<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ACS 3.2 Command Authorization Wildcards?? in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-3-2-command-authorization-wildcards/m-p/220191#M434634</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As of now, wildcards can be used with IP addresses only I guess.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 06 Apr 2004 15:46:37 GMT</pubDate>
    <dc:creator>didyap</dc:creator>
    <dc:date>2004-04-06T15:46:37Z</dc:date>
    <item>
      <title>ACS 3.2 Command Authorization Wildcards??</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-3-2-command-authorization-wildcards/m-p/220190#M434631</link>
      <description>&lt;P&gt;Does anyone know if it is possible to use wildcards with a Shell Command Authorization Set?  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am setting up the following types of users:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cisco Admins (Unrestricted)&lt;/P&gt;&lt;P&gt;Cisco Operators (restricted, but capable of a lot).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What we want to allow the operators to have enough access to fix a problem, (with us walking them through on the phone), but not allow them the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Show run, show start...  So they cannot get the passwords.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;copy ANYTHING into startup-config.  We do not want them to be able to write any configs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There are so many options to copy from:  ftp, tftp, run, flash, etc...  I wanted to use a wildcard for &lt;/P&gt;&lt;P&gt;copy; deny * startup-config&lt;/P&gt;&lt;P&gt;copy; deny running-config *&lt;/P&gt;&lt;P&gt;copy; deny startup-config *&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;this will prevent them from overwriting the startup-config, and will prevent them from copying the configs anywhere, where they can get the encrypted passwords &amp;amp; run a utility to crack the passwords.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As of now, I am putting in all possible options into the authorization set, but I would LOVE to use a wildcard.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any thoughts?&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 14:43:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-3-2-command-authorization-wildcards/m-p/220190#M434631</guid>
      <dc:creator>aaronw</dc:creator>
      <dc:date>2019-03-10T14:43:54Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 3.2 Command Authorization Wildcards??</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-3-2-command-authorization-wildcards/m-p/220191#M434634</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As of now, wildcards can be used with IP addresses only I guess.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Apr 2004 15:46:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-3-2-command-authorization-wildcards/m-p/220191#M434634</guid>
      <dc:creator>didyap</dc:creator>
      <dc:date>2004-04-06T15:46:37Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 3.2 Command Authorization Wildcards??</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-3-2-command-authorization-wildcards/m-p/220192#M434635</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I ended up with the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Copy	&lt;/P&gt;&lt;P&gt;	deny running-config&lt;/P&gt;&lt;P&gt;	deny startup-config&lt;/P&gt;&lt;P&gt;	deny tftp startup-config&lt;/P&gt;&lt;P&gt;	deny /erase&lt;/P&gt;&lt;P&gt;	deny flash startup-config&lt;/P&gt;&lt;P&gt;	deny ftp startup-config&lt;/P&gt;&lt;P&gt;	deny null startup-config&lt;/P&gt;&lt;P&gt;	deny pram startup-config&lt;/P&gt;&lt;P&gt;	deny rcp startup-config&lt;/P&gt;&lt;P&gt;	deny system startup-config&lt;/P&gt;&lt;P&gt;	deny xmodem startup-config&lt;/P&gt;&lt;P&gt;	deny ymodem startup-config&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Apr 2004 16:33:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-3-2-command-authorization-wildcards/m-p/220192#M434635</guid>
      <dc:creator>aaronw</dc:creator>
      <dc:date>2004-04-06T16:33:34Z</dc:date>
    </item>
  </channel>
</rss>

