<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA Local Command Authorization problem? in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/asa-local-command-authorization-problem/m-p/1306535#M418975</link>
    <description>&lt;P&gt;Hi,I have configured command authorization in my ASA with tacacs and also i have configured shell command authorization for different users in ACS4.2. when im using ACS for command authorization there is no problem ,but when i disconnect my connection to ACS from ASA, i stock in configuration even i have configured aaa authorization command TACACS LOCAL but when connection to ACS is lost i get very limited access to my asa(LOCAL is configured end of the above command) also i have configured user with Priv 15 so when i log in to my asa with this local user i have limited access even its Priv level is 15,so do i have to configure any thing else to give me full access in level 15 when there is no access to ACS and aaa authorization command &amp;lt;server group&amp;gt; LOCAL is configured?? thanks&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 23:43:40 GMT</pubDate>
    <dc:creator>blackhat2020</dc:creator>
    <dc:date>2019-03-10T23:43:40Z</dc:date>
    <item>
      <title>ASA Local Command Authorization problem?</title>
      <link>https://community.cisco.com/t5/network-access-control/asa-local-command-authorization-problem/m-p/1306535#M418975</link>
      <description>&lt;P&gt;Hi,I have configured command authorization in my ASA with tacacs and also i have configured shell command authorization for different users in ACS4.2. when im using ACS for command authorization there is no problem ,but when i disconnect my connection to ACS from ASA, i stock in configuration even i have configured aaa authorization command TACACS LOCAL but when connection to ACS is lost i get very limited access to my asa(LOCAL is configured end of the above command) also i have configured user with Priv 15 so when i log in to my asa with this local user i have limited access even its Priv level is 15,so do i have to configure any thing else to give me full access in level 15 when there is no access to ACS and aaa authorization command &amp;lt;server group&amp;gt; LOCAL is configured?? thanks&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 23:43:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/asa-local-command-authorization-problem/m-p/1306535#M418975</guid>
      <dc:creator>blackhat2020</dc:creator>
      <dc:date>2019-03-10T23:43:40Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Local Command Authorization problem?</title>
      <link>https://community.cisco.com/t5/network-access-control/asa-local-command-authorization-problem/m-p/1306536#M418976</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Please check this known bug,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CSCsj56051 Bug Details&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;AAA authorization commands LOCAL fallback broken&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Symptom:&lt;/P&gt;&lt;P&gt;aaa authorization fallback to LOCAL fails, blocking some commands to be executed and displaying "Command authorization failed" error message even though local authorization should be granted.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Conditions:&lt;/P&gt;&lt;P&gt;TACACS+ server communication is lost, LOCAL is configured next in the list.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Workaround:&lt;/P&gt;&lt;P&gt;none.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Further Problem Description:&lt;/P&gt;&lt;P&gt;7.2.2 does not show this behavior.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;8.0(3) does not show this behavior.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;~JG&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do rate helpful posts &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Oct 2009 12:42:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/asa-local-command-authorization-problem/m-p/1306536#M418976</guid>
      <dc:creator>Jagdeep Gambhir</dc:creator>
      <dc:date>2009-10-09T12:42:48Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Local Command Authorization problem?</title>
      <link>https://community.cisco.com/t5/network-access-control/asa-local-command-authorization-problem/m-p/1306537#M418977</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Further to JG update; I also came across this defect and i did a lab recreate for LOCAL command authorization on 8.0.3 and confirmed the issue has fixed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now with your current config and code 8.0.x you can access or run any command with privilege 15 user. However for read only access with LOCAL authorization you need to update your config with lots of command.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;JK&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Plz rate helpful posts-&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Oct 2009 13:01:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/asa-local-command-authorization-problem/m-p/1306537#M418977</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2009-10-09T13:01:11Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Local Command Authorization problem?</title>
      <link>https://community.cisco.com/t5/network-access-control/asa-local-command-authorization-problem/m-p/1306538#M418978</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you guys very much,but what about FWSM 3.2 image?becuse now I'm going to config it on 3.2 os!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Oct 2009 13:20:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/asa-local-command-authorization-problem/m-p/1306538#M418978</guid>
      <dc:creator>blackhat2020</dc:creator>
      <dc:date>2009-10-09T13:20:41Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Local Command Authorization problem?</title>
      <link>https://community.cisco.com/t5/network-access-control/asa-local-command-authorization-problem/m-p/1306539#M418979</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; I had the same problem and found out that the problem exists on 8.0.2&lt;/P&gt;&lt;P&gt;I had to downgrade to 7.2.1, remove aaa authorization command and reboot to 8.0.2 again to have normal rights.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Nov 2010 08:26:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/asa-local-command-authorization-problem/m-p/1306539#M418979</guid>
      <dc:creator>Feidopiastis.n</dc:creator>
      <dc:date>2010-11-11T08:26:47Z</dc:date>
    </item>
  </channel>
</rss>

