<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AAA IOS HTTS Cmd Authorization in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/aaa-ios-htts-cmd-authorization/m-p/1009411#M401478</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Charlie,&lt;/P&gt;&lt;P&gt;In order to access SDM, we would always need privilege level 15. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;~JG&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 22 Jun 2008 03:01:42 GMT</pubDate>
    <dc:creator>Jagdeep Gambhir</dc:creator>
    <dc:date>2008-06-22T03:01:42Z</dc:date>
    <item>
      <title>AAA IOS HTTS Cmd Authorization</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-ios-htts-cmd-authorization/m-p/1009410#M401477</link>
      <description>&lt;P&gt;On my ACS SE 4.2 setup I have CMD Authorization set up and it works nice, Service Desk type cmds: show, clear, telnet, traceroute, exit and then another group with full access (all cmds permitted).  both user groups have Priv. Levels = 15.&lt;/P&gt;&lt;P&gt;However, (there is always one) with SDM access via HTTPS it appears that all you need is Priv. Level 15 to run SDM and make any configuration changes.&lt;/P&gt;&lt;P&gt;With my current setup, a user in the NetDevOper group when Telnet'ed or SSH'ed has access to a few commands, i.e. clear crypto sessions.&lt;/P&gt;&lt;P&gt;If I change this group from Priv Level 15 to, say 14, then I will have to 'Demote' the Clear command to Priv Level 14 on each device so this group can do simple clear commands.&lt;/P&gt;&lt;P&gt;My other choice is to disable HTTP access altogether, which is what I am leaning towards.  &lt;/P&gt;&lt;P&gt;Is there another option available?&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 22:55:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-ios-htts-cmd-authorization/m-p/1009410#M401477</guid>
      <dc:creator>charlie-hall</dc:creator>
      <dc:date>2019-03-10T22:55:22Z</dc:date>
    </item>
    <item>
      <title>Re: AAA IOS HTTS Cmd Authorization</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-ios-htts-cmd-authorization/m-p/1009411#M401478</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Charlie,&lt;/P&gt;&lt;P&gt;In order to access SDM, we would always need privilege level 15. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;~JG&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 22 Jun 2008 03:01:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-ios-htts-cmd-authorization/m-p/1009411#M401478</guid>
      <dc:creator>Jagdeep Gambhir</dc:creator>
      <dc:date>2008-06-22T03:01:42Z</dc:date>
    </item>
    <item>
      <title>Re: AAA IOS HTTS Cmd Authorization</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-ios-htts-cmd-authorization/m-p/1009412#M401479</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi JG,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your reply.&lt;/P&gt;&lt;P&gt;Do you know if there is a way to limit user access via HTTP(S) (SDM) so my Service Desk can use it, but cannot make configuration changes?&lt;/P&gt;&lt;P&gt;It appears to me that the IOS code for HTTP(S) (SDM) access is only checking to see if the user has Priv Level=15 and there is no other varibles being check.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If true, I will just disable HTTP(S) SDM access to the routers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Charlie &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Jun 2008 14:57:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-ios-htts-cmd-authorization/m-p/1009412#M401479</guid>
      <dc:creator>charlie-hall</dc:creator>
      <dc:date>2008-06-23T14:57:16Z</dc:date>
    </item>
  </channel>
</rss>

