<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Help needed on command authorization set in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/help-needed-on-command-authorization-set/m-p/464229#M428844</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You could refer to  : &lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/sw/iosswrel/ps1835/products_configuration_guide_chapter09186a00800ca7a7.html" target="_blank"&gt;http://www.cisco.com/en/US/products/sw/iosswrel/ps1835/products_configuration_guide_chapter09186a00800ca7a7.html&lt;/A&gt; for the authorization commands.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 20 Jul 2005 15:05:31 GMT</pubDate>
    <dc:creator>pradeepde</dc:creator>
    <dc:date>2005-07-20T15:05:31Z</dc:date>
    <item>
      <title>Help needed on command authorization set</title>
      <link>https://community.cisco.com/t5/network-access-control/help-needed-on-command-authorization-set/m-p/464228#M428842</link>
      <description>&lt;P&gt;Dear Sir, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;on my ACS v 3.2 windows server, I have configured group A and created one user in it as B, I want this user B to have helpdesk profile i.e. he should only access show commands but it is strange to discover when B type enable he moves in to enable mode (it ask for enable password), I want to restrict B from using enable command, pls.find below mentioned my router client aaa config:- &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa new-model &lt;/P&gt;&lt;P&gt;aaa authentication login default group tacacs+ local &lt;/P&gt;&lt;P&gt;aaa authentication login enable group tacacs+ enable &lt;/P&gt;&lt;P&gt;aaa authentication ppp default local group radius &lt;/P&gt;&lt;P&gt;aaa authorization exec default group tacacs+ local &lt;/P&gt;&lt;P&gt;aaa accounting exec default start-stop group tacacs+ &lt;/P&gt;&lt;P&gt;aaa accounting commands 1 default start-stop group tacacs+ &lt;/P&gt;&lt;P&gt;aaa accounting commands 7 default start-stop group tacacs+ &lt;/P&gt;&lt;P&gt;aaa accounting commands 15 default start-stop group tacacs+ &lt;/P&gt;&lt;P&gt;aaa accounting connection default start-stop group tacacs+ &lt;/P&gt;&lt;P&gt;aaa session-id common &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kindly suggest client and server config to accomplish the needful task.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 21:13:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/help-needed-on-command-authorization-set/m-p/464228#M428842</guid>
      <dc:creator>manishn</dc:creator>
      <dc:date>2019-03-10T21:13:37Z</dc:date>
    </item>
    <item>
      <title>Re: Help needed on command authorization set</title>
      <link>https://community.cisco.com/t5/network-access-control/help-needed-on-command-authorization-set/m-p/464229#M428844</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You could refer to  : &lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/sw/iosswrel/ps1835/products_configuration_guide_chapter09186a00800ca7a7.html" target="_blank"&gt;http://www.cisco.com/en/US/products/sw/iosswrel/ps1835/products_configuration_guide_chapter09186a00800ca7a7.html&lt;/A&gt; for the authorization commands.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Jul 2005 15:05:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/help-needed-on-command-authorization-set/m-p/464229#M428844</guid>
      <dc:creator>pradeepde</dc:creator>
      <dc:date>2005-07-20T15:05:31Z</dc:date>
    </item>
    <item>
      <title>Re: Help needed on command authorization set</title>
      <link>https://community.cisco.com/t5/network-access-control/help-needed-on-command-authorization-set/m-p/464230#M428845</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thats because this is not done at from router level.  Such as above your configuration above says to use a tacacs server and if it fails then authenticate and authorize local.  So as long as the router can access the tacacs server it will pass it off to the tacacs server for it make that decision and from there pass it back to the router.  In other words make your access authorization settings on the ACS server not the router.  The router is set up fine as long as you have the tacacs-server command in there specifing what server to use with a key.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Jul 2005 20:46:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/help-needed-on-command-authorization-set/m-p/464230#M428845</guid>
      <dc:creator>vasthorvak</dc:creator>
      <dc:date>2005-07-20T20:46:25Z</dc:date>
    </item>
  </channel>
</rss>

