<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic If that user belongs to a in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/exclude-specific-user-from-aaa-authorization-commands/m-p/2635159#M74652</link>
    <description>&lt;P&gt;If that user belongs to a unique group then you can write a policy where "if the user is in group x then return "access_reject" Or return "access_accept" but set the privilege level to "1" and block all commands.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM style="font-size: 14.3999996185303px; background-color: rgb(249, 249, 249);"&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 10 Feb 2015 18:49:26 GMT</pubDate>
    <dc:creator>nspasov</dc:creator>
    <dc:date>2015-02-10T18:49:26Z</dc:date>
    <item>
      <title>Exclude specific user from aaa authorization commands</title>
      <link>https://community.cisco.com/t5/network-access-control/exclude-specific-user-from-aaa-authorization-commands/m-p/2635156#M74645</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am trying to find a solution to exclude specific users from being authorized (AAA command authorization) when entering commands on the switch/router.&lt;/P&gt;&lt;P&gt;We use an AAA setup with Cisco ACS. On the devices we use:&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family: courier new,courier,monospace;"&gt;aaa authorization config-commands&lt;BR /&gt;aaa authorization commands 1 default group tacacs+ local&lt;BR /&gt;aaa authorization commands 5 default group tacacs+ local&lt;BR /&gt;aaa authorization commands 15 default group tacacs+ local&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;is it possible, to exclude an&amp;nbsp; user, say User1, from being command authorized?&lt;/P&gt;&lt;P&gt;In other words, when User1 logs on the switch/router, the switch/router shouldn't check the ACS if User1 is authorized to use this command.&lt;/P&gt;&lt;P&gt;We tried this with method lists in combination with ACL's on the VTY's:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family: courier new,courier,monospace;"&gt;line VTY 0&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family: courier new,courier,monospace;"&gt;access-class 1 in&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family: courier new,courier,monospace;"&gt;line VTY 1&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family: courier new,courier,monospace;"&gt;access-class 2 in&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Let's say, User1 always logs in from a specific IP, which is mentioned in access-list 2, the switch would use the method mentioned within the line vty 1.&lt;/P&gt;&lt;P&gt;But apparently, when a remote connection is being established, the switch/router uses the first VTY which is available, instead of watching which ACL can be matched to the source IP from the User.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does anyone have some tips/tricks how to handle this?&lt;/P&gt;&lt;P&gt;Maybe a custom attribute from the ACS?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 05:25:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/exclude-specific-user-from-aaa-authorization-commands/m-p/2635156#M74645</guid>
      <dc:creator>diondohmen</dc:creator>
      <dc:date>2019-03-11T05:25:48Z</dc:date>
    </item>
    <item>
      <title>Where does the user you are</title>
      <link>https://community.cisco.com/t5/network-access-control/exclude-specific-user-from-aaa-authorization-commands/m-p/2635157#M74648</link>
      <description>&lt;P&gt;Where does the user you are trying to block reside? Locally on the device, AD or in the ACS database?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM style="font-size: 14.3999996185303px; background-color: rgb(249, 249, 249);"&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Feb 2015 02:23:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/exclude-specific-user-from-aaa-authorization-commands/m-p/2635157#M74648</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2015-02-10T02:23:39Z</dc:date>
    </item>
    <item>
      <title>We have a RADIUS backend</title>
      <link>https://community.cisco.com/t5/network-access-control/exclude-specific-user-from-aaa-authorization-commands/m-p/2635158#M74649</link>
      <description>&lt;P&gt;We have a RADIUS backend where the user resides&lt;/P&gt;</description>
      <pubDate>Tue, 10 Feb 2015 07:45:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/exclude-specific-user-from-aaa-authorization-commands/m-p/2635158#M74649</guid>
      <dc:creator>diondohmen</dc:creator>
      <dc:date>2015-02-10T07:45:24Z</dc:date>
    </item>
    <item>
      <title>If that user belongs to a</title>
      <link>https://community.cisco.com/t5/network-access-control/exclude-specific-user-from-aaa-authorization-commands/m-p/2635159#M74652</link>
      <description>&lt;P&gt;If that user belongs to a unique group then you can write a policy where "if the user is in group x then return "access_reject" Or return "access_accept" but set the privilege level to "1" and block all commands.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM style="font-size: 14.3999996185303px; background-color: rgb(249, 249, 249);"&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Feb 2015 18:49:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/exclude-specific-user-from-aaa-authorization-commands/m-p/2635159#M74652</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2015-02-10T18:49:26Z</dc:date>
    </item>
  </channel>
</rss>

