<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hmm, the config looks correct in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/command-authorization-failed-acs-5-6/m-p/2561164#M75227</link>
    <description>&lt;P&gt;Hmm, the config looks correct, especially if it works on one device but fails on the second. Have you tried to issue some debugs and see if you are getting any errors?&lt;/P&gt;

&lt;PRE&gt;
debug aaa authentication
debug aaa authorization
debug tacacs authorization&lt;/PRE&gt;

&lt;P&gt;Also, is there a version of code difference between the two devices? Perhaps you are hitting a bug.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 07 Jan 2015 18:02:24 GMT</pubDate>
    <dc:creator>nspasov</dc:creator>
    <dc:date>2015-01-07T18:02:24Z</dc:date>
    <item>
      <title>command authorization failed ACS 5.6</title>
      <link>https://community.cisco.com/t5/network-access-control/command-authorization-failed-acs-5-6/m-p/2561163#M75226</link>
      <description>&lt;P&gt;I have a new ACS 5.6 appliance set up that uses Active Directory authentication.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I created a shell profile, mapped it to the authorization rule, and then added devices to the system.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The first device I added was able to use ACS to authenticate and authorize users without any issues. In the ACS logs, it shows me log in and get the shell profile/privileges (15).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The second device I added authenticates me, but then I get a "command authorization failed" message every time I try to do something. In the ACS logs, it shows me log in (using AD), and get the same shell profile (level 15). Not sure what the problem is.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here are the AAA settings on the switch&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;aaa authentication login listASH group tacacs+ local&lt;BR /&gt;aaa authentication enable default group tacacs+ enable&lt;BR /&gt;aaa authorization exec listASH group tacacs+ local&lt;BR /&gt;aaa authorization commands 0 default group tacacs+ if-authenticated&lt;BR /&gt;aaa authorization commands 1 default group tacacs+ if-authenticated&lt;BR /&gt;aaa authorization commands 15 default group tacacs+ if-authenticated&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;tacacs-server host 10.1.2.212&lt;BR /&gt;tacacs-server timeout 3&lt;BR /&gt;tacacs-server directed-request&lt;BR /&gt;tacacs-server key &amp;lt;key&amp;gt;&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;line vty 0 4&lt;BR /&gt;access-class vty-access in&lt;BR /&gt;logging synchronous level all&lt;BR /&gt;login authentication listASH&lt;BR /&gt;transport input ssh&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Network connectivity is fine, and obviously, the key works (because I authenticate). Nevertheless, I cannot get proper authorization.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 05:19:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/command-authorization-failed-acs-5-6/m-p/2561163#M75226</guid>
      <dc:creator>Colin Higgins</dc:creator>
      <dc:date>2019-03-11T05:19:30Z</dc:date>
    </item>
    <item>
      <title>Hmm, the config looks correct</title>
      <link>https://community.cisco.com/t5/network-access-control/command-authorization-failed-acs-5-6/m-p/2561164#M75227</link>
      <description>&lt;P&gt;Hmm, the config looks correct, especially if it works on one device but fails on the second. Have you tried to issue some debugs and see if you are getting any errors?&lt;/P&gt;

&lt;PRE&gt;
debug aaa authentication
debug aaa authorization
debug tacacs authorization&lt;/PRE&gt;

&lt;P&gt;Also, is there a version of code difference between the two devices? Perhaps you are hitting a bug.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jan 2015 18:02:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/command-authorization-failed-acs-5-6/m-p/2561164#M75227</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2015-01-07T18:02:24Z</dc:date>
    </item>
  </channel>
</rss>

