I am using CiscoSecure ACS v3.1 and I have 200 switches and routers point to 2 ACS servers using TACACS+ to authenticate and grant management access to 3 network admins I want to limit access for some users to do all show commands and some interface level commands i.e. no shut... but not allow some commands i.e. shutdown and interface, or to do a reload... I have been told this is possible but I havent been able to do this yet.. Also all users use the same enable secret password witch is local to the switches/routers.
Thanks