06-01-2012 09:48 AM - edited 03-10-2019 07:09 PM
Hi everyone,
I am in the process of setting up ACS 5.2 for a network and have run into an issue when attempting to apply the following aaa commands to a network device:
aaa authorization exec default group tacacs+ local if-authenticated
aaa authorization commands 1 default group tacacs+ if-authenticated
aaa authorization commands 15 default group tacacs+ local if-authenticated
Once the commands have been applied to the device configuration I get "command authorization failed" when attempting to do anything. Taking a quick look at the TACACS Authorization reports I see a failure reason of "13025 Command failed to match a Permit rule" and under the Selected Command Set "DenyAllCommands" is listed.
After doing a bit of searching, I noticed some articles online that indicate I should be able to specify the appropriate command set to the authorization profile under the Default Device Admin policy. However, when I open up a Device Aministration Authorization Policy, nowhere in the window does it display command sets that I can select from.
Any thoughts? Is there something I'm missing somewhere else? Thank you in advance for your assistance.
Solved! Go to Solution.
06-01-2012 10:28 AM
Hi there,
This is a very common situation, the problem here is that the Command Set option is not enabled by default. You need to customize the Authorization page using the "Customize button" at the bottom right of the page. Move the "Command Set" option to the right and click Submit, check the screenshots below:
After that you will be able to assign the "Command Set" value.
Rate if it helps!
06-01-2012 10:28 AM
Hi there,
This is a very common situation, the problem here is that the Command Set option is not enabled by default. You need to customize the Authorization page using the "Customize button" at the bottom right of the page. Move the "Command Set" option to the right and click Submit, check the screenshots below:
After that you will be able to assign the "Command Set" value.
Rate if it helps!
06-01-2012 02:17 PM
Thank you kindly Mauricio! That remedied the issue and I'm now in business.
Best Regards,
Dan Miller
08-24-2012 08:45 AM
Thank you mauricio!!!, I was like 2 hours trying to figure out by my seft! but I couldnt, Why isnt this option enabled by default!!
08-30-2012 12:44 AM
Thank you, this has helped me a lot!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide