<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Tacacs + AAA in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/tacacs-aaa/m-p/386365#M433337</link>
    <description>&lt;P&gt;Hi.. My name is Fabio, I work on brazil like network manager. I placed Tac_plus to work on Linux, because it is needed to restrict some users accesses to routers. In the first case where users are able to give show and config commands referring "RTR"  that works well for show commands but not when user this inside config mode.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; See log below. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Wed Oct 13 22:43:38 2004 10.121.9.66 test tty2 192.168.32.8 stop task_id=210 timezone=GMT-3 service=shell start_time=1097729277 priv-lvl=15 cmd=configure terminal &lt;/P&gt;&lt;P&gt;Wed Oct 13 22:43:48 2004 10.121.9.66 test tty2 192.168.32.8 stop task_id=211 timezone=GMT-3 service=shell start_time=1097729287 priv-lvl=15 cmd=line console 0 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;see the cofig &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;group = users { &lt;/P&gt;&lt;P&gt;default service = deny &lt;/P&gt;&lt;P&gt;service = exec { &lt;/P&gt;&lt;P&gt;priv-lvl = 15 &lt;/P&gt;&lt;P&gt;} &lt;/P&gt;&lt;P&gt;} &lt;/P&gt;&lt;P&gt;############################## &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;#All services are alowed.. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;user = DEFAULT { &lt;/P&gt;&lt;P&gt;service = ppp protocol = ip {} &lt;/P&gt;&lt;P&gt;} &lt;/P&gt;&lt;P&gt;user = test { &lt;/P&gt;&lt;P&gt;login = cleartext xxxx &lt;/P&gt;&lt;P&gt;member = users &lt;/P&gt;&lt;P&gt;service = exec { &lt;/P&gt;&lt;P&gt;priv-lvl= 15 } &lt;/P&gt;&lt;P&gt;cmd = enable { &lt;/P&gt;&lt;P&gt;permit .* } &lt;/P&gt;&lt;P&gt;cmd = configure { &lt;/P&gt;&lt;P&gt;permit "terminal" } &lt;/P&gt;&lt;P&gt;cmd = rtr { &lt;/P&gt;&lt;P&gt;permit .* } &lt;/P&gt;&lt;P&gt;cmd = show { &lt;/P&gt;&lt;P&gt;permit "rtr" &lt;/P&gt;&lt;P&gt;deny .* } &lt;/P&gt;&lt;P&gt;cmd = exit { &lt;/P&gt;&lt;P&gt;permit .* } &lt;/P&gt;&lt;P&gt;} &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My problem is, in config mode the user test have a full authorization command.&lt;/P&gt;&lt;P&gt;Thanks...&lt;/P&gt;&lt;P&gt;Fábio&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 20:51:51 GMT</pubDate>
    <dc:creator>fabioosantos</dc:creator>
    <dc:date>2019-03-10T20:51:51Z</dc:date>
    <item>
      <title>Tacacs + AAA</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-aaa/m-p/386365#M433337</link>
      <description>&lt;P&gt;Hi.. My name is Fabio, I work on brazil like network manager. I placed Tac_plus to work on Linux, because it is needed to restrict some users accesses to routers. In the first case where users are able to give show and config commands referring "RTR"  that works well for show commands but not when user this inside config mode.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; See log below. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Wed Oct 13 22:43:38 2004 10.121.9.66 test tty2 192.168.32.8 stop task_id=210 timezone=GMT-3 service=shell start_time=1097729277 priv-lvl=15 cmd=configure terminal &lt;/P&gt;&lt;P&gt;Wed Oct 13 22:43:48 2004 10.121.9.66 test tty2 192.168.32.8 stop task_id=211 timezone=GMT-3 service=shell start_time=1097729287 priv-lvl=15 cmd=line console 0 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;see the cofig &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;group = users { &lt;/P&gt;&lt;P&gt;default service = deny &lt;/P&gt;&lt;P&gt;service = exec { &lt;/P&gt;&lt;P&gt;priv-lvl = 15 &lt;/P&gt;&lt;P&gt;} &lt;/P&gt;&lt;P&gt;} &lt;/P&gt;&lt;P&gt;############################## &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;#All services are alowed.. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;user = DEFAULT { &lt;/P&gt;&lt;P&gt;service = ppp protocol = ip {} &lt;/P&gt;&lt;P&gt;} &lt;/P&gt;&lt;P&gt;user = test { &lt;/P&gt;&lt;P&gt;login = cleartext xxxx &lt;/P&gt;&lt;P&gt;member = users &lt;/P&gt;&lt;P&gt;service = exec { &lt;/P&gt;&lt;P&gt;priv-lvl= 15 } &lt;/P&gt;&lt;P&gt;cmd = enable { &lt;/P&gt;&lt;P&gt;permit .* } &lt;/P&gt;&lt;P&gt;cmd = configure { &lt;/P&gt;&lt;P&gt;permit "terminal" } &lt;/P&gt;&lt;P&gt;cmd = rtr { &lt;/P&gt;&lt;P&gt;permit .* } &lt;/P&gt;&lt;P&gt;cmd = show { &lt;/P&gt;&lt;P&gt;permit "rtr" &lt;/P&gt;&lt;P&gt;deny .* } &lt;/P&gt;&lt;P&gt;cmd = exit { &lt;/P&gt;&lt;P&gt;permit .* } &lt;/P&gt;&lt;P&gt;} &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My problem is, in config mode the user test have a full authorization command.&lt;/P&gt;&lt;P&gt;Thanks...&lt;/P&gt;&lt;P&gt;Fábio&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 20:51:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-aaa/m-p/386365#M433337</guid>
      <dc:creator>fabioosantos</dc:creator>
      <dc:date>2019-03-10T20:51:51Z</dc:date>
    </item>
    <item>
      <title>Re: Tacacs + AAA</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-aaa/m-p/386366#M433338</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;How did you configure the routers?  The config should look something along the lines of this with some room for variation:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;aaa authentication login default group tacacs+ line&lt;/P&gt;&lt;P&gt;aaa authorization exec default group tacacs+ if-authenticated&lt;/P&gt;&lt;P&gt;aaa authorization commands 0 default group tacacs+ if-authenticated &lt;/P&gt;&lt;P&gt;aaa authorization commands 1 default group tacacs+ if-authenticated &lt;/P&gt;&lt;P&gt;aaa authorization commands 15 default group tacacs+ if-authenticated &lt;/P&gt;&lt;P&gt;aaa authorization config-commands&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Oct 2004 15:00:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-aaa/m-p/386366#M433338</guid>
      <dc:creator>scottosan</dc:creator>
      <dc:date>2004-10-21T15:00:54Z</dc:date>
    </item>
    <item>
      <title>Re: Tacacs + AAA</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-aaa/m-p/386367#M433339</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I didn't place the command "aaa authorization config-commands" in my configuration. I am going to place and to verify the result.&lt;/P&gt;&lt;P&gt;Thank´s&lt;/P&gt;&lt;P&gt;Fábio &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Oct 2004 15:59:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-aaa/m-p/386367#M433339</guid>
      <dc:creator>fabioosantos</dc:creator>
      <dc:date>2004-10-21T15:59:58Z</dc:date>
    </item>
    <item>
      <title>Re: Tacacs + AAA</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-aaa/m-p/386368#M433340</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scottosan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The command aaa authorization config-commands fixed my problem. Thank´s you very much.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Fábio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Oct 2004 17:11:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-aaa/m-p/386368#M433340</guid>
      <dc:creator>fabioosantos</dc:creator>
      <dc:date>2004-10-21T17:11:30Z</dc:date>
    </item>
    <item>
      <title>Re: Tacacs + AAA</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-aaa/m-p/386369#M433341</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;your welcome&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Oct 2004 17:28:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-aaa/m-p/386369#M433341</guid>
      <dc:creator>scottosan</dc:creator>
      <dc:date>2004-10-21T17:28:35Z</dc:date>
    </item>
  </channel>
</rss>

