<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic aaa Autorisation commands in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/aaa-autorisation-commands/m-p/164271#M1063967</link>
    <description>&lt;P&gt;Hallo iam trying to configure ACS &amp;amp; my Network devices to restrict the use of some commands for a group of users, i have another group ( Networking group) this group have the privileged level 15 and should be able to do evry thing. The group that i would like to restrict commands for have the name show-commands group.&lt;/P&gt;&lt;P&gt;i configured the following :&lt;/P&gt;&lt;P&gt;on ACS &lt;/P&gt;&lt;P&gt;- i definded a user that ist a member of the group show-commands&lt;/P&gt;&lt;P&gt;- by group TACACS+ Settings i checked  Shell (exec)  and  Privilege level (5)&lt;/P&gt;&lt;P&gt;- by  Shell Command Authorization Set i checked &amp;lt;Assign a Shell Command Authorization Set for any network device&amp;gt; , and used an Authorization Set name &amp;lt;lehrling&amp;gt; that i already configured in shared profiles components.&lt;/P&gt;&lt;P&gt;- Shell Command Authorization Set &amp;lt; lehrling &amp;gt; is configured as follows:&lt;/P&gt;&lt;P&gt;Name : lehrling&lt;/P&gt;&lt;P&gt;Unmatched Commands: - Deny is checked&lt;/P&gt;&lt;P&gt;                                               - permit  unchecked&lt;/P&gt;&lt;P&gt;                                               - permit unmached Args unchecked&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;********************&lt;/P&gt;&lt;P&gt;- in the window on the left hand i put the following commands&lt;/P&gt;&lt;P&gt; Debug &lt;/P&gt;&lt;P&gt;- on the right hand i put deny all&lt;/P&gt;&lt;P&gt;***************&lt;/P&gt;&lt;P&gt;i repeated this for logout, ping and tracerout with nothing in the window on the right hand&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- i put also show on the left hand  and &lt;/P&gt;&lt;P&gt;permit ver&lt;/P&gt;&lt;P&gt;permit running-config&lt;/P&gt;&lt;P&gt;permit ip interface brief&lt;/P&gt;&lt;P&gt;on the right hand&lt;/P&gt;&lt;P&gt;-&lt;/P&gt;&lt;P&gt;On the router i configured the following &lt;/P&gt;&lt;P&gt;&amp;lt; aaa authorization commands 5 default group tacacs+&amp;gt;&lt;/P&gt;&lt;P&gt;i tried also to use the name of the Authorization Set &amp;lt;lehrling&amp;gt; insted of default in the command above.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;for the user in the group show-commands , i see that they the command mentioned above have no effect, and i cann't notice the restrictions that i made.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;what i would like to do is to restrict config terminal for a group but this group should be able to use all other cammands like Debug.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 06:29:55 GMT</pubDate>
    <dc:creator>giaaaj</dc:creator>
    <dc:date>2020-02-21T06:29:55Z</dc:date>
    <item>
      <title>aaa Autorisation commands</title>
      <link>https://community.cisco.com/t5/network-security/aaa-autorisation-commands/m-p/164271#M1063967</link>
      <description>&lt;P&gt;Hallo iam trying to configure ACS &amp;amp; my Network devices to restrict the use of some commands for a group of users, i have another group ( Networking group) this group have the privileged level 15 and should be able to do evry thing. The group that i would like to restrict commands for have the name show-commands group.&lt;/P&gt;&lt;P&gt;i configured the following :&lt;/P&gt;&lt;P&gt;on ACS &lt;/P&gt;&lt;P&gt;- i definded a user that ist a member of the group show-commands&lt;/P&gt;&lt;P&gt;- by group TACACS+ Settings i checked  Shell (exec)  and  Privilege level (5)&lt;/P&gt;&lt;P&gt;- by  Shell Command Authorization Set i checked &amp;lt;Assign a Shell Command Authorization Set for any network device&amp;gt; , and used an Authorization Set name &amp;lt;lehrling&amp;gt; that i already configured in shared profiles components.&lt;/P&gt;&lt;P&gt;- Shell Command Authorization Set &amp;lt; lehrling &amp;gt; is configured as follows:&lt;/P&gt;&lt;P&gt;Name : lehrling&lt;/P&gt;&lt;P&gt;Unmatched Commands: - Deny is checked&lt;/P&gt;&lt;P&gt;                                               - permit  unchecked&lt;/P&gt;&lt;P&gt;                                               - permit unmached Args unchecked&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;********************&lt;/P&gt;&lt;P&gt;- in the window on the left hand i put the following commands&lt;/P&gt;&lt;P&gt; Debug &lt;/P&gt;&lt;P&gt;- on the right hand i put deny all&lt;/P&gt;&lt;P&gt;***************&lt;/P&gt;&lt;P&gt;i repeated this for logout, ping and tracerout with nothing in the window on the right hand&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- i put also show on the left hand  and &lt;/P&gt;&lt;P&gt;permit ver&lt;/P&gt;&lt;P&gt;permit running-config&lt;/P&gt;&lt;P&gt;permit ip interface brief&lt;/P&gt;&lt;P&gt;on the right hand&lt;/P&gt;&lt;P&gt;-&lt;/P&gt;&lt;P&gt;On the router i configured the following &lt;/P&gt;&lt;P&gt;&amp;lt; aaa authorization commands 5 default group tacacs+&amp;gt;&lt;/P&gt;&lt;P&gt;i tried also to use the name of the Authorization Set &amp;lt;lehrling&amp;gt; insted of default in the command above.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;for the user in the group show-commands , i see that they the command mentioned above have no effect, and i cann't notice the restrictions that i made.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;what i would like to do is to restrict config terminal for a group but this group should be able to use all other cammands like Debug.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 06:29:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/aaa-autorisation-commands/m-p/164271#M1063967</guid>
      <dc:creator>giaaaj</dc:creator>
      <dc:date>2020-02-21T06:29:55Z</dc:date>
    </item>
    <item>
      <title>Re: aaa Autorisation commands</title>
      <link>https://community.cisco.com/t5/network-security/aaa-autorisation-commands/m-p/164272#M1063968</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;we are using ACS 3.0 on Windows 2000&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Jan 2003 15:47:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/aaa-autorisation-commands/m-p/164272#M1063968</guid>
      <dc:creator>giaaaj</dc:creator>
      <dc:date>2003-01-16T15:47:54Z</dc:date>
    </item>
  </channel>
</rss>

