<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi, in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-privilege-level-and-command-sets/m-p/2797371#M40530</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I have a simular problem but using user authencation on the TACAS, cannt find were to associate the user with a specific profile.&lt;/P&gt;</description>
    <pubDate>Wed, 18 May 2016 15:27:46 GMT</pubDate>
    <dc:creator>Chris McCann</dc:creator>
    <dc:date>2016-05-18T15:27:46Z</dc:date>
    <item>
      <title>ACS Privilege Level and Command Sets</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-privilege-level-and-command-sets/m-p/2797367#M40526</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;
&lt;P&gt;I've been tasked with setting up ACS 5.6 to be able to authorize MS domain security groups members to have specific command access to our equipment. I've got the domain association and groups added, I have an Access Policy with a rule that is working so my domain test account can login to the switch and perform only the commands in my Command Set.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;The issue is that when I assign a Shell Profile with privilege level 7 min/max to the rule, and the user logs in with this level, they are unable to see the commands that I've allowed in the Command Set. Is there a way to have ACS tell the IOS to automatically modify the commands visible to a specific privilege level when the user logs in, even though they aren't in that privilege level?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Any help greatly appreciated,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Chris Menuey&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 06:27:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-privilege-level-and-command-sets/m-p/2797367#M40526</guid>
      <dc:creator>chrismenuey</dc:creator>
      <dc:date>2019-03-11T06:27:38Z</dc:date>
    </item>
    <item>
      <title>Since you're using command</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-privilege-level-and-command-sets/m-p/2797368#M40527</link>
      <description>&lt;P&gt;Since you're using command authorization and restricting user to certain commands, why are we using privilege 7 and not 15?&lt;/P&gt;
&lt;P&gt;~Jatin&lt;/P&gt;</description>
      <pubDate>Tue, 09 Feb 2016 15:34:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-privilege-level-and-command-sets/m-p/2797368#M40527</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2016-02-09T15:34:21Z</dc:date>
    </item>
    <item>
      <title>It was an attempt to limit</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-privilege-level-and-command-sets/m-p/2797369#M40528</link>
      <description>&lt;P&gt;It was an attempt to limit the commands visible to the junior technicians to keep them from being inundated with commands that won't have prevalence to what they need to do, assign access vlan numbers to ports, use show commands, etc. We were under the assumption that ACS would be able to do this automatically with priv 7 based on the commands we put in the command set, since it doesn't appear possible I'll just be using priv 15 and doing additional training to let them know that even though they can see it, doesn't mean they can use it &lt;span class="lia-unicode-emoji" title=":grinning_face_with_smiling_eyes:"&gt;😄&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks for the confirmation of this Jatin, help is always appreciated &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Feb 2016 04:22:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-privilege-level-and-command-sets/m-p/2797369#M40528</guid>
      <dc:creator>chrismenuey</dc:creator>
      <dc:date>2016-02-11T04:22:32Z</dc:date>
    </item>
    <item>
      <title>yw ! Here is a link to</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-privilege-level-and-command-sets/m-p/2797370#M40529</link>
      <description>&lt;P&gt;yw ! Here is a link to configure &lt;A href="http://www.cisco.com/c/en/us/support/docs/security/secure-access-control-system/113590-acs5-tacacs-config.html"&gt;command authorization on ACS&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;~ Jatin&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Feb 2016 06:19:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-privilege-level-and-command-sets/m-p/2797370#M40529</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2016-02-11T06:19:50Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-privilege-level-and-command-sets/m-p/2797371#M40530</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I have a simular problem but using user authencation on the TACAS, cannt find were to associate the user with a specific profile.&lt;/P&gt;</description>
      <pubDate>Wed, 18 May 2016 15:27:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-privilege-level-and-command-sets/m-p/2797371#M40530</guid>
      <dc:creator>Chris McCann</dc:creator>
      <dc:date>2016-05-18T15:27:46Z</dc:date>
    </item>
  </channel>
</rss>

