<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Command Set Authorization in ACS 5.0 in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/command-set-authorization-in-acs-5-0/m-p/1642766#M7597</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mathew,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From the ACS screenshots, we cannot see any activity in the TACACS+ authorization: this could be the reason why the user is not getting the exec privilege level right after the login.&lt;BR /&gt;As an example, please see the screenshot from a test in my lab when I am assigning exec privilege level 2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you'd like us to troubleshoot the issue a bit deeper, we would need the data from the following steps:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Please log in to the ACS GUI and enable the DEBUG logging level for the module "AAA Diagnostics", under&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;System Administration &amp;gt; Configuration &amp;gt; Log Configuration &amp;gt; Logging Categories &amp;gt; Global&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. Also, please log in to the ACS command line and enable the following debugs:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;admin# acs-config&lt;BR /&gt;Escape character is CNTL/D.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Username: &lt;ACS 5="" gui="" user="" name=""&gt;&lt;BR /&gt;Password: &lt;ACS 5="" gui="" password=""&gt;&lt;/ACS&gt;&lt;/ACS&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;acsadmin(config-acs)# debug-log runtime level debug&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3. On the switch, please enable the following debugs:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;debug aaa authentication&lt;BR /&gt;debug aaa authorization&lt;BR /&gt;debug tacacs&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;4. Now, with the debugs running on both ACS and the switch, please recreate the Tacacs+ authorization issue.&lt;BR /&gt;After having reproduced it, please collect the debugs from the switch and the ACS support bundle from the Monitoring &amp;amp; Report Viewer, under&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Troubleshooting &amp;gt; ACS Support Bundle&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please be sure of collecting the support bundle while checking the following options:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Include full configuration database = Unchecked&lt;BR /&gt;Include debug logs = All&lt;BR /&gt;Include local logs = All&lt;BR /&gt;Include core files = All&lt;BR /&gt;Include monitoring and reporting logs (all categories checked) = Include files from the last 1 day&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, please communicate me the user name tested for the failed authorization and the time stamp when the issue is observed, so that I can track it faster in the logs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;5. As a last info, from the switch, I would like you to please forward me the output of the "show tech".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As mentioned, however, should this require deeper investigations, you may start considering to open an official TAC case:&lt;BR /&gt;&lt;A class="jive-link-external-small" href="http://tools.cisco.com/ServiceRequestTool/create/launch.do"&gt;http://tools.cisco.com/ServiceRequestTool/create/launch.do&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Fede&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;BR /&gt;If&amp;nbsp; this helps you and/or answers your question please mark the question as&amp;nbsp; "answered" and/or rate it, so other users can easily find it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 17 Jan 2011 10:39:23 GMT</pubDate>
    <dc:creator>Federico Ziliotto</dc:creator>
    <dc:date>2011-01-17T10:39:23Z</dc:date>
    <item>
      <title>Command Set Authorization in ACS 5.0</title>
      <link>https://community.cisco.com/t5/network-access-control/command-set-authorization-in-acs-5-0/m-p/1642740#M7563</link>
      <description>&lt;P&gt;Hello Federico,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Attached is what i have done for command authorization for privilege level user 2,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Pls Pls Pls help to get success for this issue as it is pending very long from my end.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 18:25:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/command-set-authorization-in-acs-5-0/m-p/1642740#M7563</guid>
      <dc:creator>estelamathew</dc:creator>
      <dc:date>2020-02-21T18:25:47Z</dc:date>
    </item>
    <item>
      <title>Re: Command Set Authorization in ACS 5.0</title>
      <link>https://community.cisco.com/t5/network-access-control/command-set-authorization-in-acs-5-0/m-p/1642741#M7564</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mathew,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for posting again on CSC.&lt;/P&gt;&lt;P&gt;Could you please confirm what is the issue exactly?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example, are users on privilege level 2 not able to type any debug command?&lt;/P&gt;&lt;P&gt;What is the error message that the switch is returning?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Looking at the ACS configuration, everything looks OK for what concerns the authorization rule.&lt;/P&gt;&lt;P&gt;In the command set however, I could see that the permitted "debug" and "undebug" commands have no arguments.&lt;/P&gt;&lt;P&gt;This could cause users to be authorized to type "debug", but not "debug ip packet" for example.&lt;/P&gt;&lt;P&gt;If you'd like to permit any argument for a specific command, you should make sure to define the argument as a star *&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if this helps,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Fede&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;If&amp;nbsp; this helps you and/or answers your question please mark the question as&amp;nbsp; "answered" and/or rate it, so other users can easily find it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Jan 2011 08:56:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/command-set-authorization-in-acs-5-0/m-p/1642741#M7564</guid>
      <dc:creator>Federico Ziliotto</dc:creator>
      <dc:date>2011-01-10T08:56:18Z</dc:date>
    </item>
    <item>
      <title>Re: Command Set Authorization in ACS 5.0</title>
      <link>https://community.cisco.com/t5/network-access-control/command-set-authorization-in-acs-5-0/m-p/1642742#M7565</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Federico,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Very Happy to see ur reply,hope we will reach to success for this thread.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;For example, are users on privilege level 2 not able to type any debug command? What is the error message that the switch is returning?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; when user login by his username and password in switch he is in exec mode ( &amp;gt;)&amp;nbsp; instead of privilege (#) mode.The username and password and&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; user level 2 are set on ACS not configured in switch.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;I wanna authorize some commands for user level 2 denug and undebug&lt;BR /&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;If you'd like to permit any argument for a specific command, you should make sure to define the argument as a star *&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Atleast i should get the privilege (#) prompt to type debug or undebug command&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Jan 2011 20:20:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/command-set-authorization-in-acs-5-0/m-p/1642742#M7565</guid>
      <dc:creator>estelamathew</dc:creator>
      <dc:date>2011-01-10T20:20:18Z</dc:date>
    </item>
    <item>
      <title>Re: Command Set Authorization in ACS 5.0</title>
      <link>https://community.cisco.com/t5/network-access-control/command-set-authorization-in-acs-5-0/m-p/1642743#M7566</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mathew,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you are assigning privilege level 2 to users, it is expected that the first prompt will be the one for the exec mode (&amp;gt;).&lt;/P&gt;&lt;P&gt;In order to enter the privilege mode you'd need to type the "enable" command.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Only users in privilege mode 15 could be expected to be prompted for the enable mode directly (#).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Fede&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;If&amp;nbsp; this helps you and/or answers your question please mark the question as&amp;nbsp; "answered" and/or rate it, so other users can easily find it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Jan 2011 07:38:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/command-set-authorization-in-acs-5-0/m-p/1642743#M7566</guid>
      <dc:creator>Federico Ziliotto</dc:creator>
      <dc:date>2011-01-11T07:38:17Z</dc:date>
    </item>
    <item>
      <title>Re: Command Set Authorization in ACS 5.0</title>
      <link>https://community.cisco.com/t5/network-access-control/command-set-authorization-in-acs-5-0/m-p/1642744#M7567</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Federico,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When i execute a command &lt;SPAN style="color: #ff0000;"&gt;username cisco privilege 2 password cisco&lt;/SPAN&gt; on switch it direct drops me in privilege mode of level 2 (#)&amp;nbsp; BUT when the user is &lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;only&lt;/STRONG&gt;&lt;/SPAN&gt; configured in ACS then it drops me in (&amp;gt;) ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If i agree on your above words then i don't see any debug and undebug commands in ( &amp;gt;) mode for the particular user level 2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Jan 2011 07:50:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/command-set-authorization-in-acs-5-0/m-p/1642744#M7567</guid>
      <dc:creator>estelamathew</dc:creator>
      <dc:date>2011-01-11T07:50:55Z</dc:date>
    </item>
    <item>
      <title>Re: Command Set Authorization in ACS 5.0</title>
      <link>https://community.cisco.com/t5/network-access-control/command-set-authorization-in-acs-5-0/m-p/1642745#M7568</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mathew,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If possible, would you mind attaching the configuration from your switch?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Usually, debug commands for privilege level 2 users should be available after entering the enable mode.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Fede&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;If&amp;nbsp; this helps you and/or answers your question please mark the question as&amp;nbsp; "answered" and/or rate it, so other users can easily find it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Jan 2011 08:21:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/command-set-authorization-in-acs-5-0/m-p/1642745#M7568</guid>
      <dc:creator>Federico Ziliotto</dc:creator>
      <dc:date>2011-01-11T08:21:20Z</dc:date>
    </item>
    <item>
      <title>Re: Command Set Authorization in ACS 5.0</title>
      <link>https://community.cisco.com/t5/network-access-control/command-set-authorization-in-acs-5-0/m-p/1642746#M7570</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Federico,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Attached are the switch configs related to AAA,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Usually, debug commands for privilege level 2 users should be available after entering the enable mode.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But i m not able to get into enable mode after putting username and password it gives me (&amp;gt;) prompt please see in the attached.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Jan 2011 11:25:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/command-set-authorization-in-acs-5-0/m-p/1642746#M7570</guid>
      <dc:creator>estelamathew</dc:creator>
      <dc:date>2011-01-11T11:25:46Z</dc:date>
    </item>
    <item>
      <title>Re: Command Set Authorization in ACS 5.0</title>
      <link>https://community.cisco.com/t5/network-access-control/command-set-authorization-in-acs-5-0/m-p/1642747#M7573</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mathew,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In order to also enable authorization for commands on privilege level 2, you should add the following line to the switch:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authorization commands 2 rus group tacacs+&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;line vty 0 4&lt;/P&gt;&lt;P&gt;authorization commands 2 rus&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;or simply&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authorization commands 2 default group tacacs+&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Before playing with commands authorization, you may want to save the config on the switch (write memory). In case you'd accidently kick you out of command authorization, you could simply reload the switch so that you'll loose only the latest commands authorization changes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regarding the enable mode (#), when you are at the &amp;gt; prompt, please type "enable" and then enter.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Fede&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;If&amp;nbsp; this helps you and/or answers your question please mark the question as&amp;nbsp; "answered" and/or rate it, so other users can easily find it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Jan 2011 11:34:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/command-set-authorization-in-acs-5-0/m-p/1642747#M7573</guid>
      <dc:creator>Federico Ziliotto</dc:creator>
      <dc:date>2011-01-11T11:34:00Z</dc:date>
    </item>
    <item>
      <title>Re: Command Set Authorization in ACS 5.0</title>
      <link>https://community.cisco.com/t5/network-access-control/command-set-authorization-in-acs-5-0/m-p/1642748#M7575</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Federico,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regarding the enable mode (#), when you are at the &amp;gt; prompt, please type "enable" and then enter.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It does'nt accepts,without any password,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Jan 2011 13:20:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/command-set-authorization-in-acs-5-0/m-p/1642748#M7575</guid>
      <dc:creator>estelamathew</dc:creator>
      <dc:date>2011-01-11T13:20:06Z</dc:date>
    </item>
    <item>
      <title>Re: Command Set Authorization in ACS 5.0</title>
      <link>https://community.cisco.com/t5/network-access-control/command-set-authorization-in-acs-5-0/m-p/1642749#M7576</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mathew,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let's quickly take a step backwards.&lt;/P&gt;&lt;P&gt;I quickly tested a simple config in our lab that, ported to your "rus" method, it should look like the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authentication login rus group tacacs+&lt;/P&gt;&lt;P&gt;aaa authorization exec rus group tacacs+&lt;/P&gt;&lt;P&gt;aaa authorization commands 0 rus group tacacs+&lt;/P&gt;&lt;P&gt;aaa authorization commands 1 rus group tacacs+&lt;/P&gt;&lt;P&gt;aaa authorization commands 2 rus group tacacs+&lt;/P&gt;&lt;P&gt;aaa authorization commands 15 rus group tacacs+&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;line vty 0 4&lt;/P&gt;&lt;P&gt; authorization commands 0 rus&lt;/P&gt;&lt;P&gt; authorization commands 1 rus&lt;/P&gt;&lt;P&gt; authorization commands 2 rus&lt;/P&gt;&lt;P&gt; authorization commands 15 rus&lt;/P&gt;&lt;P&gt; authorization exec rus&lt;/P&gt;&lt;P&gt; login authentication rus&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On ACS, the shell profile with privilege level 2 and command set for "debug .*" should be the one to use. So please be sure that under the argument of the debug command in the ACS command set you specify '.*' that means any argument.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, please note that "debug" commands on the switch are not available under privilege level 2 by default. So we'd also need to move the "debug" commands and all the needed arguments under privilege level 2:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;privilege exec level 2 debug radius&lt;/P&gt;&lt;P&gt;privilege exec level 2 debug aaa authentication&lt;/P&gt;&lt;P&gt;privilege exec level 2 debug aaa authorization&lt;/P&gt;&lt;P&gt;etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if this helps,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Fede&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;If&amp;nbsp; this helps you and/or answers your question please mark the question as&amp;nbsp; "answered" and/or rate it, so other users can easily find it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Jan 2011 14:08:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/command-set-authorization-in-acs-5-0/m-p/1642749#M7576</guid>
      <dc:creator>Federico Ziliotto</dc:creator>
      <dc:date>2011-01-11T14:08:23Z</dc:date>
    </item>
    <item>
      <title>Re: Command Set Authorization in ACS 5.0</title>
      <link>https://community.cisco.com/t5/network-access-control/command-set-authorization-in-acs-5-0/m-p/1642750#M7578</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Federico,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Very Nice Example,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;From ur example and attched PDF files i came to know that We have to apply&amp;nbsp; privilege level commands on switch as well as on ACS server so that's the reason i was not able to authorize the command ??? If we have to apply on both the switch and ACS then why we need ACS server????????&lt;BR /&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;But after applying also i m not able to authenticate (error in authentication ) untill and unless i specify the command &lt;STRONG style="color: #ff0000; "&gt;enable secret level 2 cisco on switch &lt;/STRONG&gt;&lt;SPAN style="color: #000000;"&gt; when i&lt;/SPAN&gt;&lt;STRONG style="color: #ff0000; "&gt; &lt;/STRONG&gt;&lt;SPAN style="color: #000000;"&gt;try to login after username and password it ask's me for enable password , when i put the command switch &amp;gt; enable 2&amp;nbsp; and after than password than only i m placed in privilege level 2 and i m authorize to apply those debug and undebug commands. &lt;SPAN style="color: #ff0000;"&gt;pls have a look on the attached.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;On ACS server when i create the username there are two options for password 1st option is user's password and 2nd option is enable password, this enable password specify to which level ???&amp;nbsp; I tried putting level 2 password but not accepted when i do telnet.when i apply&lt;STRONG style="color: #ff0000; "&gt; enable secret level 2 cisco on switch &lt;/STRONG&gt;&lt;SPAN style="color: #000000;"&gt;than&lt;/SPAN&gt;&lt;STRONG style="color: #ff0000; "&gt; &lt;/STRONG&gt;&lt;SPAN style="color: #000000;"&gt;only it alllows me to enter in privilege level 2 mode.&lt;/SPAN&gt;&lt;SPAN style="color: #000000;"&gt;&lt;SPAN style="color: #ff0000;"&gt;pls have a look on the attached&lt;/SPAN&gt;.&lt;/SPAN&gt;&lt;SPAN style="color: #000000;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;I have also creted 1 user with username xyz privilege 15 password cisco when the user telnet and put his username and password he is placed in user exec mode ( &amp;gt;) instead of privilege mode (#) of level 15. Again i have to put the enable secret password of level 15 than only the user is placed in privilege 15.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please have a look on the attached PDF files in section Task 4.1, Task 4.3,Task 4.4, Task 4.5,Ur example procedure&amp;nbsp; is same mathching&amp;nbsp; PDF&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Jan 2011 21:27:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/command-set-authorization-in-acs-5-0/m-p/1642750#M7578</guid>
      <dc:creator>estelamathew</dc:creator>
      <dc:date>2011-01-11T21:27:03Z</dc:date>
    </item>
    <item>
      <title>Re: Command Set Authorization in ACS 5.0</title>
      <link>https://community.cisco.com/t5/network-access-control/command-set-authorization-in-acs-5-0/m-p/1642751#M7580</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mathew,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Few clarifications needed here:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. We don't apply the same config for privileges/command on both the ACS and the swith.&lt;/P&gt;&lt;P&gt;On ACS we need to define which commands are allowed in the command set.&lt;/P&gt;&lt;P&gt;On the switch, if you have a user logged in with a certain privilege, and you want to authorize commands that are by default available only on a different privilege, then you need to move those commands to the user's privilege level where you want to have them.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. No need for extra enable passwords on ACS as long as the switch is not configured to ask for one.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please re-attach an updated version of your switch's configuration so to double check that it is aligned with what I tested here.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Fede&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;If&amp;nbsp; this helps you and/or answers your question please mark the question as&amp;nbsp; "answered" and/or rate it, so other users can easily find it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Jan 2011 09:56:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/command-set-authorization-in-acs-5-0/m-p/1642751#M7580</guid>
      <dc:creator>Federico Ziliotto</dc:creator>
      <dc:date>2011-01-12T09:56:56Z</dc:date>
    </item>
    <item>
      <title>Re: Command Set Authorization in ACS 5.0</title>
      <link>https://community.cisco.com/t5/network-access-control/command-set-authorization-in-acs-5-0/m-p/1642752#M7581</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Federico,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;We don't apply the same config for privileges/command on both the ACS and the swith.&lt;P&gt;On ACS we need to define which commands are allowed in the command set.&lt;/P&gt;&lt;P&gt;On&amp;nbsp; the switch, if you have a user logged in with a certain privilege, and&amp;nbsp; you want to authorize commands that are by default available only on a&amp;nbsp; different privilege, then you need to move those commands to the user's&amp;nbsp; privilege level where you want to have them.&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I did'nt understood what are u trying to explain But what i understand is the command set what we r permitting on switch is the same commands we r permitting on ACS, then what is the difference, Attached is the command set what i permitted on ACS and the same commands on switch.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;. No need for extra enable passwords on ACS as long as the switch is not configured to ask for one&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; This enable passord on ACS refers where????&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;version 12.2&lt;BR /&gt;no service pad&lt;BR /&gt;&lt;BR /&gt;enable secret level 2 5 $1$3JuM$Qwx9ZmRixfbsnQ5YvoByh0&lt;BR /&gt;enable secret 5 $1$bHw2$ZGFSLF2ZaYxwn/6wDhf9J.&lt;BR /&gt;!&lt;BR /&gt;username abc password 7 094F5B5E41531A&lt;BR /&gt;username XYZ privilege 15 password 7 00071A150754&lt;BR /&gt;username XXX password 7 06051A76141804&lt;BR /&gt;&lt;BR /&gt;aaa new-model&lt;BR /&gt;aaa authentication login rus group tacacs+ local&lt;BR /&gt;aaa authentication login console none&lt;BR /&gt;aaa authorization exec default group tacacs+&lt;BR /&gt;aaa authorization commands 2 default group tacacs+&lt;BR /&gt;&lt;/LI&gt;&lt;LI&gt;tacacs-server host 10.75.X.X key 7 01100F175804&lt;BR /&gt;tacacs-server directed-request&lt;BR /&gt;radius-server source-ports 1645-1646&lt;BR /&gt;&lt;/LI&gt;&lt;LI&gt;ip tacacs source-interface vlan 120&lt;BR /&gt;&lt;SPAN style="color: #ff0000;"&gt;privilege exec level 2 undebug all&lt;BR /&gt;privilege exec level 2 undebug&lt;BR /&gt;privilege exec level 2 debug all&lt;BR /&gt;privilege exec level 2 debug&lt;/SPAN&gt;&lt;BR /&gt;!&lt;BR /&gt;line con 0&lt;BR /&gt; logging synchronous&lt;BR /&gt; login authentication console&lt;BR /&gt;line vty 0 4&lt;BR /&gt; password 7 03074E5C5E592C&lt;BR /&gt; login authentication rus&lt;BR /&gt;line vty 5 15&lt;BR /&gt; password 7 000706515C0D06&lt;BR /&gt; login authentication rus&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Jan 2011 07:44:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/command-set-authorization-in-acs-5-0/m-p/1642752#M7581</guid>
      <dc:creator>estelamathew</dc:creator>
      <dc:date>2011-01-13T07:44:38Z</dc:date>
    </item>
    <item>
      <title>Re: Command Set Authorization in ACS 5.0</title>
      <link>https://community.cisco.com/t5/network-access-control/command-set-authorization-in-acs-5-0/m-p/1642753#M7582</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you Mathew,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me restate the previous points:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. But what i understand is the command set what we r permitting on switch is the same commands we r permitting on ACS, then what is the difference?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[A] On the switch we are not permitting any set of commands: we are moving the commands that we permit through ACS to the privilege level 2 of the user we want to use.&lt;/P&gt;&lt;P&gt;The commands are permitted by ACS, not by the switch.&lt;/P&gt;&lt;P&gt;But we need to move the "debug" commands on the switch to privilege level 2, otherwise a user on privilege level 2 will not be able to see them.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. The configuration you applied on your switch is not the same that I tested and recommended:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2a) You have&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authentication login rus group tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authentication login console none&lt;/P&gt;&lt;P&gt;aaa authorization exec default group tacacs+&lt;/P&gt;&lt;P&gt;aaa authorization commands 2 default group tacacs+&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This should be changed to&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authentication login rus group tacacs+&lt;/P&gt;&lt;P&gt;aaa authentication login console none&lt;/P&gt;&lt;P&gt;aaa authorization exec rus group tacacs+&lt;/P&gt;&lt;P&gt;aaa authorization commands 0 rus group tacacs+&lt;/P&gt;&lt;P&gt;aaa authorization commands 1 rus group tacacs+&lt;/P&gt;&lt;P&gt;aaa authorization commands 2 rus group tacacs+&lt;/P&gt;&lt;P&gt;aaa authorization commands 15 rus group tacacs+&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2b) You have&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;line vty 0 4&lt;/P&gt;&lt;P&gt;password 7 03074E5C5E592C&lt;/P&gt;&lt;P&gt;login authentication rus&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This should be changed to&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;line vty 0 4&lt;/P&gt;&lt;P&gt;authorization commands 0 rus&lt;/P&gt;&lt;P&gt;authorization commands 1 rus&lt;/P&gt;&lt;P&gt;authorization commands 2 rus&lt;/P&gt;&lt;P&gt;authorization commands 15 rus&lt;/P&gt;&lt;P&gt;authorization exec rus&lt;/P&gt;&lt;P&gt;login authentication rus&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Fede&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;If&amp;nbsp; this helps you and/or answers your question please mark the question as&amp;nbsp; "answered" and/or rate it, so other users can easily find it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Jan 2011 08:26:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/command-set-authorization-in-acs-5-0/m-p/1642753#M7582</guid>
      <dc:creator>Federico Ziliotto</dc:creator>
      <dc:date>2011-01-13T08:26:50Z</dc:date>
    </item>
    <item>
      <title>Re: Command Set Authorization in ACS 5.0</title>
      <link>https://community.cisco.com/t5/network-access-control/command-set-authorization-in-acs-5-0/m-p/1642754#M7583</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Federico,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please be patients with me,and i appreciate for being with me for this thread,GOD Bless U .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;[A] On the switch we are not permitting any set of commands: we are&amp;nbsp; moving the commands that we permit through ACS to the privilege level 2&amp;nbsp; of the user we want to use.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;The commands are permitted by ACS, not by the switch.&lt;/P&gt;&lt;P&gt;But&amp;nbsp; we need to move the "debug" commands on the switch to privilege level&amp;nbsp; 2, otherwise a user on privilege level 2 will not be able to see them.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This can be done without ACS also ???. I can move commands on privilege level 2 and i can give access to certain users on level 2&amp;nbsp; with enable secret password and they can&amp;nbsp; execute the commands.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Here are the configs:&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;BR /&gt;aaa authentication login rus group tacacs+ local&lt;BR /&gt;aaa authentication login console none&lt;BR /&gt;aaa authorization exec rus group tacacs+&lt;BR /&gt;aaa authorization commands 2 rus group tacacs+&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;privilege exec level 2 undebug all&lt;BR /&gt;privilege exec level 2 undebug&lt;BR /&gt;privilege exec level 2 debug all&lt;BR /&gt;privilege exec level 2 debug&lt;BR /&gt;!&lt;BR /&gt;line con 0&lt;BR /&gt; logging synchronous&lt;BR /&gt; login authentication console&lt;BR /&gt;line vty 0 4&lt;BR /&gt; password 7 03074E5C5E592C&lt;BR /&gt; authorization commands 2 rus&lt;BR /&gt; authorization exec rus&lt;BR /&gt; login authentication rus&lt;BR /&gt;line vty 5 15&lt;BR /&gt; password 7 000706515C0D06&lt;BR /&gt; login authentication rus&lt;/P&gt;&lt;P&gt;authorization commands 2 rus&lt;BR /&gt;&amp;nbsp; authorization exec rus&lt;BR /&gt;!&lt;BR /&gt;end&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Federico the privilege commands are very much FAR for me i can't even go to the (#) prompt after appying username and password. Just have a look below.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;BR /&gt;username:cisco&lt;BR /&gt;password:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Class_room_105&amp;gt;en&amp;nbsp;&amp;nbsp; &lt;SPAN style="color: #ff0000;"&gt;????&amp;nbsp; (this is were i m stuck to give password which password i shld give here if i dont create a enable secret level 2 password&lt;/SPAN&gt;)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Jan 2011 10:02:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/command-set-authorization-in-acs-5-0/m-p/1642754#M7583</guid>
      <dc:creator>estelamathew</dc:creator>
      <dc:date>2011-01-13T10:02:35Z</dc:date>
    </item>
    <item>
      <title>Re: Command Set Authorization in ACS 5.0</title>
      <link>https://community.cisco.com/t5/network-access-control/command-set-authorization-in-acs-5-0/m-p/1642755#M7584</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mathew,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you please align 100% your configuration with mine?&lt;/P&gt;&lt;P&gt;You have&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authentication login rus group tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authentication login console none&lt;/P&gt;&lt;P&gt;aaa authorization exec rus group tacacs+&lt;/P&gt;&lt;P&gt;aaa authorization commands 2 rus group tacacs+&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This should be changed to&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authentication login rus group tacacs+&lt;/P&gt;&lt;P&gt;aaa authentication login console none&lt;/P&gt;&lt;P&gt;aaa authorization exec rus group tacacs+&lt;/P&gt;&lt;P&gt;aaa authorization commands 0 rus group tacacs+ (missing)&lt;/P&gt;&lt;P&gt;aaa authorization commands 1 rus group tacacs+ (missing)&lt;/P&gt;&lt;P&gt;aaa authorization commands 2 rus group tacacs+&lt;/P&gt;&lt;P&gt;aaa authorization commands 15 rus group tacacs+ (missing)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You have&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;line vty 0 4&lt;/P&gt;&lt;P&gt;password 7 03074E5C5E592C&lt;/P&gt;&lt;P&gt;authorization commands 2 rus&lt;/P&gt;&lt;P&gt;authorization exec rus&lt;/P&gt;&lt;P&gt;login authentication rus&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This should be changed to&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;line vty 0 4&lt;/P&gt;&lt;P&gt;no password 7 03074E5C5E592C&lt;/P&gt;&lt;P&gt;authorization commands 0 rus (missing)&lt;/P&gt;&lt;P&gt;authorization commands 1 rus (missing)&lt;/P&gt;&lt;P&gt;authorization commands 2 rus&lt;/P&gt;&lt;P&gt;authorization commands 15 rus (missing)&lt;/P&gt;&lt;P&gt;authorization exec rus&lt;/P&gt;&lt;P&gt;login authentication rus&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If this still doesn't work, please collect the following debugs while logging in with a privilege 2 user and trying to go in enable mode:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;debug aaa authentication&lt;/P&gt;&lt;P&gt;debug aaa authorization&lt;/P&gt;&lt;P&gt;debug tacacs&lt;/P&gt;&lt;P&gt;term mon (if connecting via telnet)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Fede&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;If&amp;nbsp; this helps you and/or answers your question please mark the question as&amp;nbsp; "answered" and/or rate it, so other users can easily find it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Jan 2011 10:37:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/command-set-authorization-in-acs-5-0/m-p/1642755#M7584</guid>
      <dc:creator>Federico Ziliotto</dc:creator>
      <dc:date>2011-01-13T10:37:00Z</dc:date>
    </item>
    <item>
      <title>Re: Command Set Authorization in ACS 5.0</title>
      <link>https://community.cisco.com/t5/network-access-control/command-set-authorization-in-acs-5-0/m-p/1642756#M7585</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Federico ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have been kicked out after applying those commands, I can't reload the switch as i m far away any command that can remove those command&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Jan 2011 11:15:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/command-set-authorization-in-acs-5-0/m-p/1642756#M7585</guid>
      <dc:creator>estelamathew</dc:creator>
      <dc:date>2011-01-13T11:15:16Z</dc:date>
    </item>
    <item>
      <title>Re: Command Set Authorization in ACS 5.0</title>
      <link>https://community.cisco.com/t5/network-access-control/command-set-authorization-in-acs-5-0/m-p/1642757#M7586</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mathew,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That's why my recommendation regarding being ready to reload the switch when playing with authorization... &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You may get around this by making sure that you have a user on ACS 5 for which you are passing back privilege level 15 and permitting all the commands.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Fede&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;If&amp;nbsp; this helps you and/or answers your question please mark the question as&amp;nbsp; "answered" and/or rate it, so other users can easily find it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Jan 2011 11:32:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/command-set-authorization-in-acs-5-0/m-p/1642757#M7586</guid>
      <dc:creator>Federico Ziliotto</dc:creator>
      <dc:date>2011-01-13T11:32:24Z</dc:date>
    </item>
    <item>
      <title>Re: Command Set Authorization in ACS 5.0</title>
      <link>https://community.cisco.com/t5/network-access-control/command-set-authorization-in-acs-5-0/m-p/1642758#M7587</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I m trying on different switch.The configs are same as below,as only the group name of tacacs server is changed from rus to sur&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;BR /&gt;aaa authentication login sur group tacacs+ local&lt;BR /&gt;aaa authentication login console none&lt;BR /&gt;aaa authorization exec sur group tacacs+&lt;BR /&gt;aaa authorization commands 2 sur group tacacs+&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;privilege exec level 2 undebug all&lt;BR /&gt;privilege exec level 2 undebug&lt;BR /&gt;privilege exec level 2 debug all&lt;BR /&gt;privilege exec level 2 debug&lt;BR /&gt;!&lt;BR /&gt;line con 0&lt;BR /&gt; logging synchronous&lt;BR /&gt; login authentication console&lt;BR /&gt;line vty 0 4&lt;BR /&gt; password 7 03074E5C5E592C&lt;BR /&gt; authorization commands 2 sur&lt;BR /&gt; authorization exec sur&lt;BR /&gt; login authentication sur&lt;BR /&gt;line vty 5 15&lt;BR /&gt; password 7 000706515C0D06&lt;BR /&gt; login authentication sur&lt;BR /&gt; authorization commands 2 sur&lt;BR /&gt; authorization exec sur&lt;BR /&gt;!&lt;/P&gt;&lt;P&gt;!&lt;BR /&gt;end&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I m getting the same error as such below.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;username:cisco&lt;BR /&gt;password:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Class_room_105&amp;gt;en&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the output.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*Mar 17 07:53:29.817: AAA: parse name=tty2 idb type=-1 tty=-1&lt;BR /&gt;*Mar 17 07:53:29.817: AAA: name=tty2 flags=0x11 type=5 shelf=0 slot=0 adapter=0 port=2 channel=0&lt;BR /&gt;*Mar 17 07:53:29.817: AAA/MEMORY: create_user (0x1BCE4F0) user='NULL' ruser='NULL' ds0=0 port='tty2' rem_addr='10.75.7.130' authen_type=ASCII service=LOGIN priv=1 initial_task_id='0', vrf= (id=0)&lt;BR /&gt;*Mar 17 07:53:29.817: AAA/AUTHEN/START (936946286): port='tty2' list='sur' action=LOGIN service=LOGIN&lt;BR /&gt;*Mar 17 07:53:29.817: AAA/AUTHEN/START (936946286): found list sur&lt;BR /&gt;*Mar 17 07:53:29.817: AAA/AUTHEN/START (936946286): Method=tacacs+ (tacacs+)&lt;BR /&gt;*Mar 17 07:53:29.817: TAC+: send AUTHEN/START packet ver=192 id=936946286&lt;BR /&gt;*Mar 17 07:53:29.817: TAC+: Using default tacacs server-group "tacacs+" list.&lt;BR /&gt;*Mar 17 07:53:29.817: TAC+: Opening TCP/IP to 10.75.7.135/49 timeout=5&lt;BR /&gt;*Mar 17 07:53:29.817: TAC+: Opened TCP/IP handle 0x1B56938 to 10.75.7.135/49 using source 10.75.120.9&lt;BR /&gt;*Mar 17 07:53:29.817: TAC+: 10.75.7.135 (936946286) AUTHEN/START/LOGIN/ASCII queued&lt;BR /&gt;*Mar 17 07:53:30.019: TAC+: (936946286) AUTHEN/START/LOGIN/ASCII processed&lt;BR /&gt;*Mar 17 07:53:30.019: TAC+: ver=192 id=936946286 received AUTHEN status = GETUSER&lt;BR /&gt;*Mar 17 07:53:30.019: AAA/AUTHEN (936946286): status = GETUSER&lt;BR /&gt;*Mar 17 07:53:36.377: AAA/AUTHEN/CONT (936946286): continue_login (user='(undef)')&lt;BR /&gt;*Mar 17 07:53:36.377: AAA/AUTHEN (936946286): status = GETUSER&lt;BR /&gt;*Mar 17 07:53:36.385: AAA/AUTHEN (936946286): Method=tacacs+ (tacacs+)&lt;BR /&gt;*Mar 17 07:53:36.385: TAC+: send AUTHEN/CONT packet id=936946286&lt;BR /&gt;*Mar 17 07:53:36.385: TAC+: 10.75.7.135 (936946286) AUTHEN/CONT queued&lt;BR /&gt;*Mar 17 07:53:36.587: TAC+: (936946286) AUTHEN/CONT processed&lt;BR /&gt;*Mar 17 07:53:36.587: TAC+: ver=192 id=936946286 received AUTHEN status = GETPASS&lt;BR /&gt;*Mar 17 07:53:36.587: AAA/AUTHEN (936946286): status = GETPASS&lt;BR /&gt;*Mar 17 07:53:45.160: AAA/AUTHEN/CONT (936946286): continue_login (user='cisco')&lt;BR /&gt;*Mar 17 07:53:45.160: AAA/AUTHEN (936946286): status = GETPASS&lt;BR /&gt;*Mar 17 07:53:45.160: AAA/AUTHEN (936946286): Method=tacacs+ (tacacs+)&lt;BR /&gt;*Mar 17 07:53:45.160: TAC+: send AUTHEN/CONT packet id=936946286&lt;BR /&gt;*Mar 17 07:53:45.160: TAC+: 10.75.7.135 (936946286) AUTHEN/CONT queued&lt;BR /&gt;*Mar 17 07:53:45.361: TAC+: (936946286) AUTHEN/CONT processed&lt;BR /&gt;*Mar 17 07:53:45.361: TAC+: ver=192 id=936946286 received AUTHEN status = PASS&lt;BR /&gt;*Mar 17 07:53:45.361: AAA/AUTHEN (936946286): status = PASS&lt;BR /&gt;*Mar 17 07:53:45.361: TAC+: Closing TCP/IP 0x1B56938 connection to 10.75.7.135/49&lt;BR /&gt;*Mar 17 07:53:45.361: tty2 AAA/AUTHOR/EXEC (2947805954): Port='tty2' list='sur' service=EXEC&lt;BR /&gt;*Mar 17 07:53:45.361: AAA/AUTHOR/EXEC: tty2 (2947805954) user='cisco'&lt;BR /&gt;*Mar 17 07:53:45.361: tty2 AAA/AUTHOR/EXEC (2947805954): send AV service=shell&lt;BR /&gt;*Mar 17 07:53:45.361: tty2 AAA/AUTHOR/EXEC (2947805954): send AV cmd*&lt;BR /&gt;*Mar 17 07:53:45.361: tty2 AAA/AUTHOR/EXEC (2947805954): found list "sur"&lt;BR /&gt;*Mar 17 07:53:45.361: tty2 AAA/AUTHOR/EXEC (2947805954): Method=tacacs+ (tacacs+)&lt;BR /&gt;*Mar 17 07:53:45.361: AAA/AUTHOR/TAC+: (2947805954): user=cisco&lt;BR /&gt;*Mar 17 07:53:45.361: AAA/AUTHOR/TAC+: (2947805954): send AV service=shell&lt;BR /&gt;*Mar 17 07:53:45.361: AAA/AUTHOR/TAC+: (2947805954): send AV cmd*&lt;BR /&gt;*Mar 17 07:53:45.361: TAC+: using previously set server 10.75.7.135 from group tacacs+&lt;BR /&gt;*Mar 17 07:53:45.361: TAC+: Opening TCP/IP to 10.75.7.135/49 timeout=5&lt;BR /&gt;*Mar 17 07:53:45.361: TAC+: Opened TCP/IP handle 0x1B1D86C to 10.75.7.135/49 using source 10.75.120.9&lt;BR /&gt;*Mar 17 07:53:45.361: TAC+: Opened 10.75.7.135 index=1&lt;BR /&gt;*Mar 17 07:53:45.361: TAC+: 10.75.7.135 (2947805954) AUTHOR/START queued&lt;BR /&gt;*Mar 17 07:53:45.563: TAC+: (2947805954) AUTHOR/START processed&lt;BR /&gt;*Mar 17 07:53:45.563: TAC+: (2947805954): received author response status = PASS_ADD&lt;BR /&gt;*Mar 17 07:53:45.563: TAC+: Closing TCP/IP 0x1B1D86C connection to 10.75.7.135/49&lt;BR /&gt;*Mar 17 07:53:45.563: AAA/AUTHOR (2947805954): Post authorization status = PASS_ADD&lt;BR /&gt;*Mar 17 07:53:45.563: AAA/AUTHOR/EXEC: Authorization successful&lt;BR /&gt;&lt;SPAN&gt;*Mar 17 07:53:51.233: %SYS-4-CONFIG_RESOLVE_FAILURE: System config parse from (t&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="ftp://255.255.255.255/network-confg"&gt;ftp://255.255.255.255/network-confg&lt;/A&gt;&lt;SPAN&gt;) failed&lt;/SPAN&gt;&lt;BR /&gt;*Mar 17 07:53:59.244: AAA/MEMORY: dup_user (0x1B3011C) user='cisco' ruser='NULL' ds0=0 port='tty2' rem_addr='10.75.7.130' authen_type=ASCII service=ENABLE priv=15 source='AAA dup enable'&lt;BR /&gt;*Mar 17 07:53:59.244: AAA/AUTHEN/START (3747472480): port='tty2' list='sur' action=LOGIN service=ENABLE&lt;BR /&gt;*Mar 17 07:53:59.244: AAA/AUTHEN/START (3747472480): non-console enable - default to enable password&lt;BR /&gt;*Mar 17 07:53:59.244: AAA/AUTHEN/START (3747472480): Method=ENABLE&lt;BR /&gt;*Mar 17 07:53:59.244: AAA/AUTHEN (3747472480): status = GETPASS&lt;BR /&gt;*Mar 17 07:54:07.037: AAA/AUTHEN/CONT (3747472480): continue_login (user='(undef)')&lt;BR /&gt;*Mar 17 07:54:07.037: AAA/AUTHEN (3747472480): status = GETPASS&lt;BR /&gt;*Mar 17 07:54:07.037: AAA/AUTHEN/CONT (3747472480): Method=ENABLE&lt;BR /&gt;*Mar 17 07:54:07.054: AAA/AUTHEN (3747472480): password incorrect&lt;BR /&gt;*Mar 17 07:54:07.054: AAA/AUTHEN (3747472480): status = FAIL&lt;BR /&gt;*Mar 17 07:54:07.054: AAA/MEMORY: free_user (0x1B3011C) user='NULL' ruser='NULL' port='tty2' rem_addr='10.75.7.130' authen_type=ASCII service=ENABLE priv=15&lt;BR /&gt;&lt;SPAN&gt;*Mar 17 07:54:15.275: %SYS-4-CONFIG_RESOLVE_FAILURE: System config parse from (t&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="ftp://255.255.255.255/cisconet.cfg"&gt;ftp://255.255.255.255/cisconet.cfg&lt;/A&gt;&lt;SPAN&gt;) failed&lt;/SPAN&gt;&lt;BR /&gt;*Mar 17 07:54:28.579: AAA/MEMORY: free_user (0x1BCE4F0) user='cisco' ruser='NULL' port='tty2' rem_addr='10.75.7.130' authen_type=ASCII service=LOGIN priv=1&lt;BR /&gt;&lt;SPAN&gt;*Mar 17 07:54:34.275: %SYS-4-CONFIG_RESOLVE_FAILURE: System config parse from (t&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="ftp://255.255.255.255/lab_7_sw1-confg"&gt;ftp://255.255.255.255/lab_7_sw1-confg&lt;/A&gt;&lt;SPAN&gt;) failed&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;*Mar 17 07:54:58.317: %SYS-4-CONFIG_RESOLVE_FAILURE: System config parse from (t&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="ftp://255.255.255.255/lab_7_sw.cfg"&gt;ftp://255.255.255.255/lab_7_sw.cfg&lt;/A&gt;&lt;SPAN&gt;) failed&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Jan 2011 11:58:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/command-set-authorization-in-acs-5-0/m-p/1642758#M7587</guid>
      <dc:creator>estelamathew</dc:creator>
      <dc:date>2011-01-13T11:58:36Z</dc:date>
    </item>
    <item>
      <title>Re: Command Set Authorization in ACS 5.0</title>
      <link>https://community.cisco.com/t5/network-access-control/command-set-authorization-in-acs-5-0/m-p/1642759#M7588</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mathew,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This what I am getting on my switch, up to the # prompt, without typing any commands and without the need to go through the &amp;gt; prompt:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jan 13 14:01:58.400 CET: AAA/BIND(00000075): Bind i/f&lt;/P&gt;&lt;P&gt;Jan 13 14:01:58.400 CET: AAA/AUTHEN/LOGIN (00000075): Pick method list 'MyTacacs'&lt;/P&gt;&lt;P&gt;Jan 13 14:01:58.400 CET: TPLUS: Queuing AAA Authentication request 117 for processing&lt;/P&gt;&lt;P&gt;Jan 13 14:01:58.400 CET: TPLUS: processing authentication start request id 117&lt;/P&gt;&lt;P&gt;Jan 13 14:01:58.400 CET: TPLUS: Authentication start packet created for 117()&lt;/P&gt;&lt;P&gt;Jan 13 14:01:58.408 CET: TPLUS: Using server 10.48.76.77&lt;/P&gt;&lt;P&gt;Jan 13 14:01:58.408 CET: TPLUS(00000075)/0/NB_WAIT/4C8E878: Started 5 sec timeout&lt;/P&gt;&lt;P&gt;Jan 13 14:01:58.408 CET: TPLUS(00000075)/0/NB_WAIT: socket event 2&lt;/P&gt;&lt;P&gt;Jan 13 14:01:58.408 CET: TPLUS(00000075)/0/NB_WAIT: wrote entire 37 bytes request&lt;/P&gt;&lt;P&gt;Jan 13 14:01:58.408 CET: TPLUS(00000075)/0/READ: socket event 1&lt;/P&gt;&lt;P&gt;Jan 13 14:01:58.408 CET: TPLUS(00000075)/0/READ: Would block while reading&lt;/P&gt;&lt;P&gt;Jan 13 14:01:58.408 CET: TPLUS(00000075)/0/READ: socket event 1&lt;/P&gt;&lt;P&gt;Jan 13 14:01:58.408 CET: TPLUS(00000075)/0/READ: read entire 12 header bytes (expect 15 bytes data)&lt;/P&gt;&lt;P&gt;Jan 13 14:01:58.408 CET: TPLUS(00000075)/0/READ: socket event 1&lt;/P&gt;&lt;P&gt;Jan 13 14:01:58.408 CET: TPLUS(00000075)/0/READ: read entire 27 bytes response&lt;/P&gt;&lt;P&gt;Jan 13 14:01:58.408 CET: TPLUS(00000075)/0/4C8E878: Processing the reply packet&lt;/P&gt;&lt;P&gt;Jan 13 14:01:58.408 CET: TPLUS: Received authen response status GET_USER (7)&lt;/P&gt;&lt;P&gt;Jan 13 14:02:02.191 CET: TPLUS: Queuing AAA Authentication request 117 for processing&lt;/P&gt;&lt;P&gt;Jan 13 14:02:02.191 CET: TPLUS: processing authentication continue request id 117&lt;/P&gt;&lt;P&gt;Jan 13 14:02:02.191 CET: TPLUS: Authentication continue packet generated for 117&lt;/P&gt;&lt;P&gt;Jan 13 14:02:02.191 CET: TPLUS(00000075)/0/WRITE/4B830B4: Started 5 sec timeout&lt;/P&gt;&lt;P&gt;Jan 13 14:02:02.191 CET: TPLUS(00000075)/0/WRITE: wrote entire 23 bytes request&lt;/P&gt;&lt;P&gt;Jan 13 14:02:02.191 CET: TPLUS(00000075)/0/READ: socket event 1&lt;/P&gt;&lt;P&gt;Jan 13 14:02:02.191 CET: TPLUS(00000075)/0/READ: read entire 12 header bytes (expect 15 bytes data)&lt;/P&gt;&lt;P&gt;Jan 13 14:02:02.191 CET: TPLUS(00000075)/0/READ: socket event 1&lt;/P&gt;&lt;P&gt;Jan 13 14:02:02.191 CET: TPLUS(00000075)/0/READ: read entire 27 bytes response&lt;/P&gt;&lt;P&gt;Jan 13 14:02:02.191 CET: TPLUS(00000075)/0/4B830B4: Processing the reply packet&lt;/P&gt;&lt;P&gt;Jan 13 14:02:02.191 CET: TPLUS: Received authen response status GET_PASSWORD (8)&lt;/P&gt;&lt;P&gt;Jan 13 14:02:04.289 CET: TPLUS: Queuing AAA Authentication request 117 for processing&lt;/P&gt;&lt;P&gt;Jan 13 14:02:04.289 CET: TPLUS: processing authentication continue request id 117&lt;/P&gt;&lt;P&gt;Jan 13 14:02:04.289 CET: TPLUS: Authentication continue packet generated for 117&lt;/P&gt;&lt;P&gt;Jan 13 14:02:04.289 CET: TPLUS(00000075)/0/WRITE/4B830B4: Started 5 sec timeout&lt;/P&gt;&lt;P&gt;Jan 13 14:02:04.289 CET: TPLUS(00000075)/0/WRITE: wrote entire 22 bytes request&lt;/P&gt;&lt;P&gt;Jan 13 14:02:04.305 CET: TPLUS(00000075)/0/READ: socket event 1&lt;/P&gt;&lt;P&gt;Jan 13 14:02:04.305 CET: TPLUS(00000075)/0/READ: read entire 12 header bytes (expect 6 bytes data)&lt;/P&gt;&lt;P&gt;Jan 13 14:02:04.305 CET: TPLUS(00000075)/0/READ: socket event 1&lt;/P&gt;&lt;P&gt;Jan 13 14:02:04.305 CET: TPLUS(00000075)/0/READ: read entire 18 bytes response&lt;/P&gt;&lt;P&gt;Jan 13 14:02:04.305 CET: TPLUS(00000075)/0/4B830B4: Processing the reply packet&lt;/P&gt;&lt;P&gt;Jan 13 14:02:04.305 CET: TPLUS: Received authen response status PASS (2)&lt;/P&gt;&lt;P&gt;Jan 13 14:02:04.305 CET: AAA/AUTHOR (0x75): Pick method list 'MyTacacs'&lt;/P&gt;&lt;P&gt;Jan 13 14:02:04.305 CET: TPLUS: Queuing AAA Authorization request 117 for processing&lt;/P&gt;&lt;P&gt;Jan 13 14:02:04.305 CET: TPLUS: processing authorization request id 117&lt;/P&gt;&lt;P&gt;Jan 13 14:02:04.305 CET: TPLUS: Protocol set to None .....Skipping&lt;/P&gt;&lt;P&gt;Jan 13 14:02:04.305 CET: TPLUS: Sending AV service=shell&lt;/P&gt;&lt;P&gt;Jan 13 14:02:04.305 CET: TPLUS: Sending AV cmd*&lt;/P&gt;&lt;P&gt;Jan 13 14:02:04.305 CET: TPLUS: Authorization request created for 117(zilli2)&lt;/P&gt;&lt;P&gt;Jan 13 14:02:04.305 CET: TPLUS: using previously set server 10.48.76.77 from group tacacs+&lt;/P&gt;&lt;P&gt;Jan 13 14:02:04.305 CET: TPLUS(00000075)/0/NB_WAIT/41EE6AC: Started 5 sec timeout&lt;/P&gt;&lt;P&gt;Jan 13 14:02:04.314 CET: TPLUS(00000075)/0/NB_WAIT: socket event 2&lt;/P&gt;&lt;P&gt;Jan 13 14:02:04.314 CET: TPLUS(00000075)/0/NB_WAIT: wrote entire 62 bytes request&lt;/P&gt;&lt;P&gt;Jan 13 14:02:04.314 CET: TPLUS(00000075)/0/READ: socket event 1&lt;/P&gt;&lt;P&gt;Jan 13 14:02:04.314 CET: TPLUS(00000075)/0/READ: Would block while reading&lt;/P&gt;&lt;P&gt;Jan 13 14:02:04.322 CET: TPLUS(00000075)/0/READ: socket event 1&lt;/P&gt;&lt;P&gt;Jan 13 14:02:04.331 CET: TPLUS(00000075)/0/READ: read entire 12 header bytes (expect 17 bytes data)&lt;/P&gt;&lt;P&gt;Jan 13 14:02:04.331 CET: TPLUS(00000075)/0/READ: socket event 1&lt;/P&gt;&lt;P&gt;Jan 13 14:02:04.331 CET: TPLUS(00000075)/0/READ: read entire 29 bytes response&lt;/P&gt;&lt;P&gt;Jan 13 14:02:04.331 CET: TPLUS(00000075)/0/41EE6AC: Processing the reply packet&lt;/P&gt;&lt;P&gt;Jan 13 14:02:04.331 CET: TPLUS: Processed AV priv-lvl=2&lt;/P&gt;&lt;P&gt;Jan 13 14:02:04.331 CET: TPLUS: received authorization response for 117: PASS&lt;/P&gt;&lt;P&gt;Jan 13 14:02:04.331 CET: AAA/AUTHOR/EXEC(00000075): processing AV cmd=&lt;/P&gt;&lt;P&gt;Jan 13 14:02:04.331 CET: AAA/AUTHOR/EXEC(00000075): processing AV priv-lvl=2&lt;/P&gt;&lt;P&gt;Jan 13 14:02:04.331 CET: AAA/AUTHOR/EXEC(00000075): Authorization successful&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In your case, what is currently missing is the privilege level passed back by ACS:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jan 13 14:02:04.331 CET: TPLUS(00000075)/0/41EE6AC: Processing the reply packet&lt;/P&gt;&lt;P&gt;Jan 13 14:02:04.331 CET: TPLUS: Processed AV priv-lvl=2&lt;/P&gt;&lt;P&gt;Jan 13 14:02:04.331 CET: TPLUS: received authorization response for 117: PASS&lt;/P&gt;&lt;P&gt;Jan 13 14:02:04.331 CET: AAA/AUTHOR/EXEC(00000075): processing AV cmd=&lt;/P&gt;&lt;P&gt;Jan 13 14:02:04.331 CET: AAA/AUTHOR/EXEC(00000075): processing AV priv-lvl=2&lt;/P&gt;&lt;P&gt;Jan 13 14:02:04.331 CET: AAA/AUTHOR/EXEC(00000075): Authorization successful&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As mentioned, I'd recommend to align your switch's config with mine and to check the authentication and authorization logs on ACS Monitoring&amp;amp;Report under&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Catalog &amp;gt; AAA &amp;gt; TACACS_Authentication&lt;/P&gt;&lt;P&gt;Catalog &amp;gt; AAA &amp;gt; TACACS_Authorization&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Fede&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;If&amp;nbsp; this helps you and/or answers your question please mark the question as&amp;nbsp; "answered" and/or rate it, so other users can easily find it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Jan 2011 12:12:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/command-set-authorization-in-acs-5-0/m-p/1642759#M7588</guid>
      <dc:creator>Federico Ziliotto</dc:creator>
      <dc:date>2011-01-13T12:12:38Z</dc:date>
    </item>
  </channel>
</rss>

