<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ACS Read Only Device Access in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-read-only-device-access/m-p/1577875#M361717</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As per your configuration:&lt;/P&gt;&lt;P&gt;aaa authorization commands 0 defalt group tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authorization commands 1 defalt group tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authorization commands 15 defalt group tacacs+ local&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All three lines have:&lt;/P&gt;&lt;P&gt;"defalt instead of default"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not sure if you just typed it wrong over here, if this is what you really have, then the IOS will consider this as the method list and will expect you to apply it on the vty or console lines (which is not mandatory, but it will not work until you apply it) &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You have to use default, if you don't want method lists.&lt;/P&gt;&lt;P&gt;Rate if useful &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 29 Apr 2013 16:17:09 GMT</pubDate>
    <dc:creator>edwjames</dc:creator>
    <dc:date>2013-04-29T16:17:09Z</dc:date>
    <item>
      <title>ACS Read Only Device Access</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-read-only-device-access/m-p/1577866#M361708</link>
      <description>&lt;P&gt;We are using ACS ver 4.2 and trying to setup users with limited access to our switchs and routers.&amp;nbsp; Here is what we did:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Created a user in ACS&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) Create Shell command Autorization Set - ReadOnly&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Unmatched Commands - Deny&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Commands Added&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; show&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; exit&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; * this should limit the user to the show and exit command only (correct)?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3) Created a group - HelpDesk with the following TACACS+ Settings&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Shell (exec) is checked&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Priviledge level is check with 15 as the assigned level&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Assign a Shell Command Authorization Set for any network device - selected&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ReadOnly - shell command autorization set seleted&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When the user logs on to the router/switch it appears that he has full access.&amp;nbsp; He can enter the enable command, config terminal command, etc.&amp;nbsp; All we want him to be able to do is to issue the show command.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help would be appreciated.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 00:27:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-read-only-device-access/m-p/1577866#M361708</guid>
      <dc:creator>dtom</dc:creator>
      <dc:date>2019-03-11T00:27:28Z</dc:date>
    </item>
    <item>
      <title>Re: ACS Read Only Device Access</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-read-only-device-access/m-p/1577867#M361709</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you refer to this doc&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_configuration_example09186a00808d9138.shtml"&gt;http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_configuration_example09186a00808d9138.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and compare the config, as far you say ACS config sounds correct on the switch/router you need to have the following command also&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="content"&gt;&lt;PRE&gt;aaa authorization config-commands
aaa authorization commands 0 default&amp;nbsp; group tacacs+ local
aaa authorization commands 1 default&amp;nbsp; group tacacs+ local
aaa authorization commands 15 default group tacacs+ local
&lt;/PRE&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Oct 2010 23:53:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-read-only-device-access/m-p/1577867#M361709</guid>
      <dc:creator>aneelaka</dc:creator>
      <dc:date>2010-10-01T23:53:40Z</dc:date>
    </item>
    <item>
      <title>ACS Read Only Device Access</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-read-only-device-access/m-p/1577868#M361710</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Is there any way to give priviledge level 15 and deny write access (write command)?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Apr 2013 18:34:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-read-only-device-access/m-p/1577868#M361710</guid>
      <dc:creator>dtom</dc:creator>
      <dc:date>2013-04-26T18:34:56Z</dc:date>
    </item>
    <item>
      <title>ACS Read Only Device Access</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-read-only-device-access/m-p/1577869#M361711</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can try this: Privilege for read-only access&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_configuration_example09186a00808d9138.shtml#scenario2"&gt;http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_configuration_example09186a00808d9138.shtml#scenario2&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt; &lt;BR /&gt;- Do rate helpful posts -&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Apr 2013 19:32:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-read-only-device-access/m-p/1577869#M361711</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-04-26T19:32:15Z</dc:date>
    </item>
    <item>
      <title>ACS Read Only Device Access</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-read-only-device-access/m-p/1577870#M361712</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I tried that and could not get it to work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; - 1 - &lt;/P&gt;&lt;P&gt;Shell Command Authorization Set&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Deny&lt;/P&gt;&lt;P&gt;Unmatched Commands - show&lt;/P&gt;&lt;P&gt;Permit Unmatched Args - checked&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Enable Options&lt;/P&gt;&lt;P&gt;Max Privilege for any AAA client - 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tacacs+&lt;/P&gt;&lt;P&gt;Shell Command - checked&lt;/P&gt;&lt;P&gt;Privilege level - 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With the above, the user did not have the ability to do sh run.&amp;nbsp; The user could not turn on privilege commands (enable) - access denied&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- 2 - &lt;/P&gt;&lt;P&gt;Shell Command Authorization Set&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Deny&lt;/P&gt;&lt;P&gt;Unmatched Commands - show&lt;/P&gt;&lt;P&gt;Permit Unmatched Args - checked&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Enable Options&lt;/P&gt;&lt;P&gt;Max Privilege for any AAA client - 15&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tacacs+&lt;/P&gt;&lt;P&gt;Shell Command - checked&lt;/P&gt;&lt;P&gt;Privilege level - 15&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With the above, the user had full read/write rights&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any other thoughts?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Apr 2013 20:39:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-read-only-device-access/m-p/1577870#M361712</guid>
      <dc:creator>dtom</dc:creator>
      <dc:date>2013-04-26T20:39:17Z</dc:date>
    </item>
    <item>
      <title>ACS Read Only Device Access</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-read-only-device-access/m-p/1577871#M361713</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;Dtom,&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;You need to give privilege 15 to both type of users. Now giving priv 15 does not mean that read-only user will be able to get full access. Command authorization work above privilege level.&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;Set enable and shell priv to 15&lt;BR /&gt;&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;Rest your setting is all ok.&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;Regards,&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;~JG&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;Do rate helpful posts&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Apr 2013 21:30:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-read-only-device-access/m-p/1577871#M361713</guid>
      <dc:creator>Jagdeep Gambhir</dc:creator>
      <dc:date>2013-04-26T21:30:40Z</dc:date>
    </item>
    <item>
      <title>ACS Read Only Device Access</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-read-only-device-access/m-p/1577872#M361714</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; I don't know what I am missing here.&amp;nbsp; When I give privilege 15 the user had full access.&amp;nbsp; Here is what I did:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- 1 - &lt;/P&gt;&lt;P&gt;Create Shell Command Autorization Sets - Read_Access&lt;/P&gt;&lt;P&gt;&amp;nbsp; Deny - checked&lt;/P&gt;&lt;P&gt;&amp;nbsp; Unmatched Commands - show&lt;/P&gt;&lt;P&gt;&amp;nbsp; Permit Unmatched Args - checked&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- 2 - Create Group - HelpDesk&lt;/P&gt;&lt;P&gt;&amp;nbsp; Enable Options - Max Privlege for any AAA Client 15&lt;/P&gt;&lt;P&gt;&amp;nbsp; Shell (exec) - checked&lt;/P&gt;&lt;P&gt;&amp;nbsp; Shell Command Authorization Set - Assign a Shell Command Set for any network device- Read_Access&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- 3 -&amp;nbsp; User Settings&lt;/P&gt;&lt;P&gt;&amp;nbsp; Group to which user is assigned HelpDesk&lt;/P&gt;&lt;P&gt;&amp;nbsp; TACACS+ Enable Control - Use Group Level Settings&lt;/P&gt;&lt;P&gt;&amp;nbsp; Shell Comand Authorization Set - As Group&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Apr 2013 15:20:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-read-only-device-access/m-p/1577872#M361714</guid>
      <dc:creator>dtom</dc:creator>
      <dc:date>2013-04-29T15:20:47Z</dc:date>
    </item>
    <item>
      <title>ACS Read Only Device Access</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-read-only-device-access/m-p/1577873#M361715</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you sure you have this on the device (Switch/Router)?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE&gt;aaa authorization config-commands
aaa authorization commands 0 default&amp;nbsp; group tacacs+ local
aaa authorization commands 1 default&amp;nbsp; group tacacs+ local
aaa authorization commands 15 default group tacacs+ local&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If possible attach a screenshot of the configuration on ACS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rate if it helps &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Apr 2013 15:29:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-read-only-device-access/m-p/1577873#M361715</guid>
      <dc:creator>edwjames</dc:creator>
      <dc:date>2013-04-29T15:29:08Z</dc:date>
    </item>
    <item>
      <title>ACS Read Only Device Access</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-read-only-device-access/m-p/1577874#M361716</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Here is my switch AAA config:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;aaa authentication login default group tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authorization config-commands&lt;/P&gt;&lt;P&gt;aaa authorization exec default group tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authorization commands 0 defalt group tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authorization commands 1 defalt group tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authorization commands 15 defalt group tacacs+ local&lt;/P&gt;&lt;P&gt;aaa accounting commands 15 default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt; &lt;/SPAN&gt;Here are screen shots for a user - robin.hood&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt; "&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/2/3/4/137432-tacacs1.JPG" class="jive-image" /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt; "&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/3/3/4/137433-tacacs2.JPG" class="jive-image" /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt; "&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/4/3/4/137434-tacacs3.JPG" class="jive-image" /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/5/3/4/137435-tacacs4.JPG" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/6/3/4/137436-tacacs5.JPG" class="jive-image" /&gt; &lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt; "&gt;﻿&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/7/3/4/137437-tacacs6.JPG" class="jive-image" /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Apr 2013 16:07:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-read-only-device-access/m-p/1577874#M361716</guid>
      <dc:creator>dtom</dc:creator>
      <dc:date>2013-04-29T16:07:04Z</dc:date>
    </item>
    <item>
      <title>ACS Read Only Device Access</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-read-only-device-access/m-p/1577875#M361717</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As per your configuration:&lt;/P&gt;&lt;P&gt;aaa authorization commands 0 defalt group tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authorization commands 1 defalt group tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authorization commands 15 defalt group tacacs+ local&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All three lines have:&lt;/P&gt;&lt;P&gt;"defalt instead of default"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not sure if you just typed it wrong over here, if this is what you really have, then the IOS will consider this as the method list and will expect you to apply it on the vty or console lines (which is not mandatory, but it will not work until you apply it) &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You have to use default, if you don't want method lists.&lt;/P&gt;&lt;P&gt;Rate if useful &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Apr 2013 16:17:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-read-only-device-access/m-p/1577875#M361717</guid>
      <dc:creator>edwjames</dc:creator>
      <dc:date>2013-04-29T16:17:09Z</dc:date>
    </item>
    <item>
      <title>ACS Read Only Device Access</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-read-only-device-access/m-p/1577876#M361718</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; What a dummy I am...typo.&amp;nbsp; I changed the commands and I was able to login and run the show run command.&amp;nbsp; However, I was not able to run exit and dir.&amp;nbsp; What am I missing here?&amp;nbsp; Here is a screen shot:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/7/4/4/137447-tacacs7.JPG" class="jive-image" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Apr 2013 18:24:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-read-only-device-access/m-p/1577876#M361718</guid>
      <dc:creator>dtom</dc:creator>
      <dc:date>2013-04-29T18:24:28Z</dc:date>
    </item>
    <item>
      <title>ACS Read Only Device Access</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-read-only-device-access/m-p/1577877#M361719</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;you also need to add permit &lt;CR&gt; for exit and dir on the &lt;STRONG&gt;permit unmatched Args&lt;/STRONG&gt;.&lt;/CR&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;OR&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You may check&lt;STRONG&gt; permit unmatched Args &lt;/STRONG&gt;this option for exit and dir&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt; &lt;BR /&gt;- Do rate helpful posts -&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Apr 2013 18:29:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-read-only-device-access/m-p/1577877#M361719</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-04-29T18:29:58Z</dc:date>
    </item>
    <item>
      <title>ACS Read Only Device Access</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-read-only-device-access/m-p/1577878#M361720</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; That was it.&amp;nbsp; Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, what is the easiest way to restrict a user to access only a certain device or certain subnet only?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Apr 2013 20:21:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-read-only-device-access/m-p/1577878#M361720</guid>
      <dc:creator>dtom</dc:creator>
      <dc:date>2013-04-29T20:21:11Z</dc:date>
    </item>
    <item>
      <title>ACS Read Only Device Access</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-read-only-device-access/m-p/1577879#M361721</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Read this doc:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_white_paper09186a00801a8fd0.shtml"&gt;http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_white_paper09186a00801a8fd0.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt; &lt;BR /&gt;- Do rate helpful posts -&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Apr 2013 20:29:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-read-only-device-access/m-p/1577879#M361721</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-04-29T20:29:04Z</dc:date>
    </item>
  </channel>
</rss>

