cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1520
Views
0
Helpful
1
Replies

ACS 3.1 Failed Attempt

jamesgef
Level 1
Level 1

We have a PIX firewall with authorization configured on ACS 3.1 so that certain outside users only have web access to only one machine (cmd:http arguments: permit x.x.x.x). It works fine, however, when I look into my Failed Attempts I often get the message:

Authorization Failure Code: Service Denied

Authorization Data: service=shell cmd*

What is this message about? What does "cmd*" mean?

Thanks!

James

1 Reply 1

jsivulka
Level 5
Level 5

I think the message simple means that the user is not authorised to do what he/she is trying to do. For example, a user might be trying to telnet to the router but is not authorized to do so.