<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi Mark, in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/tacacs-server-command-configuration/m-p/2892668#M36527</link>
    <description>&lt;P&gt;Hi Mark,&lt;/P&gt;
&lt;P&gt;Thanks for the reply. My question is regarding AAA authorization.&lt;/P&gt;
&lt;P&gt;As you mention if we dont use the "add" parameter, than it will wipe out all other vlan configuration on the trunk.&lt;/P&gt;
&lt;P&gt;I want to avoid that mistake by putting the tacacs+ authorization rule. As it happen before that we have for example 10 vlans on a trunk and we want add another one. By mistake we didnt use the "add" command and it wipe out all other vlan information on the trunk.&lt;/P&gt;
&lt;P&gt;So the rule should be like this&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if "add" is not use in the switchport trunk allowed vlan command -&amp;gt; deny to add the vlan.&lt;/P&gt;
&lt;P&gt;I hope now i explain what you can understand &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Best Regards&lt;/P&gt;
&lt;P&gt;Faraz&lt;/P&gt;</description>
    <pubDate>Mon, 25 Apr 2016 13:07:09 GMT</pubDate>
    <dc:creator>sfarazaz123</dc:creator>
    <dc:date>2016-04-25T13:07:09Z</dc:date>
    <item>
      <title>tacacs+ server command configuration</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-server-command-configuration/m-p/2892665#M36524</link>
      <description>&lt;P&gt;Hi guys,&lt;/P&gt;
&lt;P&gt;i am want to configure the tacacs+ server and want to add a rule that if user dont use the "add" &amp;nbsp;command in defining the new vlan on the trunk it should get denied.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;for example&lt;/P&gt;
&lt;P&gt;switchport trunk allowed vlan add xx&lt;/P&gt;
&lt;P&gt;He should not be able to use the simple command without add.&lt;/P&gt;
&lt;P&gt;How can i write this rule and how i can implement this rule on the users for all network devices.&lt;/P&gt;
&lt;P&gt;i need some simple examples to understand this.&lt;/P&gt;
&lt;P&gt;Thanks in advance&lt;/P&gt;
&lt;P&gt;Faraz&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 06:42:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-server-command-configuration/m-p/2892665#M36524</guid>
      <dc:creator>sfarazaz123</dc:creator>
      <dc:date>2019-03-11T06:42:02Z</dc:date>
    </item>
    <item>
      <title>hello!</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-server-command-configuration/m-p/2892666#M36525</link>
      <description>&lt;P&gt;hello!&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;You might want to post this on the switch / security forums.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Apr 2016 19:53:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-server-command-configuration/m-p/2892666#M36525</guid>
      <dc:creator>George Stefanick</dc:creator>
      <dc:date>2016-04-22T19:53:56Z</dc:date>
    </item>
    <item>
      <title>Hi</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-server-command-configuration/m-p/2892667#M36526</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;If you have a trunk with vlans specified you need to use add syntax if you don't it will wipe the other vlans from the trunk and only use the last one you specified so you will break the trunk link as they wont6 match any longer on each side&lt;/P&gt;
&lt;P&gt;Not sure what that has to do with tacacs though as tacacs is for access ?&lt;/P&gt;</description>
      <pubDate>Mon, 25 Apr 2016 12:40:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-server-command-configuration/m-p/2892667#M36526</guid>
      <dc:creator>Mark Malone</dc:creator>
      <dc:date>2016-04-25T12:40:18Z</dc:date>
    </item>
    <item>
      <title>Hi Mark,</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-server-command-configuration/m-p/2892668#M36527</link>
      <description>&lt;P&gt;Hi Mark,&lt;/P&gt;
&lt;P&gt;Thanks for the reply. My question is regarding AAA authorization.&lt;/P&gt;
&lt;P&gt;As you mention if we dont use the "add" parameter, than it will wipe out all other vlan configuration on the trunk.&lt;/P&gt;
&lt;P&gt;I want to avoid that mistake by putting the tacacs+ authorization rule. As it happen before that we have for example 10 vlans on a trunk and we want add another one. By mistake we didnt use the "add" command and it wipe out all other vlan information on the trunk.&lt;/P&gt;
&lt;P&gt;So the rule should be like this&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if "add" is not use in the switchport trunk allowed vlan command -&amp;gt; deny to add the vlan.&lt;/P&gt;
&lt;P&gt;I hope now i explain what you can understand &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Best Regards&lt;/P&gt;
&lt;P&gt;Faraz&lt;/P&gt;</description>
      <pubDate>Mon, 25 Apr 2016 13:07:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-server-command-configuration/m-p/2892668#M36527</guid>
      <dc:creator>sfarazaz123</dc:creator>
      <dc:date>2016-04-25T13:07:09Z</dc:date>
    </item>
    <item>
      <title>I have never seen that done</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-server-command-configuration/m-p/2892669#M36528</link>
      <description>&lt;P&gt;I have never seen that done through authorisation after being logged in ,&amp;nbsp;AAA&amp;nbsp;is not&amp;nbsp;capable of making sure a user doesn't make a mistake like that its just for access security&lt;/P&gt;
&lt;P&gt;If you were trying to do it from prime 3.0 or above&amp;nbsp;through compliance it could probably be done&amp;nbsp;as you can build rule bases against access and configuration to do it but not under cli in router/switch&lt;/P&gt;
&lt;P&gt;AAA is for access , you can put the user in a low end privilege group so he cant make changes like that again preventing this from happening but&amp;nbsp;it does not have the feature of preventing mistakes as far as im aware&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Apr 2016 14:19:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-server-command-configuration/m-p/2892669#M36528</guid>
      <dc:creator>Mark Malone</dc:creator>
      <dc:date>2016-04-25T14:19:23Z</dc:date>
    </item>
    <item>
      <title>Hi Marks</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-server-command-configuration/m-p/2892670#M36529</link>
      <description>&lt;P&gt;Hi Marks&lt;/P&gt;
&lt;P&gt;Thanks alot of the clearing the confusion.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Apr 2016 19:41:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-server-command-configuration/m-p/2892670#M36529</guid>
      <dc:creator>sfarazaz123</dc:creator>
      <dc:date>2016-04-25T19:41:03Z</dc:date>
    </item>
  </channel>
</rss>

