<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic exec authorization with radius.. in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/exec-authorization-with-radius/m-p/797927#M409006</link>
    <description>&lt;P&gt;Hi guys, i was configuring auth-proxy . i had a&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;m/c---(inside)router(outside)---internet&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;now i want that a normal user is not able to get the telnet access of my router, only certain users can have the telnet access fromt the inside. i dont want to use NAR. i want to do this only with radius authorization.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i was looking for controlling the access of the users to the router with the help of radius,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authorization exec default group tacacs+&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;when i use the above command i knw that i can control the shell access by checking shell box,but when i use the below command&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authorization exec default group radius&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i was not able to find any particular  radius av-pair which can control the exec shell access in respect to the above one. &lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 22:22:25 GMT</pubDate>
    <dc:creator>diptanshusingh</dc:creator>
    <dc:date>2019-03-10T22:22:25Z</dc:date>
    <item>
      <title>exec authorization with radius..</title>
      <link>https://community.cisco.com/t5/network-access-control/exec-authorization-with-radius/m-p/797927#M409006</link>
      <description>&lt;P&gt;Hi guys, i was configuring auth-proxy . i had a&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;m/c---(inside)router(outside)---internet&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;now i want that a normal user is not able to get the telnet access of my router, only certain users can have the telnet access fromt the inside. i dont want to use NAR. i want to do this only with radius authorization.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i was looking for controlling the access of the users to the router with the help of radius,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authorization exec default group tacacs+&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;when i use the above command i knw that i can control the shell access by checking shell box,but when i use the below command&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authorization exec default group radius&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i was not able to find any particular  radius av-pair which can control the exec shell access in respect to the above one. &lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 22:22:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/exec-authorization-with-radius/m-p/797927#M409006</guid>
      <dc:creator>diptanshusingh</dc:creator>
      <dc:date>2019-03-10T22:22:25Z</dc:date>
    </item>
    <item>
      <title>Re: exec authorization with radius..</title>
      <link>https://community.cisco.com/t5/network-access-control/exec-authorization-with-radius/m-p/797928#M409007</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Following is the av-pair for privilege level 15&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;shell:priv-lvl=15&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In Addition also select attribute 6&lt;/P&gt;&lt;P&gt;Service-type = login&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;~Rohit&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Sep 2007 07:38:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/exec-authorization-with-radius/m-p/797928#M409007</guid>
      <dc:creator>rochopra</dc:creator>
      <dc:date>2007-09-05T07:38:23Z</dc:date>
    </item>
    <item>
      <title>Re: exec authorization with radius..</title>
      <link>https://community.cisco.com/t5/network-access-control/exec-authorization-with-radius/m-p/797929#M409008</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi rohit, i am looking to deny a specific user from getting the exec shell of my router with radius authorization.. the above attributes will assign a user a priv level 15... &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Sep 2007 07:57:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/exec-authorization-with-radius/m-p/797929#M409008</guid>
      <dc:creator>diptanshusingh</dc:creator>
      <dc:date>2007-09-05T07:57:20Z</dc:date>
    </item>
    <item>
      <title>Re: exec authorization with radius..</title>
      <link>https://community.cisco.com/t5/network-access-control/exec-authorization-with-radius/m-p/797930#M409009</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So do not assign any privilege level to the user , or assign privilege level 0.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;~Rohit&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Sep 2007 01:00:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/exec-authorization-with-radius/m-p/797930#M409009</guid>
      <dc:creator>rochopra</dc:creator>
      <dc:date>2007-09-07T01:00:53Z</dc:date>
    </item>
    <item>
      <title>Re: exec authorization with radius..</title>
      <link>https://community.cisco.com/t5/network-access-control/exec-authorization-with-radius/m-p/797931#M409010</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Make use of this,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;shell:priv-lvl=15&lt;/P&gt;&lt;P&gt;shell:autocmd=exit&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So what will happen with this is, as soon as user tries to log into shell, BOOM!, user will exit out.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NOTE: I have not tried this exactly, but should work, you might be required to use separator, ";" i.e.,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;shell:priv-lvl=15;&lt;/P&gt;&lt;P&gt;shell:autocmd=exit&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Prem&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 08 Sep 2007 15:54:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/exec-authorization-with-radius/m-p/797931#M409010</guid>
      <dc:creator>Premdeep Banga</dc:creator>
      <dc:date>2007-09-08T15:54:38Z</dc:date>
    </item>
  </channel>
</rss>

