<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ACS-Shell commmand author. problem in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-shell-commmand-author-problem/m-p/396324#M432848</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;"aaa authorization commands ....." doesn't include authorization for commands done in config mode.  To enable that add the command:&lt;/P&gt;&lt;P&gt;&lt;B&gt;&lt;/B&gt;&lt;/P&gt;&lt;P&gt;aaa authorization config-commands&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then add the "set port enable" (or whatever) command into the TACACS authorization profile on the ACS server just like any other command.  Note that you'll have to allow them to get into config mode in the first place though.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 19 Jan 2005 03:04:16 GMT</pubDate>
    <dc:creator>gfullage</dc:creator>
    <dc:date>2005-01-19T03:04:16Z</dc:date>
    <item>
      <title>ACS-Shell commmand author. problem</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-shell-commmand-author-problem/m-p/396323#M432847</link>
      <description>&lt;P&gt;I have setup shell commands for the helpdesk to do basic viewing of the router.  Is there a way to limit what they can do in config mode and how do i configure that on the ACS. For instance if I want the helpdesk to enable a port on a 3560 switch. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is in the test router:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;aaa authentication login default group tacacs+ enable&lt;/P&gt;&lt;P&gt;aaa authorization exec default group tacacs+ none&lt;/P&gt;&lt;P&gt;aaa authorization commands 1 default group tacacs+ none&lt;/P&gt;&lt;P&gt;aaa authorization commands 15 default group tacacs+ none&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 20:58:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-shell-commmand-author-problem/m-p/396323#M432847</guid>
      <dc:creator>d.sasso</dc:creator>
      <dc:date>2019-03-10T20:58:31Z</dc:date>
    </item>
    <item>
      <title>Re: ACS-Shell commmand author. problem</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-shell-commmand-author-problem/m-p/396324#M432848</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;"aaa authorization commands ....." doesn't include authorization for commands done in config mode.  To enable that add the command:&lt;/P&gt;&lt;P&gt;&lt;B&gt;&lt;/B&gt;&lt;/P&gt;&lt;P&gt;aaa authorization config-commands&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then add the "set port enable" (or whatever) command into the TACACS authorization profile on the ACS server just like any other command.  Note that you'll have to allow them to get into config mode in the first place though.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Jan 2005 03:04:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-shell-commmand-author-problem/m-p/396324#M432848</guid>
      <dc:creator>gfullage</dc:creator>
      <dc:date>2005-01-19T03:04:16Z</dc:date>
    </item>
  </channel>
</rss>

