<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AAA Authorization in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/aaa-authorization/m-p/1532717#M414168</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello cadetalain&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Thanks for effort for providing me the link, but unfortunately the solution doen't work for me,Strange the user with privilege 2 is placed in privilege exec&amp;nbsp;&amp;nbsp; level 2 (Switch#) mode but user who try to login by privilege 15 they are place in user exec mode.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Also the command authorization is not working for privilege level 2 users???&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Waiting for answers Experts&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 10 Dec 2010 20:02:23 GMT</pubDate>
    <dc:creator>thomasandy32</dc:creator>
    <dc:date>2010-12-10T20:02:23Z</dc:date>
    <item>
      <title>AAA Authorization</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-authorization/m-p/1532713#M414164</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;If i want to allow certain commands for a user on switch with privilege level 2,,Do i have to create the&amp;nbsp; user in local database on switch as well as in ACS ?????? I dont think so ,&amp;nbsp;&amp;nbsp; Correct me if i m wrong???&lt;BR /&gt;&lt;/LI&gt;&lt;LI&gt;If i&amp;nbsp; have&amp;nbsp; specified privilege level 2&amp;nbsp; command in switch i dont need to specify in shell command set????? correct me if i m wrong??&lt;BR /&gt;&lt;/LI&gt;&lt;LI&gt;If i have specify in shell command set then i dont need to specify in switch ???? correct me if i m wrong?&lt;BR /&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please answer above 3 queries.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I facing issues in authorization,This is the below what i have done.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;i have created a local user in ACS 5.0 and&lt;/LI&gt;&lt;LI&gt; i have assigned hin to identity groups of&amp;nbsp; admin,&lt;/LI&gt;&lt;LI&gt;i have assigned him to all Access switches Device type &lt;BR /&gt;&lt;/LI&gt;&lt;LI&gt; Access Policies&amp;gt;default Device admin&amp;gt;authorization i created a privilege level of 15 and assigned to it. &lt;BR /&gt;&lt;/LI&gt;&lt;LI&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; I m facing&amp;nbsp; issues with admin privilege&amp;nbsp; i have given a privilege 15 in&amp;nbsp; authorization profile but still a user created with the following&amp;nbsp; command username XXX privilege 15 password cisco is been prompt for enable secret password&lt;BR /&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="color: #ff0000; "&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 00:38:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-authorization/m-p/1532713#M414164</guid>
      <dc:creator>thomasandy32</dc:creator>
      <dc:date>2019-03-11T00:38:35Z</dc:date>
    </item>
    <item>
      <title>Re: AAA Authorization</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-authorization/m-p/1532714#M414165</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;To try to answer your questions &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;OL&gt;&lt;LI&gt;If i want to allow certain commands for a user on switch with privilege level 2,,Do i have to create the&amp;nbsp; user in local database on switch as well as in ACS ?????? I dont think so ,&amp;nbsp;&amp;nbsp; Correct me if i m wrong???&lt;/LI&gt;&lt;/OL&gt;&lt;/PRE&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;Correct, you don't need to&lt;/DIV&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2 If i&amp;nbsp; have&amp;nbsp; specified privilege level 2&amp;nbsp; command in switch i dont need to specify in shell command set????? correct me if i m wrong??&lt;/PRE&gt;&lt;DIV&gt;If you have move a command under priv 2 and a user is priv 2 he will be able to use it. You need to have command authorization enabled of course. &lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3 If i have specify in shell command set then i dont need to specify in switch ???? correct me if i m wrong?&lt;/PRE&gt;&lt;P&gt;I am not sure what you mean. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope it helps a little.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Dec 2010 21:48:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-authorization/m-p/1532714#M414165</guid>
      <dc:creator>Panos Kampanakis</dc:creator>
      <dc:date>2010-12-09T21:48:14Z</dc:date>
    </item>
    <item>
      <title>Re: AAA Authorization</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-authorization/m-p/1532715#M414166</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I want to all&amp;nbsp; the below&amp;nbsp; commands&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;privilege exec level 2 undebug all&lt;BR /&gt; privilege exec all level 2 debug&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt; i want to configure in ACS,I have routed to Policy elements&amp;gt;Device Administration&amp;gt;Command Set and i have created it and i have assigned a command set to identity group but the users are not able to execute these commands?????&lt;STRONG style="color: #ff0000; "&gt; Please have a look in the attached.&lt;/STRONG&gt;&lt;BR /&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; I have created a shell profile with privi level 15 but user are prompt to type enable secret password, when they are in privi level 15 then why they&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; are prompted again for enable secret????&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Dec 2010 22:07:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-authorization/m-p/1532715#M414166</guid>
      <dc:creator>thomasandy32</dc:creator>
      <dc:date>2010-12-09T22:07:43Z</dc:date>
    </item>
    <item>
      <title>Re: AAA Authorization</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-authorization/m-p/1532716#M414167</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;2)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; I have created a shell profile with privi level 15 but user are 
prompt to type enable secret password, when they are in privi level 15 
then why they&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; are prompted again for enable secret????&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;I found the answer for this question here on this forum:&amp;nbsp; &lt;A href="https://community.cisco.com/message/621198"&gt;https://supportforums.cisco.com/message/621198&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Dec 2010 10:10:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-authorization/m-p/1532716#M414167</guid>
      <dc:creator>cadet alain</dc:creator>
      <dc:date>2010-12-10T10:10:12Z</dc:date>
    </item>
    <item>
      <title>Re: AAA Authorization</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-authorization/m-p/1532717#M414168</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello cadetalain&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Thanks for effort for providing me the link, but unfortunately the solution doen't work for me,Strange the user with privilege 2 is placed in privilege exec&amp;nbsp;&amp;nbsp; level 2 (Switch#) mode but user who try to login by privilege 15 they are place in user exec mode.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Also the command authorization is not working for privilege level 2 users???&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Waiting for answers Experts&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Dec 2010 20:02:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-authorization/m-p/1532717#M414168</guid>
      <dc:creator>thomasandy32</dc:creator>
      <dc:date>2010-12-10T20:02:23Z</dc:date>
    </item>
    <item>
      <title>Re: AAA Authorization</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-authorization/m-p/1532718#M414169</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Dears,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can anybody help me for user privileges atleast. I have stuck in this problem from very long time. please have a look on the attached in above mail's&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Dec 2010 19:40:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-authorization/m-p/1532718#M414169</guid>
      <dc:creator>thomasandy32</dc:creator>
      <dc:date>2010-12-15T19:40:22Z</dc:date>
    </item>
    <item>
      <title>Re: AAA Authorization</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-authorization/m-p/1532719#M414170</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Maybe you can post debug aaa authorization and debug aaa authentication.&lt;/P&gt;&lt;P&gt;Did you try with local database only? If so did you get same result?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Alain.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Dec 2010 19:43:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-authorization/m-p/1532719#M414170</guid>
      <dc:creator>cadet alain</dc:creator>
      <dc:date>2010-12-15T19:43:03Z</dc:date>
    </item>
    <item>
      <title>Re: AAA Authorization</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-authorization/m-p/1532720#M414171</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With local authentication and authorization it is very fine, but when i remove command from switch to do authentication and authorization it does'nt.work with ACS server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Dec 2010 20:22:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-authorization/m-p/1532720#M414171</guid>
      <dc:creator>thomasandy32</dc:creator>
      <dc:date>2010-12-15T20:22:46Z</dc:date>
    </item>
    <item>
      <title>Re: AAA Authorization</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-authorization/m-p/1532721#M414172</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Maybe it's a stupid question but as I said before I never used ACS appliance but only 4.x on 2k3, didn't you forget to tick checkbox in your last bmp included in your rar file? because I read below that default is enabled if no match.&lt;/P&gt;&lt;P&gt;But I think&amp;nbsp; debug authentication and authorization could be useful.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Alain.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Dec 2010 10:44:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-authorization/m-p/1532721#M414172</guid>
      <dc:creator>cadet alain</dc:creator>
      <dc:date>2010-12-16T10:44:02Z</dc:date>
    </item>
    <item>
      <title>Re: AAA Authorization</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-authorization/m-p/1532722#M414173</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I m trying to login by user cisco with privilege 2 on ACS, privilege level 2&amp;nbsp; is accepted but not the commands that i have allowed for privilege level 2 in ACS??????&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please help. Below is the output for debug aaa authentication and debug aaa authorization.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Dec 18 00:22:42.779: AAA/AUTHEN/START (689535616): port='tty2' list='XXX' action=LOGIN service=LOGIN&lt;BR /&gt;Dec 18 00:22:42.779: AAA/AUTHEN/START (689535616): found list XXX&lt;BR /&gt;Dec 18 00:22:42.779: AAA/AUTHEN/START (689535616): Method=tacacs+ (tacacs+)&lt;BR /&gt;Dec 18 00:22:42.782: TAC+: send AUTHEN/START packet ver=192 id=689535616&lt;BR /&gt;Dec 18 00:22:42.999: TAC+: ver=192 id=689535616 received AUTHEN status = GETUSER&lt;BR /&gt;Dec 18 00:22:42.999: AAA/AUTHEN (689535616): status = GETUSER&lt;BR /&gt;Dec 18 00:22:47.117: AAA/AUTHEN/CONT (689535616): continue_login (user='(undef)')&lt;BR /&gt;Dec 18 00:22:47.117: AAA/AUTHEN (689535616): status = GETUSER&lt;BR /&gt;Dec 18 00:22:47.117: AAA/AUTHEN (689535616): Method=tacacs+ (tacacs+)&lt;BR /&gt;Dec 18 00:22:47.117: TAC+: send AUTHEN/CONT packet id=689535616&lt;BR /&gt;Dec 18 00:22:47.319: TAC+: ver=192 id=689535616 received AUTHEN status = GETPASS&lt;BR /&gt;Dec 18 00:22:47.319: AAA/AUTHEN (689535616): status = GETPASS&lt;BR /&gt;Dec 18 00:22:55.220: AAA/AUTHEN/CONT (689535616): continue_login (user='cisco')&lt;BR /&gt;Dec 18 00:22:55.220: AAA/AUTHEN (689535616): status = GETPASS&lt;BR /&gt;Dec 18 00:22:55.220: AAA/AUTHEN (689535616): Method=tacacs+ (tacacs+)&lt;BR /&gt;Dec 18 00:22:55.220: TAC+: send AUTHEN/CONT packet id=689535616&lt;BR /&gt;Dec 18 00:22:55.425: TAC+: ver=192 id=689535616 received AUTHEN status = PASS&lt;BR /&gt;Dec 18 00:22:55.425: AAA/AUTHEN (689535616): status = PASS&lt;BR /&gt;Dec 18 00:22:55.427: tty2 AAA/AUTHOR/EXEC (2575095510): Port='tty2' list='' service=EXEC&lt;BR /&gt;Dec 18 00:22:55.427: AAA/AUTHOR/EXEC: tty2 (2575095510) user='cisco'&lt;BR /&gt;Dec 18 00:22:55.427: tty2 AAA/AUTHOR/EXEC (2575095510): send AV service=shell&lt;BR /&gt;Dec 18 00:22:55.427: tty2 AAA/AUTHOR/EXEC (2575095510): send AV cmd*&lt;BR /&gt;Dec 18 00:22:55.427: tty2 AAA/AUTHOR/EXEC (2575095510): found list "default"&lt;BR /&gt;Dec 18 00:22:55.427: tty2 AAA/AUTHOR/EXEC (2575095510): Method=tacacs+ (tacacs+)&lt;BR /&gt;Dec 18 00:22:55.427: AAA/AUTHOR/TAC+: (2575095510): user=cisco&lt;BR /&gt;Dec 18 00:22:55.427: AAA/AUTHOR/TAC+: (2575095510): send AV service=shell&lt;BR /&gt;Dec 18 00:22:55.430: AAA/AUTHOR/TAC+: (2575095510): send AV cmd*&lt;BR /&gt;Dec 18 00:22:55.655: TAC+: (2575095510): received author response status = PASS_ADD&lt;BR /&gt;Dec 18 00:22:55.655: AAA/AUTHOR (2575095510): Post authorization status = PASS_ADD&lt;BR /&gt;Dec 18 00:22:55.655: AAA/AUTHOR/EXEC: Processing AV service=shell&lt;BR /&gt;Dec 18 00:22:55.655: AAA/AUTHOR/EXEC: Processing AV cmd*&lt;BR /&gt;Dec 18 00:22:55.658: AAA/AUTHOR/EXEC: Processing AV priv-lvl=2&lt;BR /&gt;Dec 18 00:22:55.658: AAA/AUTHOR/EXEC: Authorization successful&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Dec 2010 20:33:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-authorization/m-p/1532722#M414173</guid>
      <dc:creator>thomasandy32</dc:creator>
      <dc:date>2010-12-17T20:33:05Z</dc:date>
    </item>
    <item>
      <title>Re: AAA Authorization</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-authorization/m-p/1532723#M414174</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When this happens you have disabled privilege level 15 on line?&lt;/P&gt;&lt;P&gt;Have you put aaa authorization method on line?&lt;/P&gt;&lt;P&gt;Sorry but I don't know if you have changed things since first day.&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Alain.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Dec 2010 23:17:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-authorization/m-p/1532723#M414174</guid>
      <dc:creator>cadet alain</dc:creator>
      <dc:date>2010-12-17T23:17:46Z</dc:date>
    </item>
    <item>
      <title>Re: AAA Authorization</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-authorization/m-p/1532724#M414175</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Alain,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Me too facing the same problem, We need somebody who has played&amp;nbsp; on ACS 5.0 like a game&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have not enabled aaa authorization on line, it is enabled globally on switch with command aaa authorization exec default group tacacs+, When a specific user with privilege level 2 login he is directly placed in Privilege mode of level 2 BUT he is not able to do authorization of the commands what i have enabled for level 2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 18 Dec 2010 18:28:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-authorization/m-p/1532724#M414175</guid>
      <dc:creator>estelamathew</dc:creator>
      <dc:date>2010-12-18T18:28:11Z</dc:date>
    </item>
    <item>
      <title>Re: AAA Authorization</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-authorization/m-p/1532725#M414176</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hello Experts,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there nobody who can solve my authorization problem????? pls pls sugggest where i m doing wrong.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 26 Dec 2010 19:25:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-authorization/m-p/1532725#M414176</guid>
      <dc:creator>thomasandy32</dc:creator>
      <dc:date>2010-12-26T19:25:49Z</dc:date>
    </item>
    <item>
      <title>Re: AAA Authorization</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-authorization/m-p/1532726#M414177</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you have ACS then It's not recommended to use router local user database. The same way, if you're using "Command Sets" then you shouldn't use "IOS privileges" at all.&lt;SPAN style="background-color: #f8fafd;"&gt;&amp;nbsp; "IOS privileges" was never a good tool to do authorization, and it's an ancient tool now.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;So my recommendation is to delete "privilege" commands from your switch and to leave your "Shell profile" to the defaults. Only use "command sets".&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;I only use "shell profiles " when using Cisco ACE modules, Cisco Nexus, Cisco CRS or Juniper routers, because they have a different TACACS+ approach than traditional Cisco routers and switches.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;Also please upgrade to ACS 5.1 or ACS 5.2, they're far mo&lt;/SPAN&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;re mature product than ACS 5.0.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;By the way, you also mentioned the following&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;#################&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;2)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; I have created a shell profile with privi level 15 but user are prompt to type enable secret password, when they are in privi level 15 then why they&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; are prompted again for enable secret????&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;#################&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;I just did a test using ACS 5.1 and Catalyst 6500 and shell profiles with privilege level 15 worked OK without being prompted for enable secret.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Dec 2010 00:12:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-authorization/m-p/1532726#M414177</guid>
      <dc:creator>Eduardo Aliaga</dc:creator>
      <dc:date>2010-12-28T00:12:25Z</dc:date>
    </item>
    <item>
      <title>Re: AAA Authorization</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-authorization/m-p/1532727#M414178</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;Hello,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt; background-color: #f8fafd; "&gt;So my recommendation is to delete "privilege" commands from your switch and to leave your "Shell profile" to the defaults. Only use "command sets".&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt; background-color: #f8fafd; "&gt;There are no privilege commands on switch only on ACS Once i remove the privilege level&amp;nbsp; the user is not able to move in privilege mode (#) he is exec mode (&amp;gt;) &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt; background-color: #f8fafd; "&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;Also please upgrade to ACS 5.1 or ACS 5.2, they're far mo&lt;/SPAN&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;re mature product than ACS 5.0&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt; background-color: #f8fafd; "&gt;As i have been to install and upgrade guide,it says in Step&amp;nbsp; No 2: &lt;SPAN style="font-family: JBBNI M+ Times,Times; "&gt;Install ACS 5.1 using the recovery DVD. where i will find this recovery DVD.??????&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt; background-color: #f8fafd; font-family: JBBNI M+ Times,Times; "&gt;I just did a test using ACS 5.1 and Catalyst 6500 and shell profiles with privilege level 15 worked OK without being prompted for enable secret&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt; background-color: #f8fafd; font-family: JBBNI M+ Times,Times; "&gt;Can u send me the steps,what u did,May i m missing something&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Jan 2011 23:06:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-authorization/m-p/1532727#M414178</guid>
      <dc:creator>thomasandy32</dc:creator>
      <dc:date>2011-01-06T23:06:57Z</dc:date>
    </item>
  </channel>
</rss>

