cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
575
Views
0
Helpful
8
Replies

TACACS implementation Cisco Nexus 9364C Switch NXOS: version 10.4(4)

charles-james
Level 1
Level 1

I recently upgraded a to NXOS version 10.4(4) on a Nexus 9364C  . I used the same TACACS configuration I've been using, but on this pair of switches, after logging in, when I try to do something like Sho run I'm getting '% Permission denied for the role'. I used the same configuration on a pair of Nexus9000 C9336C-FX2 version NXOS 10.4(4). When I log in I'm granted an admin role. But now on the 9364Cs I'm coming in as operator/level 0. I'm using the same config on Nexus 9364C running NXOS: version 9.3(11) with no issues. Is there something unique about using 10.4(4) on a 9364C that could be causing this

AAA configuration on both pair is:

aaa authentication login default group infrasec-tacacs
aaa accounting default group infrasec-tacacs
aaa authentication login ascii-authentication
tacacs-server directed-request
system login block-for 100 attempts 3 within 100

8 Replies 8

M02@rt37
VIP
VIP

Hello @charles-james 

With the command #show user-account, which role is assigned to your user ? Operator like you said ?

Review TACACS+...  I suspect that you should adjust shell command about the role. What is the actual configuration ?

 

 

Best regards
.ı|ı.ı|ı. If This Helps, Please Rate .ı|ı.ı|ı.

charles-james
Level 1
Level 1

roles:network-operator prior to upgrading the IOS it would be priv-0

 

Tacacs don't use attribute like radius' try use radius 

MHM

latakid644
Level 1
Level 1

The Fire Kirin app is primarily designed for Android devices. However, iOS users may be able to access the game through web-based platforms or specialized installers.

Td777
Community Member

Once the <a href="https://td777slot.com/">TD777Game</a> getting on smartphone, then you can easily play multiple games to get unlimited rewards.

Td777
Community Member

TD777Game is one of best game in the list of Betting apps like the b9 game, s9 game etc. This free app you can enjoy some of the best and top class games and also earn free cash. It is super easy to download and register. 

kavendian
Community Member

It sounds like you've encountered a change in role-mapping behavior introduced in NX-OS 10.4(4) on the Nexus 9364C series. While your TACACS configuration remains consistent across multiple models, the role-based access control (RBAC) behavior might be more strict or differently enforced on the 9364C with this newer firmware. Cisco occasionally introduces platform-specific role-mapping or privilege-handling tweaks in newer NX-OS versions, which could explain why you're defaulting to an operator/level 0 role rather than admin. You may need to explicitly configure TACACS role mapping on the switch using tacacs+ role-map settings to assign the correct role based on attributes received from your AAA server. Also, double-check any recent Cisco documentation for changes in how NX-OS 10.4 handles user roles on 9364C platforms. wink old version

kavendian
Community Member

The issue you're facing with the Nexus 9364C running NX-OS 10.4(4), where users are unexpectedly assigned a lower privilege role despite identical TACACS configurations, highlights how software updates can alter underlying behavior—even when configurations remain the same. In this case, it’s likely that role-mapping logic or enforcement policies have changed subtly in NX-OS 10.4(4), especially for newer hardware models like the 9364C. You may need to define explicit role maps using tacacs+ role-map and confirm that the TACACS server is returning the correct roles or attributes. This is a known occurrence with certain NX-OS versions where defaults shift slightly between versions or hardware lines.

Relating this to Snapseed QR codes Aesthetic it’s similar to how a filter or preset works perfectly on one photo but gives unexpected results on another—even though the QR code is the same. Different devices, image resolutions, or Snapseed app versions can interpret the same QR filter preset differently, just like how the same TACACS config behaves differently depending on the NX-OS version or hardware. In both cases, the “input” is the same, but the “environment” causes the result to vary. Knowing this, it's always good to test across all intended platforms before assuming uniform behavior.