<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AAA Different Permissions again in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/aaa-different-permissions-again/m-p/1340495#M405262</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is what I explained you in my last update to your POST.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please check again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Plz let me know if you face any issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;JK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 20 Aug 2009 14:23:12 GMT</pubDate>
    <dc:creator>Jatin Katyal</dc:creator>
    <dc:date>2009-08-20T14:23:12Z</dc:date>
    <item>
      <title>AAA Different Permissions again</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-different-permissions-again/m-p/1340494#M405261</link>
      <description>&lt;P&gt;In a previous post I asked how I could assign RO permissions when a user connects to a firewall, but RW access when they connect to a switch, I was given a Cisco Kb to follow but this only allows the user to be in a RO or RW group.. I need the same user "Joe Blogs" RO access for one device and RW for another.&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 23:39:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-different-permissions-again/m-p/1340494#M405261</guid>
      <dc:creator>networker99</dc:creator>
      <dc:date>2019-03-10T23:39:28Z</dc:date>
    </item>
    <item>
      <title>Re: AAA Different Permissions again</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-different-permissions-again/m-p/1340495#M405262</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is what I explained you in my last update to your POST.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please check again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Plz let me know if you face any issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;JK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Aug 2009 14:23:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-different-permissions-again/m-p/1340495#M405262</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2009-08-20T14:23:12Z</dc:date>
    </item>
    <item>
      <title>Re: AAA Different Permissions again</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-different-permissions-again/m-p/1340496#M405265</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I followed your post but how does it know when to use the RW group as opposed to the RO group?..  I can only place the user in one group..&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Aug 2009 15:03:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-different-permissions-again/m-p/1340496#M405265</guid>
      <dc:creator>networker99</dc:creator>
      <dc:date>2009-08-20T15:03:23Z</dc:date>
    </item>
    <item>
      <title>Re: AAA Different Permissions again</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-different-permissions-again/m-p/1340497#M405267</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This can be done by creating two NDG's and map them with respective command authorization set under the same user account.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Creating NDG's&lt;/P&gt;&lt;P&gt;----------------&lt;/P&gt;&lt;P&gt;NDG1 for ASA ---add ASA as a aaa client&lt;/P&gt;&lt;P&gt;NDG2 for switch---add switch as aaa client.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Creating command authorization set&lt;/P&gt;&lt;P&gt;----------------------------------&lt;/P&gt;&lt;P&gt;Create two different command authorization set under shared profile component for&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Switch = permit all&lt;/P&gt;&lt;P&gt;ASA = Deny all&lt;/P&gt;&lt;P&gt;and permit show only&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now, under the user account you need to map the NDG with appropriate command authorization set. When user tries to login to switch/ASA it will check the authorization set mapped with their NDG's &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;JK&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Aug 2009 15:56:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-different-permissions-again/m-p/1340497#M405267</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2009-08-20T15:56:39Z</dc:date>
    </item>
    <item>
      <title>Re: AAA Different Permissions again</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-different-permissions-again/m-p/1340498#M405269</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;"Now, under the user account you need to map the NDG with appropriate command authorization set."  I cant see how to do this.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Aug 2009 16:09:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-different-permissions-again/m-p/1340498#M405269</guid>
      <dc:creator>networker99</dc:creator>
      <dc:date>2009-08-20T16:09:55Z</dc:date>
    </item>
    <item>
      <title>Re: AAA Different Permissions again</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-different-permissions-again/m-p/1340499#M405270</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Under the user account &amp;gt;&amp;gt; Look for this radio option&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Assign a Shell Command Authorization Set on a per Network Device Group Basis.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Attached is the screen shot of the same.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Aug 2009 16:41:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-different-permissions-again/m-p/1340499#M405270</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2009-08-20T16:41:26Z</dc:date>
    </item>
    <item>
      <title>Re: AAA Different Permissions again</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-different-permissions-again/m-p/1340500#M405272</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Doesnt exist in version 4.1&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Aug 2009 16:52:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-different-permissions-again/m-p/1340500#M405272</guid>
      <dc:creator>networker99</dc:creator>
      <dc:date>2009-08-20T16:52:08Z</dc:date>
    </item>
    <item>
      <title>Re: AAA Different Permissions again</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-different-permissions-again/m-p/1340501#M405275</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This does exist in 4.1.x&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need to enable this feature on the ACS under interface configuration &amp;gt; Advanced Options &amp;gt; check this option "Per-user TACACS+/RADIUS Attributes"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After that click on cancel &amp;gt; go to TACACS+ (Cisco) &amp;gt; check this option "Shell (exec)" for user &amp;gt; hit submit and you are done &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Aug 2009 17:17:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-different-permissions-again/m-p/1340501#M405275</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2009-08-20T17:17:23Z</dc:date>
    </item>
    <item>
      <title>Re: AAA Different Permissions again</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-different-permissions-again/m-p/1340502#M405277</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks, but I only have &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-None&lt;/P&gt;&lt;P&gt;-As Group &lt;/P&gt;&lt;P&gt;-Assign a Shell Command Auth for any network device&lt;/P&gt;&lt;P&gt;-Per User command authorization&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I dont have "Based on per network device group basis"&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Aug 2009 17:29:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-different-permissions-again/m-p/1340502#M405277</guid>
      <dc:creator>networker99</dc:creator>
      <dc:date>2009-08-20T17:29:09Z</dc:date>
    </item>
    <item>
      <title>Re: AAA Different Permissions again</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-different-permissions-again/m-p/1340503#M405279</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Got it !! didnt have NDG selected under interface options&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Aug 2009 17:41:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-different-permissions-again/m-p/1340503#M405279</guid>
      <dc:creator>networker99</dc:creator>
      <dc:date>2009-08-20T17:41:28Z</dc:date>
    </item>
  </channel>
</rss>

