<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Catalyst 9800 GUI TACACS+ Command Set in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/catalyst-9800-gui-tacacs-command-set/m-p/5012413#M266246</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/146869"&gt;@rezaalikhani&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Try to change Privilege to 1&lt;/P&gt;</description>
    <pubDate>Sat, 03 Feb 2024 16:40:35 GMT</pubDate>
    <dc:creator>Ruben Cocheno</dc:creator>
    <dc:date>2024-02-03T16:40:35Z</dc:date>
    <item>
      <title>Catalyst 9800 GUI TACACS+ Command Set</title>
      <link>https://community.cisco.com/t5/wireless/catalyst-9800-gui-tacacs-command-set/m-p/5012400#M266245</link>
      <description>&lt;P&gt;Hi everybody;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Based on practical studies, Catalyst 9800 WLCs support command authorization for GUI access. Unfortunately, I am currently unable to set up the application of a defined Command Set in ISE for a user in GUI mode. Here is my configuration:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;ISE side:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rezaalikhani_0-1706974521264.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/209531iBA69E20D4CDE9F40/image-size/large?v=v2&amp;amp;px=999" role="button" title="rezaalikhani_0-1706974521264.png" alt="rezaalikhani_0-1706974521264.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rezaalikhani_1-1706974561187.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/209532iB3EC9F69EABF4725/image-size/large?v=v2&amp;amp;px=999" role="button" title="rezaalikhani_1-1706974561187.png" alt="rezaalikhani_1-1706974561187.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rezaalikhani_2-1706974674939.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/209533i4CD6B45879A006A6/image-size/large?v=v2&amp;amp;px=999" role="button" title="rezaalikhani_2-1706974674939.png" alt="rezaalikhani_2-1706974674939.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;WLC side:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rezaalikhani_3-1706974889609.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/209534i0B8D740947F6B882/image-size/large?v=v2&amp;amp;px=999" role="button" title="rezaalikhani_3-1706974889609.png" alt="rezaalikhani_3-1706974889609.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;With the above configuration, when a user in the 'Helpdesks' group logs into the WLC GUI, he has the ability to perform actions equivalent to those of a user with admin privileges.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Is there any essential configuration that I may be overlooking?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 03 Feb 2024 15:43:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/catalyst-9800-gui-tacacs-command-set/m-p/5012400#M266245</guid>
      <dc:creator>rezaalikhani</dc:creator>
      <dc:date>2024-02-03T15:43:58Z</dc:date>
    </item>
    <item>
      <title>Re: Catalyst 9800 GUI TACACS+ Command Set</title>
      <link>https://community.cisco.com/t5/wireless/catalyst-9800-gui-tacacs-command-set/m-p/5012413#M266246</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/146869"&gt;@rezaalikhani&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Try to change Privilege to 1&lt;/P&gt;</description>
      <pubDate>Sat, 03 Feb 2024 16:40:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/catalyst-9800-gui-tacacs-command-set/m-p/5012413#M266246</guid>
      <dc:creator>Ruben Cocheno</dc:creator>
      <dc:date>2024-02-03T16:40:35Z</dc:date>
    </item>
    <item>
      <title>Re: Catalyst 9800 GUI TACACS+ Command Set</title>
      <link>https://community.cisco.com/t5/wireless/catalyst-9800-gui-tacacs-command-set/m-p/5012451#M266247</link>
      <description>&lt;P&gt;I don't think that will be supported as you configured privilege 15 in TACACS profile. Privilege 15 provides full access in this case, the guide mention that any user between privilege level 1 - 14 can only view the "Monitor" tab in the WLC, and any with privilege level 15 will be granted full admin access.&lt;/P&gt;
&lt;P&gt;"&lt;EM&gt;Users with privilege level 15 and a command set that allows specific commands only are not supported. The user can still be able to execute configuration changes through the WebUI&lt;/EM&gt;"&lt;BR /&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/214490-configure-radius-and-tacacs-for-gui-and.html#toc-hId-2036691447" target="_blank"&gt;Configure RADIUS and TACACS+ for GUI and CLI Authentication on 9800 Wireless LAN Controllers - Cisco&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 03 Feb 2024 18:16:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/catalyst-9800-gui-tacacs-command-set/m-p/5012451#M266247</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2024-02-03T18:16:54Z</dc:date>
    </item>
  </channel>
</rss>

