<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Difference between authorization command 15 and 1 in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/difference-between-authorization-command-15-and-1/m-p/4824527#M581451</link>
    <description>&lt;P&gt;Hi,&lt;BR /&gt;"aaa authorization commands 15 default group tacacs+ local if-authenticated"&lt;BR /&gt;1)Does above command authorize only level 15 users?&lt;BR /&gt;2)Or does it authorize all level users 0-15(inclusive)?&lt;BR /&gt;3)Or does it authorize only 2-15 levels (inclusive)?&lt;BR /&gt;Im a bit confused with this command becase on routerfreak website , above command is configured along with "aaa authorization commands 15 default group tacacs+ local if-authenticated" as a best practice.&lt;BR /&gt;This makes me think that may be command "aaa authorization commands 15 default group tacacs+ local if-authenticated" auhtorizes ONLY 2-15 level users and best practice also would be to authorize User Exec Mode as well which is level 1&lt;BR /&gt;Please shed a light on this.&lt;/P&gt;&lt;P&gt;AAA Best practice example: &lt;A href="https://www.routerfreak.com/aaa-best-practices/comment-page-1/?unapproved=90953&amp;amp;moderation-hash=2342e87aa47d14b2dcf0af36ed7b3272#comment-90953" target="_blank"&gt;https://www.routerfreak.com/aaa-best-practices/comment-page-1/?unapproved=90953&amp;amp;moderation-hash=2342e87aa47d14b2dcf0af36ed7b3272#comment-90953&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Sat, 29 Apr 2023 09:14:55 GMT</pubDate>
    <dc:creator>karenmelkonyanstu</dc:creator>
    <dc:date>2023-04-29T09:14:55Z</dc:date>
    <item>
      <title>Difference between authorization command 15 and 1</title>
      <link>https://community.cisco.com/t5/network-access-control/difference-between-authorization-command-15-and-1/m-p/4824527#M581451</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;"aaa authorization commands 15 default group tacacs+ local if-authenticated"&lt;BR /&gt;1)Does above command authorize only level 15 users?&lt;BR /&gt;2)Or does it authorize all level users 0-15(inclusive)?&lt;BR /&gt;3)Or does it authorize only 2-15 levels (inclusive)?&lt;BR /&gt;Im a bit confused with this command becase on routerfreak website , above command is configured along with "aaa authorization commands 15 default group tacacs+ local if-authenticated" as a best practice.&lt;BR /&gt;This makes me think that may be command "aaa authorization commands 15 default group tacacs+ local if-authenticated" auhtorizes ONLY 2-15 level users and best practice also would be to authorize User Exec Mode as well which is level 1&lt;BR /&gt;Please shed a light on this.&lt;/P&gt;&lt;P&gt;AAA Best practice example: &lt;A href="https://www.routerfreak.com/aaa-best-practices/comment-page-1/?unapproved=90953&amp;amp;moderation-hash=2342e87aa47d14b2dcf0af36ed7b3272#comment-90953" target="_blank"&gt;https://www.routerfreak.com/aaa-best-practices/comment-page-1/?unapproved=90953&amp;amp;moderation-hash=2342e87aa47d14b2dcf0af36ed7b3272#comment-90953&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Sat, 29 Apr 2023 09:14:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/difference-between-authorization-command-15-and-1/m-p/4824527#M581451</guid>
      <dc:creator>karenmelkonyanstu</dc:creator>
      <dc:date>2023-04-29T09:14:55Z</dc:date>
    </item>
    <item>
      <title>Re: Difference between authorization command 15 and 1</title>
      <link>https://community.cisco.com/t5/network-access-control/difference-between-authorization-command-15-and-1/m-p/4824539#M581452</link>
      <description>&lt;P&gt;&lt;SPAN&gt;2)Or does it authorize all level users 0-15(inclusive)? NO&amp;nbsp;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;3)Or does it authorize only 2-15 levels (inclusive)? Yes this correct&amp;nbsp;&lt;BR /&gt;that why you see&amp;nbsp;&lt;BR /&gt;aaa&amp;nbsp; authz command 1 &amp;lt;&amp;lt;- protect when you go from user0 to level 1&lt;BR /&gt;aaa authz command 15&amp;nbsp; &amp;lt;&amp;lt;- protect when you go from user0 to level 2-15&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 29 Apr 2023 10:19:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/difference-between-authorization-command-15-and-1/m-p/4824539#M581452</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-04-29T10:19:36Z</dc:date>
    </item>
    <item>
      <title>Re: Difference between authorization command 15 and 1</title>
      <link>https://community.cisco.com/t5/network-access-control/difference-between-authorization-command-15-and-1/m-p/4824541#M581453</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp; This is from Cisco site:&lt;/P&gt;
&lt;P&gt;"&lt;/P&gt;
&lt;H2&gt;&lt;A name="t2" target="_blank"&gt;&lt;/A&gt;Privilege Levels&lt;/H2&gt;
&lt;P&gt;By default, there are three command levels on the router:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;privilege level 0—Includes the &lt;STRONG&gt;disable&lt;/STRONG&gt;, &lt;STRONG&gt;enable&lt;/STRONG&gt;, &lt;STRONG&gt;exit&lt;/STRONG&gt;, &lt;STRONG&gt;help&lt;/STRONG&gt;, and &lt;STRONG&gt;logout&lt;/STRONG&gt; commands&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;privilege level 1—Includes all &lt;I&gt;user&lt;/I&gt;-level commands at the &lt;TT&gt;router&amp;gt;&lt;/TT&gt; prompt&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;privilege level 15—Includes all &lt;I&gt;enable&lt;/I&gt;-level commands at the &lt;TT&gt;router&amp;gt;&lt;/TT&gt; prompt"&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;And my conclusion for your query is that, if you use 15, it means all the previous level included&amp;nbsp; For example, if you give someone root privilege, and someone else admin privilege and to another person view-only privilege, the guy with root privilege have all the previous guy privilege included.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;And an interesting explanation about if-authenticated can be found here in the blog in another thread:&lt;/P&gt;
&lt;P&gt;&lt;A title="https://community.cisco.com/t5/network-access-control/if-authenticated/td-p/1248124" href="https://community.cisco.com/t5/network-access-control/if-authenticated/td-p/1248124" target="_self"&gt;https://community.cisco.com/t5/network-access-control/if-authenticated/td-p/1248124&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 29 Apr 2023 10:24:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/difference-between-authorization-command-15-and-1/m-p/4824541#M581453</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2023-04-29T10:24:09Z</dc:date>
    </item>
    <item>
      <title>Re: Difference between authorization command 15 and 1</title>
      <link>https://community.cisco.com/t5/network-access-control/difference-between-authorization-command-15-and-1/m-p/4824542#M581454</link>
      <description>&lt;P&gt;Note :-&lt;BR /&gt;you can check the command effect by&amp;nbsp;&lt;BR /&gt;enable 1 &amp;lt;&amp;lt;- try this&amp;nbsp;&lt;BR /&gt;enable 2-15&amp;lt;&amp;lt;- try this&lt;/P&gt;</description>
      <pubDate>Sat, 29 Apr 2023 10:28:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/difference-between-authorization-command-15-and-1/m-p/4824542#M581454</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-04-29T10:28:55Z</dc:date>
    </item>
    <item>
      <title>Re: Difference between authorization command 15 and 1</title>
      <link>https://community.cisco.com/t5/network-access-control/difference-between-authorization-command-15-and-1/m-p/4824604#M581456</link>
      <description>&lt;P&gt;Thanks everyone for the response.&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/178747"&gt;@Flavio Miranda&lt;/a&gt;&amp;nbsp;Why here is &amp;gt; ,&amp;nbsp; should not it be # ??&lt;BR /&gt;"&lt;EM&gt;privilege level 15—Includes all&amp;nbsp;enable-level commands at the&amp;nbsp;router&lt;STRONG&gt;&amp;gt;&lt;/STRONG&gt;&amp;nbsp;prompt&lt;/EM&gt;"&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 29 Apr 2023 15:08:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/difference-between-authorization-command-15-and-1/m-p/4824604#M581456</guid>
      <dc:creator>karenmelkonyanstu</dc:creator>
      <dc:date>2023-04-29T15:08:36Z</dc:date>
    </item>
    <item>
      <title>Re: Difference between authorization command 15 and 1</title>
      <link>https://community.cisco.com/t5/network-access-control/difference-between-authorization-command-15-and-1/m-p/4828931#M581538</link>
      <description>&lt;P&gt;If the customer has TACACS+, then I tend to give all users Priv15, and based on their Role (SuperAdmin, Change Admin, ReadOnly) perform command authorization. The reason I use priv 15, is because a simple task like "show running-config" is not possible at any other level. Unless I am doing something wrong. Seems that showing the running config is considered a highly privileged thing (which it might be) - but if you have a junior engineer who needs to see the config (and make no changes) then you have to give them priv15 and limit the commands they can access. TACACS+ saves the day for me!&lt;/P&gt;</description>
      <pubDate>Thu, 04 May 2023 20:33:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/difference-between-authorization-command-15-and-1/m-p/4828931#M581538</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2023-05-04T20:33:40Z</dc:date>
    </item>
  </channel>
</rss>

