<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: about tacacs privilege level in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/about-tacacs-privilege-level/m-p/4905194#M583434</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- FYI :&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security-vpn/remote-authentication-dial-user-service-radius/13860-PRIV.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security-vpn/remote-authentication-dial-user-service-radius/13860-PRIV.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
    <pubDate>Tue, 15 Aug 2023 07:41:14 GMT</pubDate>
    <dc:creator>Mark Elsen</dc:creator>
    <dc:date>2023-08-15T07:41:14Z</dc:date>
    <item>
      <title>about tacacs privilege level</title>
      <link>https://community.cisco.com/t5/network-access-control/about-tacacs-privilege-level/m-p/4905192#M583433</link>
      <description>&lt;P&gt;I applied the configuration below to the router.&lt;/P&gt;&lt;P&gt;And when i connect to the router, it is authenticated by Tacas and immediately connects to level 15.&lt;/P&gt;&lt;P&gt;I want to start with level 1 and want to login level 15 by using enable command. which config should I fix?&lt;/P&gt;&lt;P&gt;aaa group server tacacs+ A&lt;/P&gt;&lt;P&gt;&amp;nbsp;server name x.x.x.x&lt;/P&gt;&lt;P&gt;&amp;nbsp;ip vrf forwarding mgmt-intf&lt;/P&gt;&lt;P&gt;&amp;nbsp;ip tacacs source-interface GigabitEthernet0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;aaa authentication login default group A local&lt;/P&gt;&lt;P&gt;aaa authentication enable default group A enable&lt;/P&gt;&lt;P&gt;aaa authorization exec default group A local&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;aaa authorization commands 15 default group A local&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;aaa accounting exec A start-stop group A&lt;/P&gt;&lt;P&gt;aaa accounting network A start-stop group A&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;aaa accounting commands 0 default start-stop group A&lt;/P&gt;&lt;P&gt;aaa accounting commands 1 default start-stop group A&lt;/P&gt;&lt;P&gt;aaa accounting commands 5 default start-stop group A&lt;/P&gt;&lt;P&gt;aaa accounting commands 15 default start-stop group A&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;tacacs-server directed-request&lt;/P&gt;&lt;P&gt;tacacs server x&lt;/P&gt;&lt;P&gt;&amp;nbsp;address ipv4 x.x.x.x&lt;/P&gt;&lt;P&gt;&amp;nbsp;key xxxx&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Aug 2023 07:34:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/about-tacacs-privilege-level/m-p/4905192#M583433</guid>
      <dc:creator>tjdwns4111</dc:creator>
      <dc:date>2023-08-15T07:34:41Z</dc:date>
    </item>
    <item>
      <title>Re: about tacacs privilege level</title>
      <link>https://community.cisco.com/t5/network-access-control/about-tacacs-privilege-level/m-p/4905194#M583434</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- FYI :&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security-vpn/remote-authentication-dial-user-service-radius/13860-PRIV.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security-vpn/remote-authentication-dial-user-service-radius/13860-PRIV.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Aug 2023 07:41:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/about-tacacs-privilege-level/m-p/4905194#M583434</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2023-08-15T07:41:14Z</dc:date>
    </item>
    <item>
      <title>Re: about tacacs privilege level</title>
      <link>https://community.cisco.com/t5/network-access-control/about-tacacs-privilege-level/m-p/4905242#M583437</link>
      <description>&lt;P&gt;Hello &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1512569"&gt;@tjdwns4111&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Please remove the 'aaa authorization commands 15 default group A local' line, since you want to start with level 1.&lt;BR /&gt;&lt;BR /&gt;Also, update the 'aaa authorization exec default group A local' line to include the if-authenticated keyword:&lt;BR /&gt;&lt;!-- /data/user/0/com.samsung.android.app.notes/files/clipdata/clipdata_bodytext_230815_120955_715.sdocx --&gt;&lt;/P&gt;&lt;P&gt;aaa authorization exec default group A if-authenticated&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Aug 2023 10:11:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/about-tacacs-privilege-level/m-p/4905242#M583437</guid>
      <dc:creator>M02@rt37</dc:creator>
      <dc:date>2023-08-15T10:11:46Z</dc:date>
    </item>
  </channel>
</rss>

