<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ACS command Authorization on PIX Console in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-command-authorization-on-pix-console/m-p/986988#M419544</link>
    <description>&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have configured the pix firewall for ACS authentication and command authorization, everything is working fine&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa-server TACACS+ protocol tacacs+ &lt;/P&gt;&lt;P&gt;aaa-server TACACS+ (inside) host 172.28.x.x x.x.x &lt;/P&gt;&lt;P&gt;aaa-server TACACS+ (inside) host 172.28.x.   xx &lt;/P&gt;&lt;P&gt;aaa authentication ssh console TACACS+ LOCAL &lt;/P&gt;&lt;P&gt;aaa authentication serial console LOCAL &lt;/P&gt;&lt;P&gt;aaa authentication enable console TACACS+ LOCAL &lt;/P&gt;&lt;P&gt;aaa authorization command TACACS+ &lt;/P&gt;&lt;P&gt;aaa accounting command privilege 15 TACACS+ &lt;/P&gt;&lt;P&gt;aaa accounting enable console TACACS+ &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but porblem is that i dont wana have ACS authentication while connecting with console. In case of emergency when&lt;/P&gt;&lt;P&gt;ACS down, i wana to get console and access the device by using local username and password&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but now after this configuration when i try to access the firewall via console, i m getting error of &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;command authorization fail.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I dont wana have any command authorization while connected with console, Please tell me how to resolve this issue&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have made the command authorization set in ACS and it is working fine for me, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 22:51:27 GMT</pubDate>
    <dc:creator>wasiimcisco</dc:creator>
    <dc:date>2019-03-10T22:51:27Z</dc:date>
    <item>
      <title>ACS command Authorization on PIX Console</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-command-authorization-on-pix-console/m-p/986988#M419544</link>
      <description>&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have configured the pix firewall for ACS authentication and command authorization, everything is working fine&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa-server TACACS+ protocol tacacs+ &lt;/P&gt;&lt;P&gt;aaa-server TACACS+ (inside) host 172.28.x.x x.x.x &lt;/P&gt;&lt;P&gt;aaa-server TACACS+ (inside) host 172.28.x.   xx &lt;/P&gt;&lt;P&gt;aaa authentication ssh console TACACS+ LOCAL &lt;/P&gt;&lt;P&gt;aaa authentication serial console LOCAL &lt;/P&gt;&lt;P&gt;aaa authentication enable console TACACS+ LOCAL &lt;/P&gt;&lt;P&gt;aaa authorization command TACACS+ &lt;/P&gt;&lt;P&gt;aaa accounting command privilege 15 TACACS+ &lt;/P&gt;&lt;P&gt;aaa accounting enable console TACACS+ &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but porblem is that i dont wana have ACS authentication while connecting with console. In case of emergency when&lt;/P&gt;&lt;P&gt;ACS down, i wana to get console and access the device by using local username and password&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but now after this configuration when i try to access the firewall via console, i m getting error of &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;command authorization fail.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I dont wana have any command authorization while connected with console, Please tell me how to resolve this issue&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have made the command authorization set in ACS and it is working fine for me, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 22:51:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-command-authorization-on-pix-console/m-p/986988#M419544</guid>
      <dc:creator>wasiimcisco</dc:creator>
      <dc:date>2019-03-10T22:51:27Z</dc:date>
    </item>
    <item>
      <title>Re: ACS command Authorization on PIX Console</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-command-authorization-on-pix-console/m-p/986989#M419547</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Wasim,&lt;/P&gt;&lt;P&gt;Seems to be a bug, the issue we are facing with ASA v 7.2, where fall back to local authentication gives 'command authorization' failed with few commands has been files as a BUG. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the bug tool link: CSCsj56051&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/cgi-bin/Support/Bugtool/home.pl" target="_blank"&gt;http://www.cisco.com/cgi-bin/Support/Bugtool/home.pl&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;***************************************************************&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;AAA authorization commands LOCAL fallback broken&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;Alternate Headline: AAA authorization commands LOCAL fallback broken&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Symptom: aaa authorization fallback to LOCAL fails, blocking some commands to be executed and displaying "Command authorization failed" error message even though local authorization should be granted.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Conditions:&lt;/P&gt;&lt;P&gt;TACACS+ server communication is lost; LOCAL is configured next in the list.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Workaround: none.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Further Problem Description:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;7.2.2 does not show this behavior&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;**************************************************************&lt;/P&gt;&lt;P&gt;The issue is resolved in 007.002(002.034), 008.000(002.011),&lt;/P&gt;&lt;P&gt;008.002(000.045)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;~JG&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 May 2008 13:46:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-command-authorization-on-pix-console/m-p/986989#M419547</guid>
      <dc:creator>Jagdeep Gambhir</dc:creator>
      <dc:date>2008-05-20T13:46:37Z</dc:date>
    </item>
    <item>
      <title>Re: ACS command Authorization on PIX Console</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-command-authorization-on-pix-console/m-p/986990#M419549</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;kindly once again check my modified configuration, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I wanted to use this option in case, ACS goes down and i can console my firewall and but it is not working fine me. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aa-server TACACS+ protocol tacacs+&lt;/P&gt;&lt;P&gt;aaa-server TACACS+ (edn) host 172.28.31.132&lt;/P&gt;&lt;P&gt;aaa-server TACACS+ (edn) host 172.28.31.133&lt;/P&gt;&lt;P&gt;aaa authentication ssh console TACACS+ LOCAL&lt;/P&gt;&lt;P&gt;aaa authentication enable console TACACS+ LOCAL&lt;/P&gt;&lt;P&gt;aaa authentication serial console LOCAL &lt;/P&gt;&lt;P&gt;aaa authentication http console LOCAL &lt;/P&gt;&lt;P&gt;aaa authorization command TACACS+ LOCAL&lt;/P&gt;&lt;P&gt;aaa accounting command privilege 15 TACACS+&lt;/P&gt;&lt;P&gt;aaa accounting enable console TACACS+&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but i m not able to login i m getting following eror&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Command authorization failed&lt;/P&gt;&lt;P&gt;TDC-INT-525-01&amp;gt; exit&lt;/P&gt;&lt;P&gt;Command authorization failed&lt;/P&gt;&lt;P&gt;TDC-INT-525-01&amp;gt; exit&lt;/P&gt;&lt;P&gt;Command authorization failed&lt;/P&gt;&lt;P&gt;TDC-INT-525-01&amp;gt; enable&lt;/P&gt;&lt;P&gt;Command authorization failed&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i also defined the local command authorization set like this&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;privilege cmd level 15 mode exec command exit&lt;/P&gt;&lt;P&gt;privilege show level 5 mode exec command running-config&lt;/P&gt;&lt;P&gt;privilege show level 15 mode exec command version&lt;/P&gt;&lt;P&gt;privilege show level 0 mode exec command access-list&lt;/P&gt;&lt;P&gt;privilege show level 0 mode configure command access-list&lt;/P&gt;&lt;P&gt;privilege cmd level 15 mode configure command exit&lt;/P&gt;&lt;P&gt;privilege cmd level 15 mode configure command no&lt;/P&gt;&lt;P&gt;privilege cmd level 0 mode configure command access-list&lt;/P&gt;&lt;P&gt;privilege cmd level 15 mode interface command exit&lt;/P&gt;&lt;P&gt;privilege cmd level 15 mode subinterface command exit&lt;/P&gt;&lt;P&gt;privilege cmd level 15 mode dynupd-method command exit&lt;/P&gt;&lt;P&gt;privilege cmd level 15 mode trange command exit&lt;/P&gt;&lt;P&gt;privilege cmd level 15 mode route-map command exit&lt;/P&gt;&lt;P&gt;privilege cmd level 15 mode router command exit&lt;/P&gt;&lt;P&gt;privilege cmd level 15 mode ldap command exit&lt;/P&gt;&lt;P&gt;privilege cmd level 15 mode aaa-server-host command exit&lt;/P&gt;&lt;P&gt;privilege cmd level 15 mode aaa-server-group command exit&lt;/P&gt;&lt;P&gt;privilege cmd level 15 mode context command exit&lt;/P&gt;&lt;P&gt;privilege cmd level 15 mode group-policy command exit&lt;/P&gt;&lt;P&gt;privilege cmd level 15 mode username command exit&lt;/P&gt;&lt;P&gt;privilege cmd level 15 mode tunnel-group-general command exit&lt;/P&gt;&lt;P&gt;privilege cmd level 15 mode tunnel-group-ipsec command exit&lt;/P&gt;&lt;P&gt;privilege cmd level 15 mode tunnel-group-ppp command exit&lt;/P&gt;&lt;P&gt;privilege cmd level 15 mode mpf-class-map command exit&lt;/P&gt;&lt;P&gt;privilege cmd level 15 mode mpf-policy-map command exit&lt;/P&gt;&lt;P&gt;privilege cmd level 15 mode mpf-policy-map-class command exit&lt;/P&gt;&lt;P&gt;privilege cmd level 15 mode mpf-policy-map-class command exit&lt;/P&gt;&lt;P&gt;privilege cmd level 15 mode mpf-policy-map-param command exit&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please tell me how to solve this problem &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 May 2008 19:54:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-command-authorization-on-pix-console/m-p/986990#M419549</guid>
      <dc:creator>wasiimcisco</dc:creator>
      <dc:date>2008-05-20T19:54:21Z</dc:date>
    </item>
    <item>
      <title>Re: ACS command Authorization on PIX Console</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-command-authorization-on-pix-console/m-p/986991#M419552</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is the issue happening only with console ? If ssh works fine then did the check the bug I mentioned in my last post ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 May 2008 20:05:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-command-authorization-on-pix-console/m-p/986991#M419552</guid>
      <dc:creator>Jagdeep Gambhir</dc:creator>
      <dc:date>2008-05-20T20:05:51Z</dc:date>
    </item>
  </channel>
</rss>

