<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AAA command authorization on Priv 7 in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/aaa-command-authorization-on-priv-7/m-p/5247710#M594228</link>
    <description>&lt;P&gt;did you check link I share?&lt;/P&gt;
&lt;P&gt;&lt;CODE&gt;R1(config)#privilege exec level 7 XXXXXXXXXXXXX&lt;/CODE&gt;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
    <pubDate>Wed, 15 Jan 2025 19:28:42 GMT</pubDate>
    <dc:creator>MHM Cisco World</dc:creator>
    <dc:date>2025-01-15T19:28:42Z</dc:date>
    <item>
      <title>AAA command authorization on Priv 7</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-command-authorization-on-priv-7/m-p/5247601#M594220</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I've setup clearpass as AAA with our cisco devices. I have a group of users that authenticate with priv level 7. I need to add a privlege level 15 command to these users (reload and clear ip *) , how do I accomplish this?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jan 2025 16:56:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-command-authorization-on-priv-7/m-p/5247601#M594220</guid>
      <dc:creator>josephbdelossantos</dc:creator>
      <dc:date>2025-01-15T16:56:02Z</dc:date>
    </item>
    <item>
      <title>Re: AAA command authorization on Priv 7</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-command-authorization-on-priv-7/m-p/5247606#M594221</link>
      <description>&lt;P&gt;&lt;A href="https://notes.networklessons.com/security-privilege-levels-and-command-output" target="_blank" rel="noopener"&gt;https://notes.networklessons.com/security-privilege-levels-and-command-output&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;check this, you need to move command&amp;nbsp; from level &lt;STRONG&gt;15&lt;/STRONG&gt; to level &lt;STRONG&gt;7&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jan 2025 17:54:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-command-authorization-on-priv-7/m-p/5247606#M594221</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-01-15T17:54:31Z</dc:date>
    </item>
    <item>
      <title>Re: AAA command authorization on Priv 7</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-command-authorization-on-priv-7/m-p/5247613#M594222</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/111319"&gt;@josephbdelossantos&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just use the command&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;username "user" privilege 15&amp;nbsp; password&amp;nbsp; "password"&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jan 2025 17:03:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-command-authorization-on-priv-7/m-p/5247613#M594222</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2025-01-15T17:03:43Z</dc:date>
    </item>
    <item>
      <title>Re: AAA command authorization on Priv 7</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-command-authorization-on-priv-7/m-p/5247666#M594224</link>
      <description>&lt;P&gt;Sorry I wasn't clear. I have a tacacs server that authenticates users and puts them on the correct privilege level. I just need to allow certain higher privilege commands to be run by these users aside from the usual priv 7 commands that are available. basically, allowing them all commands on priv 7 + reload and clear ip (but not show run, show start or config mode)&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jan 2025 17:43:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-command-authorization-on-priv-7/m-p/5247666#M594224</guid>
      <dc:creator>josephbdelossantos</dc:creator>
      <dc:date>2025-01-15T17:43:09Z</dc:date>
    </item>
    <item>
      <title>Re: AAA command authorization on Priv 7</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-command-authorization-on-priv-7/m-p/5247677#M594225</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/111319"&gt;@josephbdelossantos&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;This configuration is done on the TACACS side. In ISE for example, you can do something like "&lt;STRONG&gt;Work Centers &amp;gt; Device Administration &amp;gt; Policy Results &amp;gt; TACACS Command Sets"&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;You need to find how to do this in&amp;nbsp;clearpass.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV id="tinyMceEditor_33964637a23713FlavioMiranda_0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jan 2025 17:55:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-command-authorization-on-priv-7/m-p/5247677#M594225</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2025-01-15T17:55:50Z</dc:date>
    </item>
    <item>
      <title>Re: AAA command authorization on Priv 7</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-command-authorization-on-priv-7/m-p/5247682#M594226</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/111319"&gt;@josephbdelossantos&lt;/a&gt; on ClearPass create a TACACS Enforcement Profile, allowing the commands you want those users to run. In the "Service" match against an AD group those specific users are a member of and apply the previously created Enforcement Profile.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jan 2025 18:03:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-command-authorization-on-priv-7/m-p/5247682#M594226</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2025-01-15T18:03:35Z</dc:date>
    </item>
    <item>
      <title>Re: AAA command authorization on Priv 7</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-command-authorization-on-priv-7/m-p/5247707#M594227</link>
      <description>&lt;P&gt;I already have them configured in the tacacs side, I just want to know if I need some AAA command authorization to be configured in the switches.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="josephbdelossantos_0-1736968480041.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/237670iA0799E94C371EDFD/image-size/medium?v=v2&amp;amp;px=400" role="button" title="josephbdelossantos_0-1736968480041.png" alt="josephbdelossantos_0-1736968480041.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jan 2025 19:23:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-command-authorization-on-priv-7/m-p/5247707#M594227</guid>
      <dc:creator>josephbdelossantos</dc:creator>
      <dc:date>2025-01-15T19:23:55Z</dc:date>
    </item>
    <item>
      <title>Re: AAA command authorization on Priv 7</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-command-authorization-on-priv-7/m-p/5247710#M594228</link>
      <description>&lt;P&gt;did you check link I share?&lt;/P&gt;
&lt;P&gt;&lt;CODE&gt;R1(config)#privilege exec level 7 XXXXXXXXXXXXX&lt;/CODE&gt;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jan 2025 19:28:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-command-authorization-on-priv-7/m-p/5247710#M594228</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-01-15T19:28:42Z</dc:date>
    </item>
    <item>
      <title>Re: AAA command authorization on Priv 7</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-command-authorization-on-priv-7/m-p/5247711#M594229</link>
      <description>&lt;P&gt;That works but that doesnt accept any arguments, "reload in X" , clear ip BGP *, etc&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jan 2025 19:45:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-command-authorization-on-priv-7/m-p/5247711#M594229</guid>
      <dc:creator>josephbdelossantos</dc:creator>
      <dc:date>2025-01-15T19:45:12Z</dc:date>
    </item>
    <item>
      <title>Re: AAA command authorization on Priv 7</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-command-authorization-on-priv-7/m-p/5247718#M594230</link>
      <description>&lt;P&gt;move command reload and clear&amp;nbsp;&lt;BR /&gt;then make clearpass permit only clear ip bgp and reload in X&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jan 2025 19:55:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-command-authorization-on-priv-7/m-p/5247718#M594230</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-01-15T19:55:06Z</dc:date>
    </item>
    <item>
      <title>Re: AAA command authorization on Priv 7</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-command-authorization-on-priv-7/m-p/5247750#M594231</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/111319"&gt;@josephbdelossantos&lt;/a&gt; configure aaa authorization on the switch, this instructs the switch to send a request to the TACACS+ server when a command is executed, and permit/deny as per your configuration.&lt;/P&gt;
&lt;P&gt;Refer to the relevant section for the IOS-XE switch configuration in the guide below &lt;A href="https://community.cisco.com/t5/security-knowledge-base/cisco-ise-device-administration-prescriptive-deployment-guide/ta-p/3738365" target="_blank"&gt;https://community.cisco.com/t5/security-knowledge-base/cisco-ise-device-administration-prescriptive-deployment-guide/ta-p/3738365&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Obviously ignore the ISE information, but the switch commands will be the same when using ClearPass as the TACACS server.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jan 2025 21:15:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-command-authorization-on-priv-7/m-p/5247750#M594231</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2025-01-15T21:15:07Z</dc:date>
    </item>
    <item>
      <title>Re: AAA command authorization on Priv 7</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-command-authorization-on-priv-7/m-p/5247752#M594232</link>
      <description>&lt;P&gt;thats the problem, moving reload doesnt allow you to specify any arguments in the switch even with permitting said arguments in clearpass...&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jan 2025 21:29:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-command-authorization-on-priv-7/m-p/5247752#M594232</guid>
      <dc:creator>josephbdelossantos</dc:creator>
      <dc:date>2025-01-15T21:29:16Z</dc:date>
    </item>
    <item>
      <title>Re: AAA command authorization on Priv 7</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-command-authorization-on-priv-7/m-p/5247785#M594233</link>
      <description>&lt;P&gt;Rob, do I still need to list down all the priv 15 commands I want priv 7 users to be able to execute regardless of what I permit in clearpass? I think clearpass only checks commands to allow to execute but the actual command still need to be executable at that priv level, meaning I still need to configure&amp;nbsp;&lt;SPAN&gt;privilege exec level 7 reload , priv exec level 7 show run, etc on the switches..&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jan 2025 23:46:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-command-authorization-on-priv-7/m-p/5247785#M594233</guid>
      <dc:creator>josephbdelossantos</dc:creator>
      <dc:date>2025-01-15T23:46:27Z</dc:date>
    </item>
    <item>
      <title>Re: AAA command authorization on Priv 7</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-command-authorization-on-priv-7/m-p/5247787#M594234</link>
      <description>&lt;P&gt;hey MHM, I also tried adding the show running-config, the link does say that it executes perfectly but it wont show it because of the current priv level security, is there a way to get around that? Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jan 2025 23:53:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-command-authorization-on-priv-7/m-p/5247787#M594234</guid>
      <dc:creator>josephbdelossantos</dc:creator>
      <dc:date>2025-01-15T23:53:01Z</dc:date>
    </item>
    <item>
      <title>Re: AAA command authorization on Priv 7</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-command-authorization-on-priv-7/m-p/5248007#M594241</link>
      <description>&lt;P&gt;Solution need clearpass and sw&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1-Sw will move only ""reload"" and ""clear""&lt;/P&gt;
&lt;P&gt;2-Sw config for command authz via clearpass&amp;nbsp;&lt;/P&gt;
&lt;P&gt;3-Clearpasd authz only part of clear' like clear ip bgp*&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You do step3 and missing do step1 and 2&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jan 2025 09:35:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-command-authorization-on-priv-7/m-p/5248007#M594241</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-01-16T09:35:45Z</dc:date>
    </item>
  </channel>
</rss>

