cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1049
Views
5
Helpful
3
Replies

ACS 5.x "do" commands in Command Set

MICHAEL BURNS
Level 1
Level 1

I am having an issue allowing "do" show commands in the command set.

 

Specifically I want users to be able to issue:

 

"do show run interface *"

 

I cannot get the "do" portion to work.  Would I have "do show" in the command portion?  Or would I just have "do" in the command portion and "show run interface *" in the argument portion?

 

 

 

***Edit***

I found in ACS logs that ACS sees it come across as "do-exec" instead of just "do".  Using that, I have "do-exec" in the command field and "sh* run" in the argument field.  All good now!

1 Accepted Solution

Accepted Solutions

MICHAEL BURNS
Level 1
Level 1

Solved.

 

ACS sees all "do " commands as "do-exec".  By changing the command to "do-exec" and adding "sh* run" it fixed the issue.

View solution in original post

3 Replies 3

Hi

Do command is present in IOS based device.If get error by trying to using if, probably have no support.

 

 

-If I helped you somehow, please, rate it as useful.-

Arne Bier
VIP
VIP

That's an interesting observation.  Not sure how ACS works but in ISE this is possible, since the command uses wildcards, and the arguments use regular expressions.  I tested this in ISE 2.3

 

ISE-TACACS-do.PNG

PASSED authorization examples:

sh runn

show ru

conf t

exit

do sh ru

do show clock

 

FAILED examples

do reload

show version

 

 

 

 

 

 

MICHAEL BURNS
Level 1
Level 1

Solved.

 

ACS sees all "do " commands as "do-exec".  By changing the command to "do-exec" and adding "sh* run" it fixed the issue.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: