<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Unable to do changes - Current privilege level: -1 in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/unable-to-do-changes-current-privilege-level-1/m-p/4566356#M573309</link>
    <description>&lt;P&gt;We have also tried stopping ACS authentication and using local account (authentication was successful but could not make changes) but still could not make changes to the configuration.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The local account has role network-admin assigned to it.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Daniel&lt;/P&gt;</description>
    <pubDate>Tue, 08 Mar 2022 16:03:25 GMT</pubDate>
    <dc:creator>ziqex</dc:creator>
    <dc:date>2022-03-08T16:03:25Z</dc:date>
    <item>
      <title>Unable to do changes - Current privilege level: -1</title>
      <link>https://community.cisco.com/t5/network-access-control/unable-to-do-changes-current-privilege-level-1/m-p/4563141#M573132</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I authenticate with the switch with ACS.&lt;/P&gt;&lt;P&gt;Authentication is successful but I am unable to run show run or make change in configure terminal.&lt;/P&gt;&lt;P&gt;sh privilege&lt;BR /&gt;User name: testacc&lt;BR /&gt;Current privilege level: -1&lt;BR /&gt;Feature privilege: Disabled&lt;/P&gt;&lt;P&gt;sh run&lt;BR /&gt;% Permission denied for the role&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hardware&lt;BR /&gt;cisco Nexus5548 Chassis&lt;/P&gt;&lt;P&gt;Reason: Reset Requested by CLI command reload&lt;BR /&gt;System version: 7.3(7)N1(1b)&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please advise how can I resolve it. Thank you.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Daniel&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Mar 2022 16:07:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/unable-to-do-changes-current-privilege-level-1/m-p/4563141#M573132</guid>
      <dc:creator>ziqex</dc:creator>
      <dc:date>2022-03-03T16:07:15Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to do changes - Current privilege level: -1</title>
      <link>https://community.cisco.com/t5/network-access-control/unable-to-do-changes-current-privilege-level-1/m-p/4563153#M573133</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Current privilege level: -1&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;change level to 15&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/secure-access-control-system/116236-configure-acs-00.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/secure-access-control-system/116236-configure-acs-00.html&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Mar 2022 16:08:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/unable-to-do-changes-current-privilege-level-1/m-p/4563153#M573133</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2022-03-03T16:08:51Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to do changes - Current privilege level: -1</title>
      <link>https://community.cisco.com/t5/network-access-control/unable-to-do-changes-current-privilege-level-1/m-p/4563157#M573134</link>
      <description>&lt;P&gt;Exactly the same account has privilege 15 on different devices. Thank you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;show privilege&lt;BR /&gt;Current privilege level is 15&lt;/P&gt;</description>
      <pubDate>Thu, 03 Mar 2022 16:12:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/unable-to-do-changes-current-privilege-level-1/m-p/4563157#M573134</guid>
      <dc:creator>ziqex</dc:creator>
      <dc:date>2022-03-03T16:12:04Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to do changes - Current privilege level: -1</title>
      <link>https://community.cisco.com/t5/network-access-control/unable-to-do-changes-current-privilege-level-1/m-p/4563207#M573136</link>
      <description>&lt;P&gt;Then what prompt are you in nexus : (another device is nexus ? or IOS ?)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;gt; or #&lt;/P&gt;</description>
      <pubDate>Thu, 03 Mar 2022 17:16:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/unable-to-do-changes-current-privilege-level-1/m-p/4563207#M573136</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2022-03-03T17:16:22Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to do changes - Current privilege level: -1</title>
      <link>https://community.cisco.com/t5/network-access-control/unable-to-do-changes-current-privilege-level-1/m-p/4563222#M573137</link>
      <description>&lt;P&gt;On nexus and ios I'm getting logged in directly to&amp;nbsp;#.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Whereas for nexus I cannot execute sh run command.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Thu, 03 Mar 2022 17:23:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/unable-to-do-changes-current-privilege-level-1/m-p/4563222#M573137</guid>
      <dc:creator>ziqex</dc:creator>
      <dc:date>2022-03-03T17:23:17Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to do changes - Current privilege level: -1</title>
      <link>https://community.cisco.com/t5/network-access-control/unable-to-do-changes-current-privilege-level-1/m-p/4563231#M573138</link>
      <description>&lt;P&gt;IOS works, nexus have network-admin role&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;check the below config guide and add necessary action :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/secure-access-control-system/115925-nexus-integration-acs-00.html" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/support/docs/security/secure-access-control-system/115925-nexus-integration-acs-00.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Mar 2022 17:35:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/unable-to-do-changes-current-privilege-level-1/m-p/4563231#M573138</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2022-03-03T17:35:00Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to do changes - Current privilege level: -1</title>
      <link>https://community.cisco.com/t5/network-access-control/unable-to-do-changes-current-privilege-level-1/m-p/4564097#M573164</link>
      <description>&lt;P&gt;I've been following the guide but on the step 5 ACS I cannot create new authorization rule I have only Default rule available and cannot add new one.&amp;nbsp; Create add below and above is blank. Please advise. Thank you&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;5. Create a new authorization rule, or edit an existing rule, in the correct access policy. By default, TACACS+ requests are processed by the Default Device Admin access policy.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Mar 2022 12:46:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/unable-to-do-changes-current-privilege-level-1/m-p/4564097#M573164</guid>
      <dc:creator>ziqex</dc:creator>
      <dc:date>2022-03-04T12:46:19Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to do changes - Current privilege level: -1</title>
      <link>https://community.cisco.com/t5/network-access-control/unable-to-do-changes-current-privilege-level-1/m-p/4564113#M573166</link>
      <description>&lt;P&gt;I managed to add the new rule. I had to switch to the internet explorer as it did not like chrome for some reason. Thank you for all information provided.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Mar 2022 13:28:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/unable-to-do-changes-current-privilege-level-1/m-p/4564113#M573166</guid>
      <dc:creator>ziqex</dc:creator>
      <dc:date>2022-03-04T13:28:32Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to do changes - Current privilege level: -1</title>
      <link>https://community.cisco.com/t5/network-access-control/unable-to-do-changes-current-privilege-level-1/m-p/4564155#M573167</link>
      <description>&lt;P&gt;glad working all good, yes IE is good with ACS, some how cisco ACS not work with chrome as expected (forgot to mentioned)&lt;/P&gt;</description>
      <pubDate>Fri, 04 Mar 2022 14:19:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/unable-to-do-changes-current-privilege-level-1/m-p/4564155#M573167</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2022-03-04T14:19:59Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to do changes - Current privilege level: -1</title>
      <link>https://community.cisco.com/t5/network-access-control/unable-to-do-changes-current-privilege-level-1/m-p/4566076#M573296</link>
      <description>&lt;P&gt;I managed to view the running config after correct value to the shell profile (Value: shell:roles*"network-admin vdc-admin").&lt;/P&gt;&lt;P&gt;Unfortunately, I cannot make any configuration changes as getting the AAA authorisation error.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Error: AAA authorization failed AAA_AUTHOR_STATUS_METHOD=16(0x10)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any advice how to resolve it? Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 08 Mar 2022 08:45:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/unable-to-do-changes-current-privilege-level-1/m-p/4566076#M573296</guid>
      <dc:creator>ziqex</dc:creator>
      <dc:date>2022-03-08T08:45:42Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to do changes - Current privilege level: -1</title>
      <link>https://community.cisco.com/t5/network-access-control/unable-to-do-changes-current-privilege-level-1/m-p/4566117#M573297</link>
      <description>&lt;P&gt;how does your AAA config looks like in nexus add below command :&amp;nbsp; ( Do not lockup yourself. make sure you have fall back to Locla account)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;I&gt;aaa authorization config-commands default group radius_servers&amp;nbsp; (radisu_servers your group)&lt;BR /&gt;&lt;/I&gt;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Mar 2022 09:48:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/unable-to-do-changes-current-privilege-level-1/m-p/4566117#M573297</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2022-03-08T09:48:25Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to do changes - Current privilege level: -1</title>
      <link>https://community.cisco.com/t5/network-access-control/unable-to-do-changes-current-privilege-level-1/m-p/4566123#M573298</link>
      <description>&lt;P&gt;the current aaa config is as below&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;sh run aaa&lt;/P&gt;&lt;P&gt;!Command: show running-config aaa&lt;/P&gt;&lt;P&gt;version 7.3(7)N1(1b)&lt;BR /&gt;aaa authentication login default group ACS_Servers local&lt;BR /&gt;aaa authentication login console local&lt;BR /&gt;aaa authorization config-commands default group ACS_Servers&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 08 Mar 2022 09:52:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/unable-to-do-changes-current-privilege-level-1/m-p/4566123#M573298</guid>
      <dc:creator>ziqex</dc:creator>
      <dc:date>2022-03-08T09:52:14Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to do changes - Current privilege level: -1</title>
      <link>https://community.cisco.com/t5/network-access-control/unable-to-do-changes-current-privilege-level-1/m-p/4566338#M573306</link>
      <description>&lt;P&gt;Can you post ACS_Servers&amp;nbsp; information&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Mar 2022 15:53:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/unable-to-do-changes-current-privilege-level-1/m-p/4566338#M573306</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2022-03-08T15:53:21Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to do changes - Current privilege level: -1</title>
      <link>https://community.cisco.com/t5/network-access-control/unable-to-do-changes-current-privilege-level-1/m-p/4566341#M573307</link>
      <description>&lt;P&gt;aaa group server tacacs+ ACS_Servers&lt;BR /&gt;server 10.94.1.28&lt;BR /&gt;server 10.94.2.30&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Tue, 08 Mar 2022 15:56:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/unable-to-do-changes-current-privilege-level-1/m-p/4566341#M573307</guid>
      <dc:creator>ziqex</dc:creator>
      <dc:date>2022-03-08T15:56:28Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to do changes - Current privilege level: -1</title>
      <link>https://community.cisco.com/t5/network-access-control/unable-to-do-changes-current-privilege-level-1/m-p/4566356#M573309</link>
      <description>&lt;P&gt;We have also tried stopping ACS authentication and using local account (authentication was successful but could not make changes) but still could not make changes to the configuration.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The local account has role network-admin assigned to it.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Daniel&lt;/P&gt;</description>
      <pubDate>Tue, 08 Mar 2022 16:03:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/unable-to-do-changes-current-privilege-level-1/m-p/4566356#M573309</guid>
      <dc:creator>ziqex</dc:creator>
      <dc:date>2022-03-08T16:03:25Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to do changes - Current privilege level: -1</title>
      <link>https://community.cisco.com/t5/network-access-control/unable-to-do-changes-current-privilege-level-1/m-p/4566397#M573313</link>
      <description>&lt;P&gt;have this configuration written ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In this case Looks like it locked up now, you have only Option here is console, try connect to console , since it confgured as local.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Mar 2022 16:43:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/unable-to-do-changes-current-privilege-level-1/m-p/4566397#M573313</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2022-03-08T16:43:13Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to do changes - Current privilege level: -1</title>
      <link>https://community.cisco.com/t5/network-access-control/unable-to-do-changes-current-privilege-level-1/m-p/4566890#M573326</link>
      <description>&lt;P&gt;I still have remote access to the device. Is there any command that will allow me to have option to change configuration?&lt;/P&gt;&lt;P&gt;In the current state I can only view show commands.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 09 Mar 2022 08:33:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/unable-to-do-changes-current-privilege-level-1/m-p/4566890#M573326</guid>
      <dc:creator>ziqex</dc:creator>
      <dc:date>2022-03-09T08:33:37Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to do changes - Current privilege level: -1</title>
      <link>https://community.cisco.com/t5/network-access-control/unable-to-do-changes-current-privilege-level-1/m-p/4567029#M573338</link>
      <description>&lt;P&gt;if you have remote access, are you using local account or radius loging ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;do you have any config command access :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;post aaa command information what configured&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Mar 2022 12:43:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/unable-to-do-changes-current-privilege-level-1/m-p/4567029#M573338</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2022-03-09T12:43:53Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to do changes - Current privilege level: -1</title>
      <link>https://community.cisco.com/t5/network-access-control/unable-to-do-changes-current-privilege-level-1/m-p/4567033#M573339</link>
      <description>&lt;P&gt;I am using account that was created in ACS, it has&amp;nbsp;&lt;SPAN&gt;Value: shell:roles*"network-admin vdc-admin" assigned to the shell profile.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;It still prevents me from creating new vlans in the configuration mode. Thanks&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;sh run aaa&lt;/P&gt;&lt;P&gt;!Command: show running-config aaa&lt;/P&gt;&lt;P&gt;aaa authentication login default group ACS_Servers local&lt;BR /&gt;aaa authentication login console local&lt;BR /&gt;aaa authorization config-commands default group ACS_Servers&lt;/P&gt;</description>
      <pubDate>Wed, 09 Mar 2022 12:48:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/unable-to-do-changes-current-privilege-level-1/m-p/4567033#M573339</guid>
      <dc:creator>ziqex</dc:creator>
      <dc:date>2022-03-09T12:48:17Z</dc:date>
    </item>
  </channel>
</rss>

