<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AAA policy help in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/aaa-policy-help/m-p/918287#M407948</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Thanks for your reply.  But this thing I have already done on ACS.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After intorducing following commands on Router, it worked.&lt;/P&gt;&lt;P&gt;aaa authorization commands 1 default tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authorization commands 2 default tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authorization commands 3 default tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authorization commands 4 default tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authorization commands 5 default tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authorization commands 6 default tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authorization commands 7 default tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authorization commands 8 default tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authorization commands 9 default tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authorization commands 10 default tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authorization commands 11 default tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authorization commands 12 default tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authorization commands 13 default tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authorization commands 14 default tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authorization commands 15 default tacacs+ local&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your help&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Bharat&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 10 Jan 2008 14:47:58 GMT</pubDate>
    <dc:creator>Bharat Negi</dc:creator>
    <dc:date>2008-01-10T14:47:58Z</dc:date>
    <item>
      <title>AAA policy help</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-policy-help/m-p/918285#M407946</link>
      <description>&lt;P&gt;Hi All&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;user1 &amp;gt;&amp;gt;&amp;gt;GroupA &amp;amp; user2 &amp;gt;&amp;gt;&amp;gt;GroupB&lt;/P&gt;&lt;P&gt;Router1 &amp;gt;&amp;gt;&amp;gt;NDG-A &amp;amp; Router2 &amp;gt;&amp;gt;&amp;gt;NDG-B&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now, &lt;/P&gt;&lt;P&gt;GroupA user must have "sh run" permission on NDG-A but not on NDG-B.&lt;/P&gt;&lt;P&gt;GroupB user must have "sh run" permission on NDG-B but not on NDG-A.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I created two shell command authorisation set  and mapped it to GroupA &amp;amp; GroupB.  Then inside the Group, I mapped the Shell command set to NDG.  Here I have two associations.&lt;/P&gt;&lt;P&gt;(**I have tested with single association and its working.  But not not with two)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But somehow its not working.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Bharat&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 22:35:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-policy-help/m-p/918285#M407946</guid>
      <dc:creator>Bharat Negi</dc:creator>
      <dc:date>2019-03-10T22:35:48Z</dc:date>
    </item>
    <item>
      <title>Re: AAA policy help</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-policy-help/m-p/918286#M407947</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Bharat,&lt;/P&gt;&lt;P&gt;You need to set up Assign a Shell Command Authorization Set on a per Network Device Group Basis&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In GroupA---&amp;gt; Assign a Shell Command Authorization Set on a per Network Device Group Basis----&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Add NDG A&amp;lt;====&amp;gt; Allow show run set**&lt;/P&gt;&lt;P&gt;Add NDG B&amp;lt;====&amp;gt; Deny all***&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In Group B-----&amp;gt;Assign a Shell Command Authorization Set on a per Network Device Group Basis----&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Add NDG B&amp;lt;====&amp;gt; Allow show run **&lt;/P&gt;&lt;P&gt;ADD NDG A&amp;lt;====&amp;gt; Deny all***&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;** Command autho set allowing Only show run&lt;/P&gt;&lt;P&gt;*** Command author set that deny's every thing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please check this link,&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://cisco.com/en/US/products/sw/secursw/ps2086/products_configuration_example09186a00808d9138.shtml" target="_blank"&gt;http://cisco.com/en/US/products/sw/secursw/ps2086/products_configuration_example09186a00808d9138.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps !&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;~JG&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do rate helpful posts&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Jan 2008 14:20:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-policy-help/m-p/918286#M407947</guid>
      <dc:creator>Jagdeep Gambhir</dc:creator>
      <dc:date>2008-01-10T14:20:57Z</dc:date>
    </item>
    <item>
      <title>Re: AAA policy help</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-policy-help/m-p/918287#M407948</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Thanks for your reply.  But this thing I have already done on ACS.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After intorducing following commands on Router, it worked.&lt;/P&gt;&lt;P&gt;aaa authorization commands 1 default tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authorization commands 2 default tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authorization commands 3 default tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authorization commands 4 default tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authorization commands 5 default tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authorization commands 6 default tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authorization commands 7 default tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authorization commands 8 default tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authorization commands 9 default tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authorization commands 10 default tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authorization commands 11 default tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authorization commands 12 default tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authorization commands 13 default tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authorization commands 14 default tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authorization commands 15 default tacacs+ local&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your help&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Bharat&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Jan 2008 14:47:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-policy-help/m-p/918287#M407948</guid>
      <dc:creator>Bharat Negi</dc:creator>
      <dc:date>2008-01-10T14:47:58Z</dc:date>
    </item>
    <item>
      <title>Re: AAA policy help</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-policy-help/m-p/918288#M407949</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We need to have these commands on the router. You never mentioned it in your orignal post.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyways , there is no need to put 15 line on the router. Just three will take care&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; i.e.&lt;/P&gt;&lt;P&gt;aaa authorization commands 0 default tacacs+ local &lt;/P&gt;&lt;P&gt;aaa authorization commands 1 default tacacs+ local &lt;/P&gt;&lt;P&gt;aaa authorization commands 15 default tacacs+ local &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No need to count from 1 to 15.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;~JG&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do rate helpful posts&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Jan 2008 14:23:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-policy-help/m-p/918288#M407949</guid>
      <dc:creator>Jagdeep Gambhir</dc:creator>
      <dc:date>2008-01-11T14:23:01Z</dc:date>
    </item>
  </channel>
</rss>

