<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AAA Exclude specific command for Privileges 15 User in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/aaa-exclude-specific-command-for-privileges-15-user/m-p/4818433#M581311</link>
    <description>&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/200208-Configure-ISE-2-0-IOS-TACACS-Authentic.html" target="_blank"&gt;Configure ISE 2.0 TACACS+ Authentication Command Authorization - Cisco&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;in ISE TACACS you can deny/permit any command&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot (636).png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/182459i6BEA2EC621D7FD71/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot (636).png" alt="Screenshot (636).png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 20 Apr 2023 09:33:39 GMT</pubDate>
    <dc:creator>MHM Cisco World</dc:creator>
    <dc:date>2023-04-20T09:33:39Z</dc:date>
    <item>
      <title>AAA Exclude specific command for Privileges 15 User</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-exclude-specific-command-for-privileges-15-user/m-p/4817848#M581287</link>
      <description>&lt;P&gt;Hi Guys,&lt;BR /&gt;&lt;BR /&gt;Let's say I want to create user with privileges 15 but I don't want him to be able to execute&amp;nbsp; particular command&amp;nbsp; "debut ip packet"&lt;BR /&gt;How can I do that without having TACACS Server?&lt;BR /&gt;&lt;BR /&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Apr 2023 16:06:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-exclude-specific-command-for-privileges-15-user/m-p/4817848#M581287</guid>
      <dc:creator>karenmelkonyanstu</dc:creator>
      <dc:date>2023-04-19T16:06:49Z</dc:date>
    </item>
    <item>
      <title>Re: AAA Exclude specific command for Privileges 15 User</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-exclude-specific-command-for-privileges-15-user/m-p/4817875#M581291</link>
      <description>&lt;P&gt;Without TACACS server I don't think you can do command authorization locally.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Apr 2023 16:52:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-exclude-specific-command-for-privileges-15-user/m-p/4817875#M581291</guid>
      <dc:creator>Nancy Saini</dc:creator>
      <dc:date>2023-04-19T16:52:08Z</dc:date>
    </item>
    <item>
      <title>Re: AAA Exclude specific command for Privileges 15 User</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-exclude-specific-command-for-privileges-15-user/m-p/4817880#M581292</link>
      <description>&lt;P&gt;OK If I had TACACS Server - should I configure it ONLY on TACACS Server?&lt;BR /&gt;Or is there anything else besides bellow command I would have to configure on the switch\router?&lt;BR /&gt;aaa group server tacacs+ TACACS-SERVER&lt;BR /&gt;server-private 10.84.45.37 key 7 XXXXXXXXXXXXXXX&lt;BR /&gt;server-private 10.84.45.18 key 7 XXXXXXXXXXXXXXX&lt;BR /&gt;ip tacacs source-interface Vlan177&lt;BR /&gt;!&lt;BR /&gt;aaa authentication login default group TACACS-SERVER local&lt;BR /&gt;aaa authentication enable default group TACACS-SERVER enable&lt;BR /&gt;aaa authorization exec default group TACACS-SERVER if-authenticated&lt;BR /&gt;aaa authorization commands 15 default group TACACS-SERVER if-authenticated&lt;BR /&gt;!&lt;BR /&gt;aaa session-id common&lt;/P&gt;</description>
      <pubDate>Wed, 19 Apr 2023 16:56:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-exclude-specific-command-for-privileges-15-user/m-p/4817880#M581292</guid>
      <dc:creator>karenmelkonyanstu</dc:creator>
      <dc:date>2023-04-19T16:56:27Z</dc:date>
    </item>
    <item>
      <title>Re: AAA Exclude specific command for Privileges 15 User</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-exclude-specific-command-for-privileges-15-user/m-p/4817887#M581293</link>
      <description>&lt;P&gt;First define the TACACS server and check reachability using command "test aaa group TACACS-SERVER &amp;lt;username&amp;gt; &amp;lt;password&amp;gt; new-code". Check if the request is reaching the TACACS server. Once confirmed then define remaining AAA commands.&lt;/P&gt;
&lt;P&gt;The configuration looks fine but certain network devices may require some additional attributes to be pushed from TACACS server.&lt;/P&gt;
&lt;P&gt;If this doesn't work, open a case with TAC for further troubleshooting.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Apr 2023 17:08:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-exclude-specific-command-for-privileges-15-user/m-p/4817887#M581293</guid>
      <dc:creator>Nancy Saini</dc:creator>
      <dc:date>2023-04-19T17:08:47Z</dc:date>
    </item>
    <item>
      <title>Re: AAA Exclude specific command for Privileges 15 User</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-exclude-specific-command-for-privileges-15-user/m-p/4818408#M581310</link>
      <description>&lt;P&gt;1)Thanks for the response.&lt;BR /&gt;Just to confirm - when you say "&lt;EM&gt;define remaining AAA Commands&lt;/EM&gt;" you mean to do it on the actual TACACS Server?&lt;BR /&gt;Or do you mean define some other AAA Commands on the router itself?&lt;BR /&gt;My main concern is HOW to prohibit one particular command for a particular user even if he has privilege 15.&lt;BR /&gt;So if I want for a TACACS User Bob to have prohibited "debug ip packet" command&amp;nbsp; - I should do some configuration on the actual TACACS Server?&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;EM&gt;2"The configuration looks fine but certain network devices may require some additional attributes to be pushed from TACACS server."&lt;BR /&gt;&lt;BR /&gt;&lt;/EM&gt;What are those certain network devices ?&lt;/P&gt;</description>
      <pubDate>Thu, 20 Apr 2023 09:24:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-exclude-specific-command-for-privileges-15-user/m-p/4818408#M581310</guid>
      <dc:creator>karenmelkonyanstu</dc:creator>
      <dc:date>2023-04-20T09:24:25Z</dc:date>
    </item>
    <item>
      <title>Re: AAA Exclude specific command for Privileges 15 User</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-exclude-specific-command-for-privileges-15-user/m-p/4818433#M581311</link>
      <description>&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/200208-Configure-ISE-2-0-IOS-TACACS-Authentic.html" target="_blank"&gt;Configure ISE 2.0 TACACS+ Authentication Command Authorization - Cisco&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;in ISE TACACS you can deny/permit any command&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot (636).png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/182459i6BEA2EC621D7FD71/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot (636).png" alt="Screenshot (636).png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Apr 2023 09:33:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-exclude-specific-command-for-privileges-15-user/m-p/4818433#M581311</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-04-20T09:33:39Z</dc:date>
    </item>
    <item>
      <title>Re: AAA Exclude specific command for Privileges 15 User</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-exclude-specific-command-for-privileges-15-user/m-p/4818767#M581320</link>
      <description>&lt;P&gt;To permit or deny commands on ISE, as &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1065752"&gt;@MHM Cisco World&lt;/a&gt;&amp;nbsp; mentioned you have to define under TACACS command set in Policy Elements.&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;"The configuration looks fine but certain network devices may require some additional attributes to be pushed from TACACS server."&lt;/EM&gt; - here I was referring to NXOS platform. It needs certain additional attributes to be pushed in shell profile from ISE. &lt;/P&gt;</description>
      <pubDate>Thu, 20 Apr 2023 17:02:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-exclude-specific-command-for-privileges-15-user/m-p/4818767#M581320</guid>
      <dc:creator>Nancy Saini</dc:creator>
      <dc:date>2023-04-20T17:02:50Z</dc:date>
    </item>
    <item>
      <title>Re: AAA Exclude specific command for Privileges 15 User</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-exclude-specific-command-for-privileges-15-user/m-p/4818989#M581334</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1448937"&gt;@karenmelkonyanstu&lt;/a&gt;&amp;nbsp;- you asked how this could be done without TACACS+.&amp;nbsp; There is a feature called &lt;A href="https://www.cisco.com/en/US/docs/ios/12_3t/12_3t7/feature/guide/gtclivws.html" target="_self"&gt;Role Based CLI&lt;/A&gt; - it's a very old feature but I reckon it's still in IOS today. I have never used it myself. The idea is that you create "views" for a user after they have logged in - and you can be very granular about what that used can see and do.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Apr 2023 03:25:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-exclude-specific-command-for-privileges-15-user/m-p/4818989#M581334</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2023-04-21T03:25:32Z</dc:date>
    </item>
    <item>
      <title>Re: AAA Exclude specific command for Privileges 15 User</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-exclude-specific-command-for-privileges-15-user/m-p/4819194#M581337</link>
      <description>&lt;P&gt;Hi Arne,&lt;BR /&gt;&lt;BR /&gt;Thanks - good to know.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Apr 2023 10:46:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-exclude-specific-command-for-privileges-15-user/m-p/4819194#M581337</guid>
      <dc:creator>karenmelkonyanstu</dc:creator>
      <dc:date>2023-04-21T10:46:21Z</dc:date>
    </item>
  </channel>
</rss>

