<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: problem with command authorisation with acs  in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/problem-with-command-authorisation-with-acs/m-p/506403#M9142</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi thanks. yeah i tried that but it's still ain't working. someone told me that in acs command authorisation will not work for privilege level commands. that we cannot move the level 1 commands from one user to the other.say i have 2 users one at level 5 and other at level 7 . the ping command is available for both the users. so if i move the command from level 5 to level 7 then this command should only be to level 7 user. still level 5 users can execute ping command. i hope u understand the problem i am facing here. i can achieve this from local command authorisation on the router but not with acs server. waiting for ur reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sebastan &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 08 Apr 2006 02:53:30 GMT</pubDate>
    <dc:creator>sebastan_bach</dc:creator>
    <dc:date>2006-04-08T02:53:30Z</dc:date>
    <item>
      <title>problem with command authorisation with acs</title>
      <link>https://community.cisco.com/t5/network-access-control/problem-with-command-authorisation-with-acs/m-p/506401#M9140</link>
      <description>&lt;P&gt;R1 &lt;/P&gt;&lt;P&gt;i have not posted the local aaa config. i am using acs server 3.3 trial version. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authentication login cisco group tacacs+&lt;/P&gt;&lt;P&gt;aaa authoristion exec cisco group tacacs+&lt;/P&gt;&lt;P&gt;aaa authorisation commands 10 cisco group tacacs+&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;line vty 0 4&lt;/P&gt;&lt;P&gt;login authentication cisco&lt;/P&gt;&lt;P&gt;authorisation exec cisco &lt;/P&gt;&lt;P&gt;authorisation commands 10 cisco&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;on the acs server &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i have created user cisco&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;x shell&lt;/P&gt;&lt;P&gt;.priviledge level =10&lt;/P&gt;&lt;P&gt;x per user command authorization&lt;/P&gt;&lt;P&gt;unmatched cisco IOS command: deny&lt;/P&gt;&lt;P&gt;x command&lt;/P&gt;&lt;P&gt;show&lt;/P&gt;&lt;P&gt;arguments: permit ruuning-config&lt;/P&gt;&lt;P&gt;unlisted argument: deny&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;when this user logs in the router . he gets authenticated and authorised as privilege level 10 &lt;/P&gt;&lt;P&gt;but he cannot issue the command show running-config. is this because i am using a trial version.i am not sure abt it. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i am also not able to move commands to higher privilege levels . &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i created a another user with privilege level 14 name john &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;x shell&lt;/P&gt;&lt;P&gt;.priviledge level =14&lt;/P&gt;&lt;P&gt;x per user command authorization&lt;/P&gt;&lt;P&gt;unmatched cisco IOS command: deny&lt;/P&gt;&lt;P&gt;x command&lt;/P&gt;&lt;P&gt;ping &lt;/P&gt;&lt;P&gt;arguments: &lt;/P&gt;&lt;P&gt;unlisted argument: deny&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;with this the ping command should not be available  to the level 10 user but it is. the level 10 user is still able to issue the command. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;can anyone pls help me with this configuration. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sebastan&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 18:15:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problem-with-command-authorisation-with-acs/m-p/506401#M9140</guid>
      <dc:creator>sebastan_bach</dc:creator>
      <dc:date>2020-02-21T18:15:17Z</dc:date>
    </item>
    <item>
      <title>Re: problem with command authorisation with acs</title>
      <link>https://community.cisco.com/t5/network-access-control/problem-with-command-authorisation-with-acs/m-p/506402#M9141</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is happening because by default, all commands are either in level 1 or level 15. The "show runn" command is at level 15 by default. So, if the user is at level 10, he will not be able to execute the "sh runn" command. You need to move the "sh runn" command from existing level 15 to level 10 using the "privilege exec" command.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Apr 2006 15:37:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problem-with-command-authorisation-with-acs/m-p/506402#M9141</guid>
      <dc:creator>vkapoor5</dc:creator>
      <dc:date>2006-04-07T15:37:16Z</dc:date>
    </item>
    <item>
      <title>Re: problem with command authorisation with acs</title>
      <link>https://community.cisco.com/t5/network-access-control/problem-with-command-authorisation-with-acs/m-p/506403#M9142</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi thanks. yeah i tried that but it's still ain't working. someone told me that in acs command authorisation will not work for privilege level commands. that we cannot move the level 1 commands from one user to the other.say i have 2 users one at level 5 and other at level 7 . the ping command is available for both the users. so if i move the command from level 5 to level 7 then this command should only be to level 7 user. still level 5 users can execute ping command. i hope u understand the problem i am facing here. i can achieve this from local command authorisation on the router but not with acs server. waiting for ur reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sebastan &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 08 Apr 2006 02:53:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problem-with-command-authorisation-with-acs/m-p/506403#M9142</guid>
      <dc:creator>sebastan_bach</dc:creator>
      <dc:date>2006-04-08T02:53:30Z</dc:date>
    </item>
  </channel>
</rss>

