<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to restrict &amp;quot;Reload&amp;quot; command on some devices in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/how-to-restrict-quot-reload-quot-command-on-some-devices/m-p/2858237#M39234</link>
    <description>&lt;P&gt;&lt;SPAN class="" lang="en"&gt;&lt;SPAN class=""&gt;Hello, sorry for my English.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="" lang="en"&gt;&lt;SPAN class=""&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN id="result_box" class="" lang="en"&gt;&lt;SPAN class=""&gt;We&lt;/SPAN&gt; &lt;SPAN&gt;need to restrict the&lt;/SPAN&gt; &lt;SPAN&gt;execution of the "&lt;/SPAN&gt;&lt;SPAN&gt;Reload"&lt;/SPAN&gt; &lt;SPAN&gt;command on&lt;/SPAN&gt; &lt;SPAN&gt;certain&lt;/SPAN&gt; &lt;SPAN&gt;switches&lt;/SPAN&gt; &lt;SPAN&gt;and&lt;/SPAN&gt; &lt;SPAN class=""&gt;routers&lt;/SPAN&gt; &lt;SPAN&gt;considered&lt;/SPAN&gt; &lt;SPAN&gt;Core&lt;/SPAN&gt; &lt;SPAN&gt;or&lt;/SPAN&gt; &lt;SPAN&gt;concentrators&lt;/SPAN&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I could&lt;/SPAN&gt; &lt;SPAN&gt;implement&lt;/SPAN&gt; &lt;SPAN&gt;the restriction of the&lt;/SPAN&gt; &lt;SPAN&gt;use of&lt;/SPAN&gt; &lt;SPAN&gt;command&lt;/SPAN&gt; &lt;SPAN&gt;using&lt;/SPAN&gt; &lt;SPAN&gt;EEM&lt;/SPAN&gt; &lt;SPAN&gt;but&lt;/SPAN&gt; &lt;SPAN&gt;I&lt;/SPAN&gt; &lt;SPAN&gt;left out&lt;/SPAN&gt; &lt;SPAN&gt;a switch&lt;/SPAN&gt; &lt;SPAN&gt;6500&lt;/SPAN&gt;&lt;SPAN&gt;, Core&lt;/SPAN&gt; &lt;SPAN&gt;of&lt;/SPAN&gt; &lt;SPAN&gt;Data&lt;/SPAN&gt; &lt;SPAN&gt;Center,&lt;/SPAN&gt; &lt;SPAN&gt;because the&lt;/SPAN&gt; &lt;SPAN&gt;version of the operating&lt;/SPAN&gt; &lt;SPAN&gt;system does not support&lt;/SPAN&gt; &lt;SPAN&gt;EEM&lt;/SPAN&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN class=""&gt;We have&lt;/SPAN&gt; &lt;SPAN&gt;configured&lt;/SPAN&gt; &lt;SPAN&gt;AAA&lt;/SPAN&gt; &lt;SPAN&gt;and do&lt;/SPAN&gt; &lt;SPAN&gt;authentication&lt;/SPAN&gt; &lt;SPAN&gt;against a&lt;/SPAN&gt; &lt;SPAN&gt;TACACS&lt;/SPAN&gt; &lt;SPAN&gt;server&lt;/SPAN&gt; &lt;SPAN&gt;where&lt;/SPAN&gt; &lt;SPAN&gt;users&lt;/SPAN&gt; &lt;SPAN class=""&gt;listed&lt;/SPAN&gt; &lt;SPAN class=""&gt;there&lt;/SPAN&gt; &lt;SPAN&gt;(&lt;/SPAN&gt;&lt;SPAN&gt;nonlocal&lt;/SPAN&gt;&lt;SPAN&gt;) to access&lt;/SPAN&gt; &lt;SPAN&gt;the devices.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN class=""&gt;In fact,&lt;/SPAN&gt; &lt;SPAN class=""&gt;we grant&lt;/SPAN&gt; &lt;SPAN class=""&gt;permissions&lt;/SPAN&gt; &lt;SPAN&gt;to&lt;/SPAN&gt; &lt;SPAN&gt;execute&lt;/SPAN&gt; &lt;SPAN&gt;certain commands&lt;/SPAN&gt; &lt;SPAN&gt;only&lt;/SPAN&gt; &lt;SPAN&gt;via the&lt;/SPAN&gt; &lt;SPAN&gt;file "&lt;/SPAN&gt;&lt;SPAN class=""&gt;tac_plus.conf&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt; &lt;SPAN class=""&gt;that resides on the&lt;/SPAN&gt; &lt;SPAN&gt;TACACS&lt;/SPAN&gt; &lt;SPAN&gt;server&lt;/SPAN&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN class=""&gt;What&lt;/SPAN&gt; &lt;SPAN class=""&gt;I could not do&lt;/SPAN&gt; &lt;SPAN&gt;is&lt;/SPAN&gt; &lt;SPAN class=""&gt;restrict the execution&lt;/SPAN&gt; &lt;SPAN&gt;of&lt;/SPAN&gt; &lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN&gt;Reload"&lt;/SPAN&gt; &lt;SPAN&gt;using the same method&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt; &lt;SPAN&gt;only&lt;/SPAN&gt; &lt;SPAN class=""&gt;I got&lt;/SPAN&gt; &lt;SPAN&gt;doing&lt;/SPAN&gt; &lt;SPAN&gt;with&lt;/SPAN&gt; &lt;SPAN&gt;EEM&lt;/SPAN&gt; &lt;SPAN class=""&gt;on routers&lt;/SPAN&gt; &lt;SPAN class=""&gt;and&lt;/SPAN&gt; &lt;SPAN&gt;switches&lt;/SPAN&gt; &lt;SPAN&gt;critical&lt;/SPAN&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I would like&lt;/SPAN&gt; &lt;SPAN&gt;to know if&lt;/SPAN&gt; &lt;SPAN&gt;it is possible to&lt;/SPAN&gt; &lt;SPAN class=""&gt;restrict the&lt;/SPAN&gt; &lt;SPAN&gt;"reload&lt;/SPAN&gt;&lt;SPAN&gt;" command&lt;/SPAN&gt; &lt;SPAN&gt;on certain devices&lt;/SPAN&gt;&lt;SPAN class=""&gt;, configuring&lt;/SPAN&gt; &lt;SPAN&gt;the instructions&lt;/SPAN&gt; &lt;SPAN&gt;in the "&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;tac_plus.conf&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN class=""&gt;" file.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN class=""&gt;Thank you very much.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 06:54:06 GMT</pubDate>
    <dc:creator>JCRE</dc:creator>
    <dc:date>2019-03-11T06:54:06Z</dc:date>
    <item>
      <title>How to restrict "Reload" command on some devices</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-restrict-quot-reload-quot-command-on-some-devices/m-p/2858237#M39234</link>
      <description>&lt;P&gt;&lt;SPAN class="" lang="en"&gt;&lt;SPAN class=""&gt;Hello, sorry for my English.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="" lang="en"&gt;&lt;SPAN class=""&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN id="result_box" class="" lang="en"&gt;&lt;SPAN class=""&gt;We&lt;/SPAN&gt; &lt;SPAN&gt;need to restrict the&lt;/SPAN&gt; &lt;SPAN&gt;execution of the "&lt;/SPAN&gt;&lt;SPAN&gt;Reload"&lt;/SPAN&gt; &lt;SPAN&gt;command on&lt;/SPAN&gt; &lt;SPAN&gt;certain&lt;/SPAN&gt; &lt;SPAN&gt;switches&lt;/SPAN&gt; &lt;SPAN&gt;and&lt;/SPAN&gt; &lt;SPAN class=""&gt;routers&lt;/SPAN&gt; &lt;SPAN&gt;considered&lt;/SPAN&gt; &lt;SPAN&gt;Core&lt;/SPAN&gt; &lt;SPAN&gt;or&lt;/SPAN&gt; &lt;SPAN&gt;concentrators&lt;/SPAN&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I could&lt;/SPAN&gt; &lt;SPAN&gt;implement&lt;/SPAN&gt; &lt;SPAN&gt;the restriction of the&lt;/SPAN&gt; &lt;SPAN&gt;use of&lt;/SPAN&gt; &lt;SPAN&gt;command&lt;/SPAN&gt; &lt;SPAN&gt;using&lt;/SPAN&gt; &lt;SPAN&gt;EEM&lt;/SPAN&gt; &lt;SPAN&gt;but&lt;/SPAN&gt; &lt;SPAN&gt;I&lt;/SPAN&gt; &lt;SPAN&gt;left out&lt;/SPAN&gt; &lt;SPAN&gt;a switch&lt;/SPAN&gt; &lt;SPAN&gt;6500&lt;/SPAN&gt;&lt;SPAN&gt;, Core&lt;/SPAN&gt; &lt;SPAN&gt;of&lt;/SPAN&gt; &lt;SPAN&gt;Data&lt;/SPAN&gt; &lt;SPAN&gt;Center,&lt;/SPAN&gt; &lt;SPAN&gt;because the&lt;/SPAN&gt; &lt;SPAN&gt;version of the operating&lt;/SPAN&gt; &lt;SPAN&gt;system does not support&lt;/SPAN&gt; &lt;SPAN&gt;EEM&lt;/SPAN&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN class=""&gt;We have&lt;/SPAN&gt; &lt;SPAN&gt;configured&lt;/SPAN&gt; &lt;SPAN&gt;AAA&lt;/SPAN&gt; &lt;SPAN&gt;and do&lt;/SPAN&gt; &lt;SPAN&gt;authentication&lt;/SPAN&gt; &lt;SPAN&gt;against a&lt;/SPAN&gt; &lt;SPAN&gt;TACACS&lt;/SPAN&gt; &lt;SPAN&gt;server&lt;/SPAN&gt; &lt;SPAN&gt;where&lt;/SPAN&gt; &lt;SPAN&gt;users&lt;/SPAN&gt; &lt;SPAN class=""&gt;listed&lt;/SPAN&gt; &lt;SPAN class=""&gt;there&lt;/SPAN&gt; &lt;SPAN&gt;(&lt;/SPAN&gt;&lt;SPAN&gt;nonlocal&lt;/SPAN&gt;&lt;SPAN&gt;) to access&lt;/SPAN&gt; &lt;SPAN&gt;the devices.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN class=""&gt;In fact,&lt;/SPAN&gt; &lt;SPAN class=""&gt;we grant&lt;/SPAN&gt; &lt;SPAN class=""&gt;permissions&lt;/SPAN&gt; &lt;SPAN&gt;to&lt;/SPAN&gt; &lt;SPAN&gt;execute&lt;/SPAN&gt; &lt;SPAN&gt;certain commands&lt;/SPAN&gt; &lt;SPAN&gt;only&lt;/SPAN&gt; &lt;SPAN&gt;via the&lt;/SPAN&gt; &lt;SPAN&gt;file "&lt;/SPAN&gt;&lt;SPAN class=""&gt;tac_plus.conf&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt; &lt;SPAN class=""&gt;that resides on the&lt;/SPAN&gt; &lt;SPAN&gt;TACACS&lt;/SPAN&gt; &lt;SPAN&gt;server&lt;/SPAN&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN class=""&gt;What&lt;/SPAN&gt; &lt;SPAN class=""&gt;I could not do&lt;/SPAN&gt; &lt;SPAN&gt;is&lt;/SPAN&gt; &lt;SPAN class=""&gt;restrict the execution&lt;/SPAN&gt; &lt;SPAN&gt;of&lt;/SPAN&gt; &lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN&gt;Reload"&lt;/SPAN&gt; &lt;SPAN&gt;using the same method&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt; &lt;SPAN&gt;only&lt;/SPAN&gt; &lt;SPAN class=""&gt;I got&lt;/SPAN&gt; &lt;SPAN&gt;doing&lt;/SPAN&gt; &lt;SPAN&gt;with&lt;/SPAN&gt; &lt;SPAN&gt;EEM&lt;/SPAN&gt; &lt;SPAN class=""&gt;on routers&lt;/SPAN&gt; &lt;SPAN class=""&gt;and&lt;/SPAN&gt; &lt;SPAN&gt;switches&lt;/SPAN&gt; &lt;SPAN&gt;critical&lt;/SPAN&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I would like&lt;/SPAN&gt; &lt;SPAN&gt;to know if&lt;/SPAN&gt; &lt;SPAN&gt;it is possible to&lt;/SPAN&gt; &lt;SPAN class=""&gt;restrict the&lt;/SPAN&gt; &lt;SPAN&gt;"reload&lt;/SPAN&gt;&lt;SPAN&gt;" command&lt;/SPAN&gt; &lt;SPAN&gt;on certain devices&lt;/SPAN&gt;&lt;SPAN class=""&gt;, configuring&lt;/SPAN&gt; &lt;SPAN&gt;the instructions&lt;/SPAN&gt; &lt;SPAN&gt;in the "&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;tac_plus.conf&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN class=""&gt;" file.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN class=""&gt;Thank you very much.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 06:54:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-restrict-quot-reload-quot-command-on-some-devices/m-p/2858237#M39234</guid>
      <dc:creator>JCRE</dc:creator>
      <dc:date>2019-03-11T06:54:06Z</dc:date>
    </item>
    <item>
      <title>Hi</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-restrict-quot-reload-quot-command-on-some-devices/m-p/2858238#M39236</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I've never used in production other tacacs server except Cisco ACS.&lt;/P&gt;
&lt;P&gt;However, on your tac_plus.conf, you can create some profiles and deny or permit some commands. Within this profiles, you can do a deny "reload". Have you tried it?&lt;/P&gt;
&lt;P&gt;It should looks like:&lt;/P&gt;
&lt;P&gt;group = Usercommand&amp;nbsp;{&lt;BR /&gt; default service = permit&lt;BR /&gt; cmd = no {&lt;BR /&gt; deny reload*&lt;BR /&gt;....."&lt;/P&gt;
&lt;P&gt;On the switch, I assume you have configured the aaa authorization command?&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;PS: Please don't forget to rate and mark as correct answer if this solved your issue&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jun 2016 20:56:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-restrict-quot-reload-quot-command-on-some-devices/m-p/2858238#M39236</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2016-06-30T20:56:21Z</dc:date>
    </item>
    <item>
      <title>Hi supportlan,</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-restrict-quot-reload-quot-command-on-some-devices/m-p/2858239#M39239</link>
      <description>&lt;P&gt;Hi &lt;STRONG&gt;supportlan&lt;/STRONG&gt;,&lt;/P&gt;
&lt;DIV id="gt-res-content" class="almost_half_cell"&gt;
&lt;DIV dir="ltr"&gt;&lt;SPAN id="result_box" class="" lang="en"&gt;&lt;SPAN title="Nosotros usamos el archivo tac_plus.conf, a través del cual permitimos determinados comandos, por ejemplo:

"&gt;&lt;SPAN title="Nosotros usamos el archivo tac_plus.conf, a través del cual permitimos determinados comandos, esto es una parte de lo que tenemos configurado:

"&gt;We use the tac_plus.conf file, through which we allow certain commands, this is part of what we have configured:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN title="group = monitoreo {
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;"&gt;&lt;SPAN style="color: #ff0000;"&gt;monitoring group = {&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;SPAN title="#Mesa de Monitoreo - Utilizan Skey y tienen comandos permitidos
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;"&gt;#Mesa Monitoring - Use Skey and have allowed commands&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN title="login = skey
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;"&gt;login = skey&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN title="service = exec {
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;"&gt;service = exec {&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN title="}
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;"&gt;}&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN title="cmd = configure {
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;"&gt;cmd = set {&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN title="permit terminal
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;"&gt;permit terminal&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN title="}
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;"&gt;}&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN title="cmd = interface {
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;"&gt;cmd = interface {&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN title="permit .*
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;"&gt;permit. *&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN title="}
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;"&gt;}&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN title="cmd = ip {
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;"&gt;cmd = ip {&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN title="permit accounting
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;"&gt;permit accounting&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN title="}

"&gt;&lt;SPAN style="color: #ff0000;"&gt;}&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN title="Si yo aplico la denegación del comando &amp;quot;reload&amp;quot; tal como vos lo sugerís, esto aplicaría a todos los dispositivos de la red, pero nosotros solo queremos hacerlo sobre los dispositivos considerados Core.
"&gt;If I apply the denial of "reload" command as what you suggest, this would apply to all devices on the network, but we just want to do about the devices considered Core.&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN title="¿Estoy en lo cierto?

"&gt;&lt;SPAN title="¿Estoy yo en lo cierto?

"&gt;Am I right?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN title="Sí, te confirmo que tenemos configurado &amp;quot;aaa authorization command&amp;quot;.

"&gt;Yes, I confirm that we have set "aaa authorization command".&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN title="Esto es lo que tenemos configurado en el switch:

"&gt;This is what we have configured on the switch:&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;SPAN title="aaa new-model
"&gt;aaa new-model&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN title="aaa authentication login default group tacacs+ local
"&gt;aaa authentication login default group tacacs Local +&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN title="aaa authorization console
"&gt;aaa authorization console&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN title="aaa authorization config-commands
"&gt;aaa authorization config-commands&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN title="aaa authorization exec default group tacacs+ local
"&gt;aaa authorization exec default group tacacs Local +&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN title="aaa authorization commands 1 default group tacacs+ if-authenticated local
"&gt;aaa authorization commands 1 default group tacacs + if-authenticated Local&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN title="aaa authorization commands 15 default group tacacs+ if-authenticated local"&gt;aaa authorization commands 15 default group tacacs + if-authenticated Local&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks for your help.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Jul 2016 13:21:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-restrict-quot-reload-quot-command-on-some-devices/m-p/2858239#M39239</guid>
      <dc:creator>JCRE</dc:creator>
      <dc:date>2016-07-01T13:21:30Z</dc:date>
    </item>
    <item>
      <title>On ACS it would be possible</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-restrict-quot-reload-quot-command-on-some-devices/m-p/2858240#M39243</link>
      <description>&lt;P&gt;On ACS it would be possible but don't know on your server. Are you able to define rules on specific nas-ip?&lt;/P&gt;
&lt;P&gt;I'm not very familiar with 3rd party tacacs server. As I know you can define rules per user but what about nas-ip (client device)?&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;PS: Please don't forget to rate and mark as correct answer if this solved your issue&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Jul 2016 13:50:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-restrict-quot-reload-quot-command-on-some-devices/m-p/2858240#M39243</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2016-07-01T13:50:45Z</dc:date>
    </item>
    <item>
      <title>Hello, I very much appreciate</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-restrict-quot-reload-quot-command-on-some-devices/m-p/2858241#M39244</link>
      <description>&lt;P&gt;&lt;SPAN id="result_box" class="" lang="en"&gt;&lt;SPAN class=""&gt;Hello,&lt;/SPAN&gt; &lt;SPAN&gt;I very much appreciate&lt;/SPAN&gt; &lt;SPAN&gt;your&lt;/SPAN&gt; &lt;SPAN&gt;answer, I believe&lt;/SPAN&gt; &lt;SPAN&gt;to be right&lt;/SPAN&gt; &lt;SPAN&gt;when I say&lt;/SPAN&gt; &lt;SPAN&gt;that if I use&lt;/SPAN&gt; &lt;SPAN class=""&gt;"deny&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt; &lt;SPAN&gt;for a command,&lt;/SPAN&gt; &lt;SPAN&gt;this&lt;/SPAN&gt; &lt;SPAN&gt;applies&lt;/SPAN&gt; &lt;SPAN&gt;across the network&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt; &lt;SPAN&gt;therefore I&lt;/SPAN&gt; &lt;SPAN&gt;is not helpful&lt;/SPAN&gt; &lt;SPAN&gt;to&lt;/SPAN&gt; &lt;SPAN class=""&gt;our case.&lt;/SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN id="result_box" class="" lang="en"&gt;&lt;STRONG&gt;Anyway, thank you very much for your time and help.&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Jul 2016 14:28:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-restrict-quot-reload-quot-command-on-some-devices/m-p/2858241#M39244</guid>
      <dc:creator>JCRE</dc:creator>
      <dc:date>2016-07-01T14:28:41Z</dc:date>
    </item>
    <item>
      <title>Across the network, well it</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-restrict-quot-reload-quot-command-on-some-devices/m-p/2858242#M39247</link>
      <description>&lt;P&gt;Across the network, well it depend if you can do rule set bases on nas-ip.&lt;/P&gt;
&lt;P&gt;you're very welcome&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Jul 2016 14:36:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-restrict-quot-reload-quot-command-on-some-devices/m-p/2858242#M39247</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2016-07-01T14:36:26Z</dc:date>
    </item>
  </channel>
</rss>

