<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Tacacs Authorization in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/tacacs-authorization/m-p/3587980#M511907</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Below is my current tacacs configuration. I am trying to configure my ASR which is running Cisco IOS XR ver 5.3.3. I am trying to configure my device for when the tacacs server is unavailable I can still log in and make configurations. When I input the configuration I receive an error and I am not sure why.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tacacs Config:&lt;/P&gt;&lt;P&gt;aaa accounting exec default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting commands default stop-only group tacacs+&lt;/P&gt;&lt;P&gt;aaa authorization exec default group tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authorization commands 0 group tacacs+&lt;/P&gt;&lt;P&gt;aaa authorization commands 1 group tacacs+&lt;/P&gt;&lt;P&gt;aaa authorization commands 15 group tacacs+&lt;/P&gt;&lt;P&gt;aaa authorization commands default group tacacs+&lt;/P&gt;&lt;P&gt;aaa authorization eventmanager default local&lt;/P&gt;&lt;P&gt;aaa authorization eventmanager tcluser local&lt;/P&gt;&lt;P&gt;aaa authentication login default group tacacs+ local&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Error:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;#aaa authorization commands default group tacacs+ local&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ^&lt;/P&gt;&lt;P&gt;% Invalid input detected at '^' marker.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 01 Mar 2018 21:56:59 GMT</pubDate>
    <dc:creator>jharper2</dc:creator>
    <dc:date>2018-03-01T21:56:59Z</dc:date>
    <item>
      <title>Tacacs Authorization</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-authorization/m-p/3587980#M511907</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Below is my current tacacs configuration. I am trying to configure my ASR which is running Cisco IOS XR ver 5.3.3. I am trying to configure my device for when the tacacs server is unavailable I can still log in and make configurations. When I input the configuration I receive an error and I am not sure why.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tacacs Config:&lt;/P&gt;&lt;P&gt;aaa accounting exec default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting commands default stop-only group tacacs+&lt;/P&gt;&lt;P&gt;aaa authorization exec default group tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authorization commands 0 group tacacs+&lt;/P&gt;&lt;P&gt;aaa authorization commands 1 group tacacs+&lt;/P&gt;&lt;P&gt;aaa authorization commands 15 group tacacs+&lt;/P&gt;&lt;P&gt;aaa authorization commands default group tacacs+&lt;/P&gt;&lt;P&gt;aaa authorization eventmanager default local&lt;/P&gt;&lt;P&gt;aaa authorization eventmanager tcluser local&lt;/P&gt;&lt;P&gt;aaa authentication login default group tacacs+ local&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Error:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;#aaa authorization commands default group tacacs+ local&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ^&lt;/P&gt;&lt;P&gt;% Invalid input detected at '^' marker.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Mar 2018 21:56:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-authorization/m-p/3587980#M511907</guid>
      <dc:creator>jharper2</dc:creator>
      <dc:date>2018-03-01T21:56:59Z</dc:date>
    </item>
    <item>
      <title>Re: Tacacs Authorization</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-authorization/m-p/3587981#M511909</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you've already validated that no syntax issue, then please consult with the support team for the ASR or Cisco IOS XR. It might be a bug in that platform.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Mar 2018 00:41:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-authorization/m-p/3587981#M511909</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-03-02T00:41:42Z</dc:date>
    </item>
    <item>
      <title>Re: Tacacs Authorization</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-authorization/m-p/3587982#M511910</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Justin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I believe the syntax on ASR have to be&lt;/P&gt;&lt;P&gt;" aaa authorization commands 15 default group tacacs+ local " or&lt;/P&gt;&lt;P&gt;" aaa authorization commands 0 default group tacacs+ local "&lt;/P&gt;&lt;P&gt;Got to put enable level.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sai&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Mar 2018 02:33:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-authorization/m-p/3587982#M511910</guid>
      <dc:creator>danielsai</dc:creator>
      <dc:date>2018-03-02T02:33:09Z</dc:date>
    </item>
    <item>
      <title>Re: Tacacs Authorization</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-authorization/m-p/3587983#M511914</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sai is correct. On Cisco IOS or the like, the commands are associated with run levels. If you have customized commands to some specific levels, then just follow the same syntax to add the additional run levels.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Mar 2018 04:24:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-authorization/m-p/3587983#M511914</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-03-02T04:24:44Z</dc:date>
    </item>
    <item>
      <title>Re: Tacacs Authorization</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-authorization/m-p/3587984#M511916</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have validated the syntax issue. And I have tried adding the local group to the enable levels I still get an error. Below is the output from the syntax validation:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authorization commands default group tacacs+ group local&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;(config)#commit&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;% Failed to commit one or more configuration items during a pseudo-atomic operation. All changes made have been reverted. Please issue 'show configuration failed [inheritance]' from this session to view the errors&lt;/P&gt;&lt;P&gt;(config)#show configuration failed&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!! SEMANTIC ERRORS: This configuration was rejected by &lt;/P&gt;&lt;P&gt;!! the system due to semantic errors. The individual &lt;/P&gt;&lt;P&gt;!! errors with each failed configuration command can be &lt;/P&gt;&lt;P&gt;!! found below.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authorization commands default group tacacs+ group local&lt;/P&gt;&lt;P&gt;!!% An invalid method was specified in the message or required configuration is missing: %AAA-3-ILLEGALNAME: Illegal authorization server-group name "local" rejected&lt;/P&gt;&lt;P&gt;end&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Mar 2018 15:27:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-authorization/m-p/3587984#M511916</guid>
      <dc:creator>jharper2</dc:creator>
      <dc:date>2018-03-02T15:27:58Z</dc:date>
    </item>
    <item>
      <title>Re: Tacacs Authorization</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-authorization/m-p/3587985#M511920</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If it working without "local", then it seems in that particular IOS-XR release and ASR platform combination does not support local for "default". I do not think you need that anyway if all the run-levels are explicitly specified.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Mar 2018 17:15:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-authorization/m-p/3587985#M511920</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-03-02T17:15:47Z</dc:date>
    </item>
  </channel>
</rss>

