<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi Gagan in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/asa-accounting/m-p/2951891#M37280</link>
    <description>&lt;P&gt;Hi Gagan&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks for your reply.&lt;/P&gt;
&lt;P&gt;I tried that but it denies access at enable login.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;here is the aaa config&lt;/P&gt;
&lt;P&gt;aaa-server TACACS+ protocol tacacs+&lt;BR /&gt;aaa-server TACACS+ (inside) host&amp;nbsp;ACS1&lt;BR /&gt;aaa-server RADIUS protocol radius&lt;BR /&gt;aaa-server VPNINBOUND protocol radius&lt;BR /&gt;aaa-server VPNINBOUND (inside) host&amp;nbsp;ACS1&lt;BR /&gt;aaa-server VPNINBOUND (inside) host&amp;nbsp;ACS2&lt;BR /&gt;aaa authentication http console VPNINBOUND&lt;BR /&gt;aaa authentication telnet console VPNINBOUND&lt;BR /&gt;aaa authentication ssh console VPNINBOUND LOCAL&lt;BR /&gt;aaa accounting enable console TACACS+&lt;BR /&gt;aaa accounting ssh console TACACS+&lt;BR /&gt;aaa accounting command TACACS+&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 14 Dec 2016 10:01:57 GMT</pubDate>
    <dc:creator>mickyq</dc:creator>
    <dc:date>2016-12-14T10:01:57Z</dc:date>
    <item>
      <title>ASA accounting</title>
      <link>https://community.cisco.com/t5/network-access-control/asa-accounting/m-p/2951889#M37267</link>
      <description>&lt;P&gt;Ive setup accounting with ACS 5.3 so I can see when an admin logs in. This level uses AD for authentication.&lt;/P&gt;
&lt;P&gt;When going to enable mode it uses the local account and the username changes to enable_15 in the logs. is there any way to retain the original username when using enable command.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 07:17:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/asa-accounting/m-p/2951889#M37267</guid>
      <dc:creator>mickyq</dc:creator>
      <dc:date>2019-03-11T07:17:36Z</dc:date>
    </item>
    <item>
      <title>This happens when we have</title>
      <link>https://community.cisco.com/t5/network-access-control/asa-accounting/m-p/2951890#M37273</link>
      <description>&lt;P&gt;This happens when we have command authorization enabled on ASA and try to run any level 15 commands on ASA.&lt;/P&gt;
&lt;P&gt;Would suggest to execute this command on the ASA:&lt;/P&gt;
&lt;P&gt;aaa authentication enable console LOCAL&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Gagan&lt;/P&gt;
&lt;P&gt;ps : rate as correct if it helps!!!!&lt;/P&gt;</description>
      <pubDate>Tue, 13 Dec 2016 22:36:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/asa-accounting/m-p/2951890#M37273</guid>
      <dc:creator>Gagandeep Singh</dc:creator>
      <dc:date>2016-12-13T22:36:15Z</dc:date>
    </item>
    <item>
      <title>Hi Gagan</title>
      <link>https://community.cisco.com/t5/network-access-control/asa-accounting/m-p/2951891#M37280</link>
      <description>&lt;P&gt;Hi Gagan&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks for your reply.&lt;/P&gt;
&lt;P&gt;I tried that but it denies access at enable login.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;here is the aaa config&lt;/P&gt;
&lt;P&gt;aaa-server TACACS+ protocol tacacs+&lt;BR /&gt;aaa-server TACACS+ (inside) host&amp;nbsp;ACS1&lt;BR /&gt;aaa-server RADIUS protocol radius&lt;BR /&gt;aaa-server VPNINBOUND protocol radius&lt;BR /&gt;aaa-server VPNINBOUND (inside) host&amp;nbsp;ACS1&lt;BR /&gt;aaa-server VPNINBOUND (inside) host&amp;nbsp;ACS2&lt;BR /&gt;aaa authentication http console VPNINBOUND&lt;BR /&gt;aaa authentication telnet console VPNINBOUND&lt;BR /&gt;aaa authentication ssh console VPNINBOUND LOCAL&lt;BR /&gt;aaa accounting enable console TACACS+&lt;BR /&gt;aaa accounting ssh console TACACS+&lt;BR /&gt;aaa accounting command TACACS+&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Dec 2016 10:01:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/asa-accounting/m-p/2951891#M37280</guid>
      <dc:creator>mickyq</dc:creator>
      <dc:date>2016-12-14T10:01:57Z</dc:date>
    </item>
    <item>
      <title>Hello Michael-</title>
      <link>https://community.cisco.com/t5/network-access-control/asa-accounting/m-p/2951892#M37286</link>
      <description>&lt;P&gt;Hello Michael-&lt;/P&gt;
&lt;P&gt;Are you returning the proper attributes with the Authorization Profile in ACS? You need to set the privilege level in the authorization profile in order for this to work. Here is what I have on my end:&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;priv-lvl=15&lt;BR /&gt;max_priv_lvl=15&lt;/PRE&gt;
&lt;P&gt;Here is also a snipit from my ASA configs (you can ignore the authorization portion unless you want to do authorization on your end as well).&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;sh run aaa&lt;BR /&gt;aaa authentication ssh console NS-TACACS LOCAL&lt;BR /&gt;aaa authentication enable console NS-TACACS LOCAL&lt;BR /&gt;aaa authentication telnet console NS-TACACS LOCAL&lt;BR /&gt;aaa authentication http console NS-TACACS LOCAL&lt;BR /&gt;aaa authentication serial console NS-TACACS LOCAL&lt;BR /&gt;aaa authorization command NS-TACACS LOCAL&lt;BR /&gt;aaa accounting enable console NS-TACACS&lt;BR /&gt;aaa accounting serial console NS-TACACS&lt;BR /&gt;aaa accounting ssh console NS-TACACS&lt;BR /&gt;aaa accounting telnet console NS-TACACS&lt;BR /&gt;aaa accounting command privilege 15 NS-TACACS&lt;BR /&gt;aaa authorization exec authentication-server auto-enable&lt;/PRE&gt;
&lt;P&gt;I hope this helps!&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 17 Dec 2016 02:39:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/asa-accounting/m-p/2951892#M37286</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2016-12-17T02:39:43Z</dc:date>
    </item>
  </channel>
</rss>

