<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: asa cmd authorization using acs in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/asa-cmd-authorization-using-acs/m-p/730370#M420897</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thankx a lot&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 02 May 2007 12:15:24 GMT</pubDate>
    <dc:creator>diptanshusingh</dc:creator>
    <dc:date>2007-05-02T12:15:24Z</dc:date>
    <item>
      <title>asa cmd authorization using acs</title>
      <link>https://community.cisco.com/t5/network-access-control/asa-cmd-authorization-using-acs/m-p/730366#M420888</link>
      <description>&lt;P&gt;Hi all, i was trying to authorize the asa with acs 3.2 on priv lvl 7 using tacacs+,but the users were geting priv-lvl 15 only..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa-server aaa_serv protocol tacacs+&lt;/P&gt;&lt;P&gt;aaa-server aaa_serv host 10.0.0.10&lt;/P&gt;&lt;P&gt; key cisco123&lt;/P&gt;&lt;P&gt;aaa authentication serial console tac_serv &lt;/P&gt;&lt;P&gt;aaa authentication telnet console tac_serv &lt;/P&gt;&lt;P&gt;aaa authentication enable console tac_serv &lt;/P&gt;&lt;P&gt;aaa authorization command tac_serv&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i had brought some commands also in priv 7 using privilege commandm but the problem is that when i try to login i am geting priv-lvl 15 only not 7.i had set in acs also in tacacs+ seting to assign priv lvl=7 only to the users .. but dnt knw why it is nt wrking ..&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 22:07:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/asa-cmd-authorization-using-acs/m-p/730366#M420888</guid>
      <dc:creator>diptanshusingh</dc:creator>
      <dc:date>2019-03-10T22:07:48Z</dc:date>
    </item>
    <item>
      <title>Re: asa cmd authorization using acs</title>
      <link>https://community.cisco.com/t5/network-access-control/asa-cmd-authorization-using-acs/m-p/730367#M420890</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ASA does not have any authorization exec command so Priv Level does not work with ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Max privilege(enable attrib. in ACS)works with ASA.&lt;/P&gt;&lt;P&gt;But if you implementing command authorization with ASA no need to configure max priv levels, let them all fall on priv level 15 and control access through command authorization.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2 main commands required for command authorization are &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authentication enable console tac_serv (this is because we do not have authorization exec in ASA so enable authentication is required for command auth to work)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authorization command tac_serv &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 01 May 2007 21:12:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/asa-cmd-authorization-using-acs/m-p/730367#M420890</guid>
      <dc:creator>rochopra</dc:creator>
      <dc:date>2007-05-01T21:12:25Z</dc:date>
    </item>
    <item>
      <title>Re: asa cmd authorization using acs</title>
      <link>https://community.cisco.com/t5/network-access-control/asa-cmd-authorization-using-acs/m-p/730368#M420892</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I agree with you but then what is the use of priviliege commands.. what will i do by bringing commands at some x priv level ..&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 May 2007 01:56:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/asa-cmd-authorization-using-acs/m-p/730368#M420892</guid>
      <dc:creator>diptanshusingh</dc:creator>
      <dc:date>2007-05-02T01:56:15Z</dc:date>
    </item>
    <item>
      <title>Re: asa cmd authorization using acs</title>
      <link>https://community.cisco.com/t5/network-access-control/asa-cmd-authorization-using-acs/m-p/730369#M420894</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;This link from TAC case collection will provide you info on ASA exec author,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; 	&lt;A class="jive-link-custom" href="http://www.ciscotaccc.com/security/showcase?case=K25224726" target="_blank"&gt;http://www.ciscotaccc.com/security/showcase?case=K25224726&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 May 2007 12:12:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/asa-cmd-authorization-using-acs/m-p/730369#M420894</guid>
      <dc:creator>Jagdeep Gambhir</dc:creator>
      <dc:date>2007-05-02T12:12:42Z</dc:date>
    </item>
    <item>
      <title>Re: asa cmd authorization using acs</title>
      <link>https://community.cisco.com/t5/network-access-control/asa-cmd-authorization-using-acs/m-p/730370#M420897</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thankx a lot&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 May 2007 12:15:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/asa-cmd-authorization-using-acs/m-p/730370#M420897</guid>
      <dc:creator>diptanshusingh</dc:creator>
      <dc:date>2007-05-02T12:15:24Z</dc:date>
    </item>
  </channel>
</rss>

