cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2348
Views
0
Helpful
2
Replies

ASA 8.2(3): can't "enable" TACACS ACS4.2 user with privilege level 10

Roman Rodichev
Level 7
Level 7

I can't seem to enable in ASA with a non-15 privilege level user configured in ACS 4.2 (tacacs).

When I enable in IOS device, it enables and "show privilege" shows level 10 as expected. ACS should be configured correctly as it works fine with IOS. User is not set with explicit settings. Group is set with "max enable level" 15 and "shell exec priv level" 15. The enable password is set to the internal ACS PAP password. Works fine in IOS.

When I enable in ASA, it fails to enable, and ACS log says "Tacacs+ enable privilege too low". I suspect that ASA tries to enable into level 15 explicitely. If I try to issue "enable 10" command in ASA it says:

Enabling to privilege levels is not allowed when configured for

AAA authentication. Use 'enable' only.

My config (only showing relevant commands):

aaa authentication telnet console mmsacs01 LOCAL

aaa authentication enable console mmsacs01 LOCAL

aaa authorization command mmsacs01 LOCAL

aaa authorization exec authentication-server

Thanks!

1 Accepted Solution

Accepted Solutions

Calvin Ryver
Level 1
Level 1

Set the Enable Options in the grp to

Max Priv for any AAA Client

to

Level 15

this will allow enable and also limit your shell options to 10 and the command set you created

View solution in original post

2 Replies 2

Calvin Ryver
Level 1
Level 1

Set the Enable Options in the grp to

Max Priv for any AAA Client

to

Level 15

this will allow enable and also limit your shell options to 10 and the command set you created

That was it! Thanks a lot!

Roman

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: