<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Since you already have  in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-4-1-shell-command-authorization-set-vlan-configuration/m-p/2447179#M87031</link>
    <description>&lt;P&gt;&lt;SPAN class="marker"&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;Since you already have "unmatched commads" set to DENY and "permit unmatched args" is uncheceked than you don't need explicit "deny access vlan 11". Can you remove it from there and try again.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="marker"&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;In case it doesn't work, please get following information:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="marker"&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;debug aaa authen&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="marker"&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;debug aaa autho&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="marker"&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;debug tacacs&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="marker"&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;Login to ACS &amp;gt; reports and activities &amp;gt; tacacs administration &amp;gt; check what format of the command coming there.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="marker"&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;Regards,&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="marker"&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;Jatin Katyal&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="marker"&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;*Do rate helpful posts*&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 27 Mar 2014 03:21:10 GMT</pubDate>
    <dc:creator>Jatin Katyal</dc:creator>
    <dc:date>2014-03-27T03:21:10Z</dc:date>
    <item>
      <title>ACS 4.1 Shell command Authorization set - VLAN configuration</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-4-1-shell-command-authorization-set-vlan-configuration/m-p/2447178#M87029</link>
      <description>&lt;P&gt;I am looking to limit certain users on which VLANs they can set on switch ports. &amp;nbsp;I have the following configured on the command "switchport":&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;deny access vlan 11&lt;BR /&gt;permit access vlan 10&lt;BR /&gt;permit access vlan 13&lt;BR /&gt;permit access vlan 40&lt;BR /&gt;permit access vlan 50&lt;BR /&gt;permit access vlan 60&lt;BR /&gt;permit access vlan 101&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But it is still allowing "switchport access vlan 11" to be a viable command on that group. &amp;nbsp;I do not have "permit unmatched args" checked and I have the "Unmatched Commands" set to deny. &amp;nbsp;It's as if the "switchport access" portion is being acknowledged but the rest is ignored. &amp;nbsp;Can you only put a single argument per command? &amp;nbsp;If that is the case, I tried adding a command of "vlan" and limiting it similarly to deny 11 and allow the rest, but that also didn't work.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 04:34:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-4-1-shell-command-authorization-set-vlan-configuration/m-p/2447178#M87029</guid>
      <dc:creator>Richard Rowe</dc:creator>
      <dc:date>2019-03-11T04:34:41Z</dc:date>
    </item>
    <item>
      <title>Since you already have</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-4-1-shell-command-authorization-set-vlan-configuration/m-p/2447179#M87031</link>
      <description>&lt;P&gt;&lt;SPAN class="marker"&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;Since you already have "unmatched commads" set to DENY and "permit unmatched args" is uncheceked than you don't need explicit "deny access vlan 11". Can you remove it from there and try again.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="marker"&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;In case it doesn't work, please get following information:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="marker"&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;debug aaa authen&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="marker"&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;debug aaa autho&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="marker"&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;debug tacacs&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="marker"&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;Login to ACS &amp;gt; reports and activities &amp;gt; tacacs administration &amp;gt; check what format of the command coming there.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="marker"&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;Regards,&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="marker"&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;Jatin Katyal&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="marker"&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;*Do rate helpful posts*&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Mar 2014 03:21:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-4-1-shell-command-authorization-set-vlan-configuration/m-p/2447179#M87031</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2014-03-27T03:21:10Z</dc:date>
    </item>
    <item>
      <title>Ahh gezz, I found the problem</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-4-1-shell-command-authorization-set-vlan-configuration/m-p/2447180#M87034</link>
      <description>&lt;P&gt;Ahh gezz, I found the problem after doing the debugs - some of my AAA configuration was missing from the particular switch I was having an issue with.&lt;/P&gt;&lt;P&gt;Thanks for the reply though. &amp;nbsp;Wouldn't have known the right debugging to try so that helps for future troubleshooting.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Mar 2014 11:54:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-4-1-shell-command-authorization-set-vlan-configuration/m-p/2447180#M87034</guid>
      <dc:creator>Richard Rowe</dc:creator>
      <dc:date>2014-03-27T11:54:02Z</dc:date>
    </item>
    <item>
      <title>No worries. Keep posting.</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-4-1-shell-command-authorization-set-vlan-configuration/m-p/2447181#M87038</link>
      <description>&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;No worries. Keep posting.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;Regards,&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;Jatin Katyal&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:verdana,geneva,sans-serif;"&gt;*Do rate helpful posts*&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Mar 2014 13:57:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-4-1-shell-command-authorization-set-vlan-configuration/m-p/2447181#M87038</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2014-03-27T13:57:04Z</dc:date>
    </item>
  </channel>
</rss>

