<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: TACACS - specific commands only in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/tacacs-specific-commands-only/m-p/4676320#M576916</link>
    <description>&lt;P&gt;If you like to configure eigrp process that is the only way you can do as per i know, there is no short cut if you using RBAC.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/admin_guide/b_ISE_admin_guide_24/m_ise_tacacs_device_admin.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/admin_guide/b_ISE_admin_guide_24/m_ise_tacacs_device_admin.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI id="reference_19B20BAAC40A46B4ACB252739C010879__li_5905CDA35CE84DD1A669F6EBB6693DBC" class="li"&gt;
&lt;P class="p"&gt;Any character in the command in the command set may be "?", which matches any individual character that must exist in the requested command&lt;/P&gt;
&lt;/LI&gt;
&lt;LI id="reference_19B20BAAC40A46B4ACB252739C010879__li_8476B5CB246C423BA0230870EDC7DE12" class="li"&gt;
&lt;P class="p"&gt;Any character in the command in the command set may be "*", which matches zero or more characters in the requested command&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/200208-Configure-ISE-2-0-IOS-TACACS-Authentic.html#anc12" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/200208-Configure-ISE-2-0-IOS-TACACS-Authentic.html#anc12&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 26 Aug 2022 15:46:53 GMT</pubDate>
    <dc:creator>balaji.bandi</dc:creator>
    <dc:date>2022-08-26T15:46:53Z</dc:date>
    <item>
      <title>TACACS - specific commands only</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-specific-commands-only/m-p/4676279#M576914</link>
      <description>&lt;P&gt;I would like to create a TACACS profile in ISE to allow only certain configuration commands / sub-commands.&amp;nbsp; I have most of this working - but need some assistance.&amp;nbsp; Thank you for your time.&lt;/P&gt;&lt;P&gt;What i'm trying to do is create a profile that allows a 'helpdesk' user to configure only EIGRP commands on the router.&amp;nbsp; I have one to allow them to show eigrp also.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Grant&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Command&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Arguments&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;PERMIT&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; enable&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 7&lt;/P&gt;&lt;P&gt;PERMIT&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; config*&lt;/P&gt;&lt;P&gt;PERMIT&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; exit&lt;/P&gt;&lt;P&gt;PERMIT&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; router&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; eigrp&lt;/P&gt;&lt;P&gt;PERMIT&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; show&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ip eigrp*&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am able to verify I can only issue show ip eigrp and config t / router eigrp commands.&amp;nbsp; I can't do things like 'show clock' 'show ip ospf' 'router ospf 1' etc.&amp;nbsp; ONLY the above commands I can execute - that is working.&amp;nbsp; The issue i'm having is when I am in the eigrp process.&amp;nbsp; Say i issue "config t" then "router eigpr 10" - I can't cofigure any commands within the EIGRP process.&amp;nbsp; They are not listed in my command set - so this makes sense.&amp;nbsp; What i'd like to know is if there is an easy way to allow these EIGRP sub commands or do i really have to go in the process - type a ? to see the avaiable commands and then add the top level commands to the command set?&amp;nbsp; I'd like to think there is a much easier way to do this than that.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks again for your help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Aug 2022 14:51:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-specific-commands-only/m-p/4676279#M576914</guid>
      <dc:creator>wannabCCIE</dc:creator>
      <dc:date>2022-08-26T14:51:22Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS - specific commands only</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-specific-commands-only/m-p/4676320#M576916</link>
      <description>&lt;P&gt;If you like to configure eigrp process that is the only way you can do as per i know, there is no short cut if you using RBAC.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/admin_guide/b_ISE_admin_guide_24/m_ise_tacacs_device_admin.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/admin_guide/b_ISE_admin_guide_24/m_ise_tacacs_device_admin.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI id="reference_19B20BAAC40A46B4ACB252739C010879__li_5905CDA35CE84DD1A669F6EBB6693DBC" class="li"&gt;
&lt;P class="p"&gt;Any character in the command in the command set may be "?", which matches any individual character that must exist in the requested command&lt;/P&gt;
&lt;/LI&gt;
&lt;LI id="reference_19B20BAAC40A46B4ACB252739C010879__li_8476B5CB246C423BA0230870EDC7DE12" class="li"&gt;
&lt;P class="p"&gt;Any character in the command in the command set may be "*", which matches zero or more characters in the requested command&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/200208-Configure-ISE-2-0-IOS-TACACS-Authentic.html#anc12" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/200208-Configure-ISE-2-0-IOS-TACACS-Authentic.html#anc12&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Aug 2022 15:46:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-specific-commands-only/m-p/4676320#M576916</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2022-08-26T15:46:53Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS - specific commands only</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-specific-commands-only/m-p/4676329#M576917</link>
      <description>&lt;P&gt;Thanks for the help.&amp;nbsp; I've just configured all the EIGRP sub commands and this works.&amp;nbsp; Was just hoping there was a nice/easy way to include sub-commands.&amp;nbsp; I also found another post about interface sub-commands.&amp;nbsp; Basically asking the same thing - just for interface configuration.&amp;nbsp; Same solution.&amp;nbsp; Just have to add each sub-command to the command set.&lt;/P&gt;&lt;P&gt;Thanks again.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Aug 2022 16:14:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-specific-commands-only/m-p/4676329#M576917</guid>
      <dc:creator>wannabCCIE</dc:creator>
      <dc:date>2022-08-26T16:14:16Z</dc:date>
    </item>
  </channel>
</rss>

