<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic privilege problem in ACS in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/privilege-problem-in-acs/m-p/2735446#M56992</link>
    <description>&lt;P style="margin-bottom: 0px; padding: 0px; border: 0px; font-size: 14px; font-family: Arial; vertical-align: baseline;"&gt;Hi dears ,&lt;/P&gt;&lt;P style="margin-bottom: 0px; padding: 0px; border: 0px; font-size: 14px; font-family: Arial; vertical-align: baseline;"&gt;I have set a topology which there is ACS 5.5 and windows 2008 ,server is not working yet ,I have applied AAA methods to the just R6 and R7 ,both of them is asking for username which I created internally inside ACS&amp;nbsp; ,but there is a small problem , i created user tahir which privilege is 15 ,and user zeynal privilege 1 .when I telnet to the router I enter the username and password for zeynal ,it gives this output.&lt;/P&gt;&lt;P style="margin-bottom: 0px; padding: 0px; border: 0px; font-size: 14px; font-family: Arial; vertical-align: baseline; min-height: 8pt;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="margin-bottom: 0px; padding: 0px; border: 0px; font-size: 14px; font-family: Arial; vertical-align: baseline;"&gt;R6&amp;gt;show privi&lt;/P&gt;&lt;P style="margin-bottom: 0px; padding: 0px; border: 0px; font-size: 14px; font-family: Arial; vertical-align: baseline;"&gt;Current privilege level is 1&lt;/P&gt;&lt;P style="margin-bottom: 0px; padding: 0px; border: 0px; font-size: 14px; font-family: Arial; vertical-align: baseline;"&gt;R6&amp;gt;en&lt;/P&gt;&lt;P style="margin-bottom: 0px; padding: 0px; border: 0px; font-size: 14px; font-family: Arial; vertical-align: baseline;"&gt;Password:&lt;/P&gt;&lt;P style="margin-bottom: 0px; padding: 0px; border: 0px; font-size: 14px; font-family: Arial; vertical-align: baseline;"&gt;R6#sho&lt;/P&gt;&lt;P style="margin-bottom: 0px; padding: 0px; border: 0px; font-size: 14px; font-family: Arial; vertical-align: baseline;"&gt;R6#show pri&lt;/P&gt;&lt;P style="margin-bottom: 0px; padding: 0px; border: 0px; font-size: 14px; font-family: Arial; vertical-align: baseline;"&gt;R6#show privi&lt;/P&gt;&lt;P style="margin-bottom: 0px; padding: 0px; border: 0px; font-size: 14px; font-family: Arial; vertical-align: baseline;"&gt;R6#show privilege&lt;/P&gt;&lt;P style="margin-bottom: 0px; padding: 0px; border: 0px; font-size: 14px; font-family: Arial; vertical-align: baseline;"&gt;Current privilege level is 15&lt;/P&gt;&lt;P style="margin-bottom: 0px; padding: 0px; border: 0px; font-size: 14px; font-family: Arial; vertical-align: baseline; min-height: 8pt;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="margin-bottom: 0px; padding: 0px; border: 0px; font-size: 14px; font-family: Arial; vertical-align: baseline;"&gt;Why it turns to privilige 15 ??? I just have given to zeynal user privilege 1.&lt;/P&gt;&lt;P style="margin-bottom: 0px; padding: 0px; border: 0px; font-size: 14px; font-family: Arial; vertical-align: baseline; min-height: 8pt;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="margin-bottom: 0px; padding: 0px; border: 0px; font-size: 14px; font-family: Arial; vertical-align: baseline;"&gt;Can anyone please help me ??&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 06:10:50 GMT</pubDate>
    <dc:creator>hacizeynal</dc:creator>
    <dc:date>2019-03-11T06:10:50Z</dc:date>
    <item>
      <title>privilege problem in ACS</title>
      <link>https://community.cisco.com/t5/network-access-control/privilege-problem-in-acs/m-p/2735446#M56992</link>
      <description>&lt;P style="margin-bottom: 0px; padding: 0px; border: 0px; font-size: 14px; font-family: Arial; vertical-align: baseline;"&gt;Hi dears ,&lt;/P&gt;&lt;P style="margin-bottom: 0px; padding: 0px; border: 0px; font-size: 14px; font-family: Arial; vertical-align: baseline;"&gt;I have set a topology which there is ACS 5.5 and windows 2008 ,server is not working yet ,I have applied AAA methods to the just R6 and R7 ,both of them is asking for username which I created internally inside ACS&amp;nbsp; ,but there is a small problem , i created user tahir which privilege is 15 ,and user zeynal privilege 1 .when I telnet to the router I enter the username and password for zeynal ,it gives this output.&lt;/P&gt;&lt;P style="margin-bottom: 0px; padding: 0px; border: 0px; font-size: 14px; font-family: Arial; vertical-align: baseline; min-height: 8pt;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="margin-bottom: 0px; padding: 0px; border: 0px; font-size: 14px; font-family: Arial; vertical-align: baseline;"&gt;R6&amp;gt;show privi&lt;/P&gt;&lt;P style="margin-bottom: 0px; padding: 0px; border: 0px; font-size: 14px; font-family: Arial; vertical-align: baseline;"&gt;Current privilege level is 1&lt;/P&gt;&lt;P style="margin-bottom: 0px; padding: 0px; border: 0px; font-size: 14px; font-family: Arial; vertical-align: baseline;"&gt;R6&amp;gt;en&lt;/P&gt;&lt;P style="margin-bottom: 0px; padding: 0px; border: 0px; font-size: 14px; font-family: Arial; vertical-align: baseline;"&gt;Password:&lt;/P&gt;&lt;P style="margin-bottom: 0px; padding: 0px; border: 0px; font-size: 14px; font-family: Arial; vertical-align: baseline;"&gt;R6#sho&lt;/P&gt;&lt;P style="margin-bottom: 0px; padding: 0px; border: 0px; font-size: 14px; font-family: Arial; vertical-align: baseline;"&gt;R6#show pri&lt;/P&gt;&lt;P style="margin-bottom: 0px; padding: 0px; border: 0px; font-size: 14px; font-family: Arial; vertical-align: baseline;"&gt;R6#show privi&lt;/P&gt;&lt;P style="margin-bottom: 0px; padding: 0px; border: 0px; font-size: 14px; font-family: Arial; vertical-align: baseline;"&gt;R6#show privilege&lt;/P&gt;&lt;P style="margin-bottom: 0px; padding: 0px; border: 0px; font-size: 14px; font-family: Arial; vertical-align: baseline;"&gt;Current privilege level is 15&lt;/P&gt;&lt;P style="margin-bottom: 0px; padding: 0px; border: 0px; font-size: 14px; font-family: Arial; vertical-align: baseline; min-height: 8pt;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="margin-bottom: 0px; padding: 0px; border: 0px; font-size: 14px; font-family: Arial; vertical-align: baseline;"&gt;Why it turns to privilige 15 ??? I just have given to zeynal user privilege 1.&lt;/P&gt;&lt;P style="margin-bottom: 0px; padding: 0px; border: 0px; font-size: 14px; font-family: Arial; vertical-align: baseline; min-height: 8pt;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="margin-bottom: 0px; padding: 0px; border: 0px; font-size: 14px; font-family: Arial; vertical-align: baseline;"&gt;Can anyone please help me ??&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 06:10:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/privilege-problem-in-acs/m-p/2735446#M56992</guid>
      <dc:creator>hacizeynal</dc:creator>
      <dc:date>2019-03-11T06:10:50Z</dc:date>
    </item>
    <item>
      <title>Hi dears ,</title>
      <link>https://community.cisco.com/t5/network-access-control/privilege-problem-in-acs/m-p/2735447#M56993</link>
      <description>&lt;PRE style="margin-bottom: 0px; font-size: 14px; padding: 0px; border: 0px; font-family: Arial;"&gt;
Hi dears ,

I have set a topology which there is ACS 5.5 and windows 2008 ,server is not working yet ,I have applied AAA methods to the just R6 and R7 ,both of them is asking for username which I created internally inside ACS  ,but there is a small problem , i created user tahir which privilege is 15 ,and user zeynal privilege 1 .when I telnet to the router I enter the username and password for zeynal ,it gives this output.


R6&amp;gt;show privi

Current privilege level is 1

R6&amp;gt;en

Password:

R6#sho

R6#show pri

R6#show privi

R6#show privilege

Current privilege level is 15


Why it turns to privilige 15 ??? I just have given to zeynal user privilege 1.


Can anyone please help me ??&lt;/PRE&gt;

&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Without seeing the configuration it is hard to comment anything but have look on the below two links which specifically speaks about ACS 5.5 and cisco router authorisation configuration.&lt;/P&gt;
&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/td/docs/net_mgmt/cisco_secure_access_control_system/5-5/migration/guide/migration_guide/Migration_Configure.html"&gt;ACS 5.5 configuration&lt;/A&gt;&amp;nbsp;and &lt;A href="http://www.cisco.com/c/en/us/td/docs/ios/12_2/security/command/reference/fsecur_r/srfauth.html"&gt;Authorization in cisco router&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Hope it Helps..&lt;/P&gt;
&lt;P&gt;-GI&lt;/P&gt;
&lt;P&gt;Rate if it Helps&lt;/P&gt;</description>
      <pubDate>Sun, 25 Oct 2015 03:59:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/privilege-problem-in-acs/m-p/2735447#M56993</guid>
      <dc:creator>Ganesh Hariharan</dc:creator>
      <dc:date>2015-10-25T03:59:13Z</dc:date>
    </item>
    <item>
      <title>aaa new-modelaaa</title>
      <link>https://community.cisco.com/t5/network-access-control/privilege-problem-in-acs/m-p/2735448#M56994</link>
      <description>&lt;P&gt;&lt;BR /&gt;aaa new-model&lt;BR /&gt;aaa authentication login Zeynal group tacacs+ local enable&lt;BR /&gt;aaa authorization exec Zeynal group tacacs+ local&lt;BR /&gt;aaa authorization commands 2 default group tacacs+&lt;BR /&gt;aaa authorization commands 2 Zeynal group tacacs+&lt;BR /&gt;aaa authorization commands 15 default group tacacs+&lt;BR /&gt;aaa authorization commands 15 Zeynal group tacacs+&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 25 Oct 2015 11:51:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/privilege-problem-in-acs/m-p/2735448#M56994</guid>
      <dc:creator>hacizeynal</dc:creator>
      <dc:date>2015-10-25T11:51:43Z</dc:date>
    </item>
    <item>
      <title>aaa new-model</title>
      <link>https://community.cisco.com/t5/network-access-control/privilege-problem-in-acs/m-p/2735449#M56995</link>
      <description>&lt;PRE&gt;
&lt;SPAN style="font-size: 14px;"&gt;aaa new-model&lt;/SPAN&gt;
&lt;SPAN style="font-size: 14px;"&gt;aaa authentication login Zeynal group tacacs+ local enable&lt;/SPAN&gt;
&lt;SPAN style="font-size: 14px;"&gt;aaa authorization exec Zeynal group tacacs+ local&lt;/SPAN&gt;
&lt;SPAN style="font-size: 14px;"&gt;aaa authorization commands 2 default group tacacs+&lt;/SPAN&gt;
&lt;SPAN style="font-size: 14px;"&gt;aaa authorization commands 2 Zeynal group tacacs+&lt;/SPAN&gt;
&lt;SPAN style="font-size: 14px;"&gt;aaa authorization commands 15 default group tacacs+&lt;/SPAN&gt;
&lt;SPAN style="font-size: 14px;"&gt;aaa authorization commands 15 Zeynal group tacacs+&lt;/SPAN&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;SPAN style="font-size: 14px;"&gt;Hi,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 14px;"&gt;​Try removing Zeynal with default as&amp;nbsp;authorisation is coming from cisco ACS.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 14px;"&gt;-GI&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Oct 2015 17:18:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/privilege-problem-in-acs/m-p/2735449#M56995</guid>
      <dc:creator>Ganesh Hariharan</dc:creator>
      <dc:date>2015-10-26T17:18:48Z</dc:date>
    </item>
  </channel>
</rss>

