<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Enable mode with AAA &amp; ACS in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/enable-mode-with-aaa-acs/m-p/121197#M438509</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A while back you had asked for assistance regarding setting up TACAS to the router logins to skip over to enable mode.  I am currently trying to get this to work myself.  Would it be possbile for you to post your working configuration (minus passwords of course), on the Cisco site? Also, any comments regarding what you had to do on the CiscoSecure site would be useful as well.   &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you in advance.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 03 Feb 2003 19:19:46 GMT</pubDate>
    <dc:creator>ed.daly</dc:creator>
    <dc:date>2003-02-03T19:19:46Z</dc:date>
    <item>
      <title>Enable mode with AAA &amp; ACS</title>
      <link>https://community.cisco.com/t5/network-access-control/enable-mode-with-aaa-acs/m-p/121189#M438501</link>
      <description>&lt;P&gt; I'm trying to config a 12.0(5.1)XP 2900XL IOS switch to automatically go into enable mode once authenticated, without having to enter "enable." I'm running ACS3.1. Her is the AAA config:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;aaa authentication login default group tacacs+ local-case&lt;/P&gt;&lt;P&gt;aaa authentication login LOCAL local-case none&lt;/P&gt;&lt;P&gt;aaa authentication enable default group tacacs+ enable&lt;/P&gt;&lt;P&gt;aaa authorization exec default if-authenticated group tacacs+&lt;/P&gt;&lt;P&gt;aaa authorization commands 0 default local group tacacs+ if-authenticated&lt;/P&gt;&lt;P&gt;aaa authorization commands 15 default local group tacacs+ if-authenticated&lt;/P&gt;&lt;P&gt;aaa accounting update newinfo&lt;/P&gt;&lt;P&gt;aaa accounting exec default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting exec LOCAL start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting commands 0 default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting commands 0 LOCAL start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting commands 15 default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting commands 15 LOCAL start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting system default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 14:05:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/enable-mode-with-aaa-acs/m-p/121189#M438501</guid>
      <dc:creator>gamoore</dc:creator>
      <dc:date>2019-03-10T14:05:36Z</dc:date>
    </item>
    <item>
      <title>Re: Enable mode with AAA &amp; ACS</title>
      <link>https://community.cisco.com/t5/network-access-control/enable-mode-with-aaa-acs/m-p/121190#M438502</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you assign privilege level 15 to the user or group, EXEC authorization takes care of  this with the service=shell, set-priv-lvl=15 Attribute Value Pair.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You have aaa authorization exec configured correctly, assign priv 15 and see if it works. If you do have it assigned and it is not working, let us know, there are some other issues that may be causing this....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Jan 2003 13:50:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/enable-mode-with-aaa-acs/m-p/121190#M438502</guid>
      <dc:creator>4brown</dc:creator>
      <dc:date>2003-01-02T13:50:05Z</dc:date>
    </item>
    <item>
      <title>Re: Enable mode with AAA &amp; ACS</title>
      <link>https://community.cisco.com/t5/network-access-control/enable-mode-with-aaa-acs/m-p/121191#M438503</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; I set the Service=shell and Privlege Level=15 on both the users and group levels areas of the ACS, and neither did the trick.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Jan 2003 04:22:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/enable-mode-with-aaa-acs/m-p/121191#M438503</guid>
      <dc:creator>gamoore</dc:creator>
      <dc:date>2003-01-03T04:22:57Z</dc:date>
    </item>
    <item>
      <title>Re: Enable mode with AAA &amp; ACS</title>
      <link>https://community.cisco.com/t5/network-access-control/enable-mode-with-aaa-acs/m-p/121192#M438504</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I forgot to mention that I'm using ACS for WIndows.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Jan 2003 05:31:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/enable-mode-with-aaa-acs/m-p/121192#M438504</guid>
      <dc:creator>gamoore</dc:creator>
      <dc:date>2003-01-03T05:31:55Z</dc:date>
    </item>
    <item>
      <title>Re: Enable mode with AAA &amp; ACS</title>
      <link>https://community.cisco.com/t5/network-access-control/enable-mode-with-aaa-acs/m-p/121193#M438505</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Does it work on vty (telnet) sessions and not the console?  If so, try:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authorization console&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Jan 2003 10:59:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/enable-mode-with-aaa-acs/m-p/121193#M438505</guid>
      <dc:creator>4brown</dc:creator>
      <dc:date>2003-01-03T10:59:10Z</dc:date>
    </item>
    <item>
      <title>Re: Enable mode with AAA &amp; ACS</title>
      <link>https://community.cisco.com/t5/network-access-control/enable-mode-with-aaa-acs/m-p/121194#M438506</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It doesn't work on vty connections. Before I added the ACS server, it was working on vty connections using local username and password authentication with the following AAA config.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hostname s1-carson&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;aaa authentication password-prompt Password:&lt;/P&gt;&lt;P&gt;aaa authentication username-prompt Username:&lt;/P&gt;&lt;P&gt;aaa authentication login default local-case enable&lt;/P&gt;&lt;P&gt;aaa authorization exec default local none&lt;/P&gt;&lt;P&gt;aaa authorization commands 15 default local none&lt;/P&gt;&lt;P&gt;enable secret 5 ***** Text Removed *****&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;username ** removed ** psnet privilege 15 password 7 ** removed **&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;line con 0&lt;/P&gt;&lt;P&gt; transport input none&lt;/P&gt;&lt;P&gt; stopbits 1&lt;/P&gt;&lt;P&gt;line vty 0 4&lt;/P&gt;&lt;P&gt; length 25&lt;/P&gt;&lt;P&gt;line vty 5 15&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 04 Jan 2003 22:58:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/enable-mode-with-aaa-acs/m-p/121194#M438506</guid>
      <dc:creator>gamoore</dc:creator>
      <dc:date>2003-01-04T22:58:06Z</dc:date>
    </item>
    <item>
      <title>Re: Enable mode with AAA &amp; ACS</title>
      <link>https://community.cisco.com/t5/network-access-control/enable-mode-with-aaa-acs/m-p/121195#M438507</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Try changing:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authorization exec default if-authenticated group tacacs+ &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;to:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authorization exec default group tacacs+ none&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think the if-authenticated is being used instead of the TACACS server attributes cause you have it first.  In fact, the TACACS server will never be used for authorization with your current setup because the "if-authenticated" will always be used first and will never fail (unless authentication fails first). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Jan 2003 02:42:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/enable-mode-with-aaa-acs/m-p/121195#M438507</guid>
      <dc:creator>gfullage</dc:creator>
      <dc:date>2003-01-06T02:42:34Z</dc:date>
    </item>
    <item>
      <title>Re: Enable mode with AAA &amp; ACS</title>
      <link>https://community.cisco.com/t5/network-access-control/enable-mode-with-aaa-acs/m-p/121196#M438508</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks that did the trick!!!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Jan 2003 08:16:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/enable-mode-with-aaa-acs/m-p/121196#M438508</guid>
      <dc:creator>gamoore</dc:creator>
      <dc:date>2003-01-07T08:16:47Z</dc:date>
    </item>
    <item>
      <title>Re: Enable mode with AAA &amp; ACS</title>
      <link>https://community.cisco.com/t5/network-access-control/enable-mode-with-aaa-acs/m-p/121197#M438509</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A while back you had asked for assistance regarding setting up TACAS to the router logins to skip over to enable mode.  I am currently trying to get this to work myself.  Would it be possbile for you to post your working configuration (minus passwords of course), on the Cisco site? Also, any comments regarding what you had to do on the CiscoSecure site would be useful as well.   &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you in advance.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 Feb 2003 19:19:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/enable-mode-with-aaa-acs/m-p/121197#M438509</guid>
      <dc:creator>ed.daly</dc:creator>
      <dc:date>2003-02-03T19:19:46Z</dc:date>
    </item>
    <item>
      <title>Re: Enable mode with AAA &amp; ACS</title>
      <link>https://community.cisco.com/t5/network-access-control/enable-mode-with-aaa-acs/m-p/121198#M438510</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is part of EXEC authorization when the user logs in:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;aaa authentication login default group tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authorization exec default group tacacs+ local &lt;/P&gt;&lt;P&gt;tac server &lt;IP address=""&gt; key &lt;KEY&gt;&lt;/KEY&gt;&lt;/IP&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;username foo privilege 15 password bar&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Assign the user or group privilege level 15 and away you go.  You can use your local account if the connection to the tac+ server goes down or you receive an error for things like a key mismatch.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There are oodles of examples on cisco.com.  Here is a good reference:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/pcgi-bin/Support/browse/psp_view.pl?p=Internetworking:Tacacs_plus&amp;amp;s=Implementation_and_Configuration" target="_blank"&gt;http://www.cisco.com/pcgi-bin/Support/browse/psp_view.pl?p=Internetworking:Tacacs_plus&amp;amp;s=Implementation_and_Configuration&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Feb 2003 01:11:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/enable-mode-with-aaa-acs/m-p/121198#M438510</guid>
      <dc:creator>4brown</dc:creator>
      <dc:date>2003-02-05T01:11:03Z</dc:date>
    </item>
  </channel>
</rss>

