cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
338
Views
0
Helpful
2
Replies

Cisco ISE TACACS Query

sondevi
Cisco Employee
Cisco Employee

Hi Team,

I have query regarding ISE TACACS device admin configuration:

1. what is the difference between "Default Priv" and "Max priv" levels in shell profile.

2. for a CU deployment, just to make the easy deployment, can we restrict only on basis of command sets for different users access group and configure the single shell profile with static 15/15 value for "Default Priv" and "Max priv" levels. 

I am more in favour of security/restriction over ease ability if defining the different shell profiles can make difference.

1 Accepted Solution

Accepted Solutions

paul
Level 10
Level 10

Yes just sent both to 15 and do command authorization to grant the users what access they need.  I believe the default priv. level is the initial priv level the user is put in.  If the user chooses to elevate (with the enable command as an example) the max priv value is checked to see if that is allowed.  I don't use the concept of priv level any more and everyone gets 15 from the start.

View solution in original post

2 Replies 2

paul
Level 10
Level 10

Yes just sent both to 15 and do command authorization to grant the users what access they need.  I believe the default priv. level is the initial priv level the user is put in.  If the user chooses to elevate (with the enable command as an example) the max priv value is checked to see if that is allowed.  I don't use the concept of priv level any more and everyone gets 15 from the start.

sondevi
Cisco Employee
Cisco Employee

Thanks Paul for quick reply. same thought.