<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic aaa authorization?? in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/aaa-authorization/m-p/135436#M438221</link>
    <description>&lt;P&gt;I'm having trouble figuring out how to limit the commands a user can execute on a NAS (3660 router) using the local database.    I have aaa authentication set up.  I use the command username xxxx privilege 1 for one of my user, but it doesn't seem to restrict them from anything.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help would be greatly appreciated.&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 14:14:24 GMT</pubDate>
    <dc:creator>b-price</dc:creator>
    <dc:date>2019-03-10T14:14:24Z</dc:date>
    <item>
      <title>aaa authorization??</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-authorization/m-p/135436#M438221</link>
      <description>&lt;P&gt;I'm having trouble figuring out how to limit the commands a user can execute on a NAS (3660 router) using the local database.    I have aaa authentication set up.  I use the command username xxxx privilege 1 for one of my user, but it doesn't seem to restrict them from anything.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help would be greatly appreciated.&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 14:14:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-authorization/m-p/135436#M438221</guid>
      <dc:creator>b-price</dc:creator>
      <dc:date>2019-03-10T14:14:24Z</dc:date>
    </item>
    <item>
      <title>Re: aaa authorization??</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-authorization/m-p/135437#M438222</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You need to define the commands that you want to assign under different privilege levels. Here is the link for sample config on How to Assign Privilege Levels with TACACS+ and RADIUS&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/warp/public/480/PRIV.html" target="_blank"&gt;http://www.cisco.com/warp/public/480/PRIV.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;For local config of privilege levels, pl. visit config example at following location&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/warp/public/471/84.html" target="_blank"&gt;http://www.cisco.com/warp/public/471/84.html&lt;/A&gt;\&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 04 Apr 2003 23:43:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-authorization/m-p/135437#M438222</guid>
      <dc:creator>tepatel</dc:creator>
      <dc:date>2003-04-04T23:43:44Z</dc:date>
    </item>
    <item>
      <title>Re: aaa authorization??</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-authorization/m-p/135438#M438223</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm not using a TACACS+ or RADIUS server yet, (budget restrictions).  I'm trying to set up authorization on the local database.  This is what I did:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;aaa authentication login default local enable&lt;/P&gt;&lt;P&gt;aaa authorization exec default local&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;username bradley privilege 5 password 7 04035D505F&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;privilege exec level 5 show run&lt;/P&gt;&lt;P&gt;privilege exec level 5 show interfaces&lt;/P&gt;&lt;P&gt;privilege exec level 5 show ip interface brief&lt;/P&gt;&lt;P&gt;privilege exec level 5 ping&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;to test this I have a sub interface.  I log on as this person, get into Int confiuration mode and successfully shut the interface down.  I only want him to be able to execute the command listed above.  Why doesn't it work?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for you input.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 05 Apr 2003 15:10:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-authorization/m-p/135438#M438223</guid>
      <dc:creator>b-price</dc:creator>
      <dc:date>2003-04-05T15:10:25Z</dc:date>
    </item>
    <item>
      <title>Re: aaa authorization??</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-authorization/m-p/135439#M438225</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You may have entered in "enable" mode to use "conf t" and change the interface config. Enable mode is privilege 15 command which let you do everything with the router. Also if the user is given privilege level 5 access, that means users got level 0 to level 5 access. So don't get in to enable mode and check again.&lt;/P&gt;&lt;P&gt;with only priv level 5 config like above, user bradley will only be able to issue show commands and ping..(if he don't get in enable mode)..Pl. visit following url for more detailed explanation&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/univercd/cc/td/doc/product/software/ios121/121cgcr/secur_c/scprt5/scdpass.htm" target="_blank"&gt;http://www.cisco.com/univercd/cc/td/doc/product/software/ios121/121cgcr/secur_c/scprt5/scdpass.htm&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 06 Apr 2003 22:32:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-authorization/m-p/135439#M438225</guid>
      <dc:creator>tepatel</dc:creator>
      <dc:date>2003-04-06T22:32:17Z</dc:date>
    </item>
  </channel>
</rss>

