÂ&amp;#148;, and Â&amp;#147;clear countersÂ&amp;#148;.  I want to deny commands such as Â&amp;#147;show running-configÂ&amp;#148; and Â&amp;#147;configureÂ&amp;#148;.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have setup shell command authorization in every possible way (user level, group level, creating shell command authorization sets, per NDG etc.) and I cannot get them to work.  I have read through many docs on CiscoÂ&amp;#146;s website and IÂ&amp;#146;m still unable to get this to work.  I suspect there may be some AAA settings on the devices that may be overriding the ACS settings, but IÂ&amp;#146;m not sure.  IÂ&amp;#146;m relatively new at configuring ACS and IÂ&amp;#146;ve run out of ideas.  Any suggestions?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 23:40:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/shell-command-authorization/m-p/1309438#M348500</guid>
      <dc:creator>admin_2</dc:creator>
      <dc:date>2019-03-10T23:40:20Z</dc:date>
    </item>
    <item>
      <title>Re: Shell Command Authorization</title>
      <link>https://community.cisco.com/t5/network-access-control/shell-command-authorization/m-p/1309439#M348501</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Something more simpler.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Configuring Security with Passwords, Privilege Levels, and Login Usernames for CLI Sessions on Networking Devices&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/ios/security/configuration/guide/sec_cfg_sec_4cli_ps6017_TSD_Products_Configuration_Guide_Chapter.html#wp1170533" target="_blank"&gt;http://www.cisco.com/en/US/docs/ios/security/configuration/guide/sec_cfg_sec_4cli_ps6017_TSD_Products_Configuration_Guide_Chapter.html#wp1170533&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Sep 2009 22:13:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/shell-command-authorization/m-p/1309439#M348501</guid>
      <dc:creator>Leo Laohoo</dc:creator>
      <dc:date>2009-09-02T22:13:41Z</dc:date>
    </item>
    <item>
      <title>Re: Shell Command Authorization</title>
      <link>https://community.cisco.com/t5/network-access-control/shell-command-authorization/m-p/1309440#M348502</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Look at the authentication/authorization logs in the ACS and it will give you a better idea of what the issues is.  You are definently on the right track.  Per Group Level is the best idea.  Not sure if you are mapping back to an AD Group or using seperate ID's on the ACS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The other option is to give them access to a network management system that will show them the current status of the device, errors in the last 5 minutes through the last x days,months, years, events, snmp traps etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Solarwinds is a good product for this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let us know what the ACS logs show, what shell commands you have set, NDG, Shared Resources and group settings you have set.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Aaron Magruder&lt;/P&gt;&lt;P&gt;NonStop Networks, LLC&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.nonstopnetworks.net" target="_blank"&gt;http://www.nonstopnetworks.net&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Sep 2009 01:29:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/shell-command-authorization/m-p/1309440#M348502</guid>
      <dc:creator>nsn-amagruder</dc:creator>
      <dc:date>2009-09-03T01:29:54Z</dc:date>
    </item>
    <item>
      <title>Re: Shell Command Authorization</title>
      <link>https://community.cisco.com/t5/network-access-control/shell-command-authorization/m-p/1309441#M348503</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The TACACS+ Accounting log shows me the date &amp;amp; time my test account authenticated, what group it belongs to, from what IP, the session starting &amp;amp; stopping, &amp;amp; the elapsed time.  The TACACS+ Administration log show what commands were issued.  What other logs do you suggest I look at?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;They do have access to solarwinds for monitoring and this does provide a wealth of information.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am going to start from scratch - new router with a blank config, new ACS group and test user.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your help!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Sep 2009 11:26:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/shell-command-authorization/m-p/1309441#M348503</guid>
      <dc:creator />
      <dc:date>2009-09-03T11:26:41Z</dc:date>
    </item>
    <item>
      <title>Re: Shell Command Authorization</title>
      <link>https://community.cisco.com/t5/network-access-control/shell-command-authorization/m-p/1309442#M348504</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm not sure if the login or commands were failing at the network device.  May it fail, then check the failed attempts log.  This log usually points directly to the issue.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Sep 2009 11:37:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/shell-command-authorization/m-p/1309442#M348504</guid>
      <dc:creator>nsn-amagruder</dc:creator>
      <dc:date>2009-09-03T11:37:33Z</dc:date>
    </item>
    <item>
      <title>Re: Shell Command Authorization</title>
      <link>https://community.cisco.com/t5/network-access-control/shell-command-authorization/m-p/1309443#M348505</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks! The problem is I am unable to restrict specific commands using the shell command authorization.  The test account can authenticate, enter privileged mode and run all commands.  No matter how I setup shell command authorization, I cannot get it to deny any commands.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Sep 2009 12:12:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/shell-command-authorization/m-p/1309443#M348505</guid>
      <dc:creator />
      <dc:date>2009-09-03T12:12:32Z</dc:date>
    </item>
    <item>
      <title>Re: Shell Command Authorization</title>
      <link>https://community.cisco.com/t5/network-access-control/shell-command-authorization/m-p/1309444#M348506</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Gotcha...Under the Group, what shell privilege level is check or entered under the shell section?  I believe you can also set the shell command sets in this section.  Set the privelege level to 1.  I don't have access to one at the moment, but I believe their is a drop down menue and a place to check a box privilege level and type 1.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the passed authentication log, are the users getting mapped to the group you are setting the rights on?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try setting the command authorization to none just to verify that the group can no longer do anything.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To prevent the application of any shell command-authorization set, select (or accept the default of) the None option. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.0/user/guide/g.html#wp480029" target="_blank"&gt;http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.0/user/guide/g.html#wp480029&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;command sets&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.1/user/SPC.html#wp697557" target="_blank"&gt;http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.1/user/SPC.html#wp697557&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Sep 2009 12:43:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/shell-command-authorization/m-p/1309444#M348506</guid>
      <dc:creator>nsn-amagruder</dc:creator>
      <dc:date>2009-09-03T12:43:14Z</dc:date>
    </item>
    <item>
      <title>Re: Shell Command Authorization</title>
      <link>https://community.cisco.com/t5/network-access-control/shell-command-authorization/m-p/1309445#M348507</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;privilege is 1&lt;/P&gt;&lt;P&gt;I've checked the authentication logs, and my test user is getting mapped to the correct group.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I changed the shell command authorization to "none" and it still allowed me to issue commands.  There has to be something else that is over riding this.  I just can't find it yet.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Sep 2009 19:01:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/shell-command-authorization/m-p/1309445#M348507</guid>
      <dc:creator />
      <dc:date>2009-09-03T19:01:39Z</dc:date>
    </item>
  </channel>
</rss>

