<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Tacacs+ Setup on OpenBSD in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/tacacs-setup-on-openbsd/m-p/441872#M427902</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you want to authorize admin group directly to privilege mode, you can provide the following none authentication configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authentication enable default none.This will stop forcing authentication into the privilege mode.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 19 Jan 2006 17:30:46 GMT</pubDate>
    <dc:creator>pradeepde</dc:creator>
    <dc:date>2006-01-19T17:30:46Z</dc:date>
    <item>
      <title>Tacacs+ Setup on OpenBSD</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-setup-on-openbsd/m-p/441871#M427901</link>
      <description>&lt;P&gt;Having some dificulties with creating the configuration file for the Tacacs4.0.4.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have my test switch authenticating and authorizing, but am not able to figure out how to get the admins group to login directly to the privileged exec mode. Also when I configure &lt;/P&gt;&lt;P&gt;aaa authorization enable group tacacs+ enable &lt;/P&gt;&lt;P&gt;I am not able to authenticate, and have not been able to figure out how to do it for authorization to work. If I create a user = $enable$ with a password, all users get privilege level 15, and I dont want PL 15 at the vty login either. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is pretty much the only thing I am stumped on, I have authorization and authentication working with the groups and individual users and also seperate command groups, my next step is accounting once I figure out how to create the darned log file in OpenBSD. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is my admin group&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;group = admin {&lt;/P&gt;&lt;P&gt;        default service = permit&lt;/P&gt;&lt;P&gt;        login = cleartext "test"&lt;/P&gt;&lt;P&gt;}&lt;/P&gt;&lt;P&gt; I want to put the exec and shell stuff under this group, and not under individual users. &lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 21:26:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-setup-on-openbsd/m-p/441871#M427901</guid>
      <dc:creator>tahequivoice</dc:creator>
      <dc:date>2019-03-10T21:26:17Z</dc:date>
    </item>
    <item>
      <title>Re: Tacacs+ Setup on OpenBSD</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-setup-on-openbsd/m-p/441872#M427902</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you want to authorize admin group directly to privilege mode, you can provide the following none authentication configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authentication enable default none.This will stop forcing authentication into the privilege mode.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Jan 2006 17:30:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-setup-on-openbsd/m-p/441872#M427902</guid>
      <dc:creator>pradeepde</dc:creator>
      <dc:date>2006-01-19T17:30:46Z</dc:date>
    </item>
  </channel>
</rss>

