<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Unable to create a Read-Only policy in ISE 2.4; 'enable' password doesnt work in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/unable-to-create-a-read-only-policy-in-ise-2-4-enable-password/m-p/3593361#M509022</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;IN my opinion the best way to do any sort of user levels on devices is to do command authorization.&amp;nbsp; The ASA allows you to send users to priv 15 just like any other Cisco product. Send all users to priv 15 and do command authorization to create whatever class of users you want.&amp;nbsp; If they are using ASDM you need to allow “write net” so the config can be sent into ASDM.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 14 Jun 2018 11:51:27 GMT</pubDate>
    <dc:creator>paul</dc:creator>
    <dc:date>2018-06-14T11:51:27Z</dc:date>
    <item>
      <title>Unable to create a Read-Only policy in ISE 2.4; 'enable' password doesnt work</title>
      <link>https://community.cisco.com/t5/network-access-control/unable-to-create-a-read-only-policy-in-ise-2-4-enable-password/m-p/3593359#M509017</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am trying to create a read-only authorization policy for firewalls for a particular team in ISE 2.4, but I am unable to do it efficiently. I have configured the shell profile for the team to have a default privilege of 1 and max of 7. But for some reason, whenever they log into the ASA, they say their 'login' password works fine, but their 'enable' password isnt working; as a result of which they are unable to get a privilege level of 7. I have tried enabling/disabling the 'enable' password but still its of no avail. So can someone help me out on this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Abhijit&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Jun 2018 23:55:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/unable-to-create-a-read-only-policy-in-ise-2-4-enable-password/m-p/3593359#M509017</guid>
      <dc:creator>abhijith891</dc:creator>
      <dc:date>2018-06-13T23:55:38Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to create a Read-Only policy in ISE 2.4; 'enable' password doesnt work</title>
      <link>https://community.cisco.com/t5/network-access-control/unable-to-create-a-read-only-policy-in-ise-2-4-enable-password/m-p/3593360#M509019</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ASA has no option for "enable" so its "enable" is actually "enable 15". Thus, please set the default privilege to 7.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Jun 2018 00:53:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/unable-to-create-a-read-only-policy-in-ise-2-4-enable-password/m-p/3593360#M509019</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-06-14T00:53:16Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to create a Read-Only policy in ISE 2.4; 'enable' password doesnt work</title>
      <link>https://community.cisco.com/t5/network-access-control/unable-to-create-a-read-only-policy-in-ise-2-4-enable-password/m-p/3593361#M509022</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;IN my opinion the best way to do any sort of user levels on devices is to do command authorization.&amp;nbsp; The ASA allows you to send users to priv 15 just like any other Cisco product. Send all users to priv 15 and do command authorization to create whatever class of users you want.&amp;nbsp; If they are using ASDM you need to allow “write net” so the config can be sent into ASDM.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Jun 2018 11:51:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/unable-to-create-a-read-only-policy-in-ise-2-4-enable-password/m-p/3593361#M509022</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2018-06-14T11:51:27Z</dc:date>
    </item>
  </channel>
</rss>

