09-10-2012 03:49 PM - edited 03-10-2019 07:31 PM
I have an ASA 5520 8.2(5) with ACS 5.1, I made the configutation of Authentication and is working well, now how I can configure the authorization and get into the privileged level 15 mode directly.
Thanks.
09-10-2012 03:55 PM
Adrian,
You can not directly get priv 15 access on the ASA, it will always prompt you for the enable password.
Thanks,
Tarik Admani
*Please rate helpful posts*
09-11-2012 06:12 AM
Tarik how I can configure correctly authorization in the ASA because I made the configuration after that I can ingress with the enable password into the privilege mode but I can't execute any command.
Thanks for the help.
09-11-2012 06:15 AM
Adrian,
This is a common issue, it may be related to the authorization profile which doesnt have the command set option visible for you to be able to run any commands.
Please go to your tacacs authorization policy and select the "Customize" button on the bottom right. After seeing the Customize button please see if the "Command Sets" option is moved over from the left to the right. Once you move it over click save.
After that you should see that the command set is set to deny all commands, make the change to permit and that should resolve this issue.
Thanks,
Tarik Admani
*Please rate helpful posts*
09-11-2012 07:46 AM
Tarik, this configuration have to be made in the ACS? Because I have a user enabled like administrator and this user work well with all devices in the network, only I have problem with the ASA.
Thanks.
09-11-2012 01:36 PM
Adrian,
What errors are you seeing on the ASA? You will still need to add priv level 15 in the tacacs response. You just can get straight into exec like you can on the IOS devices (with aaa authorization exec...) you will still have to provide the correct enable password.
Thanks
Tarik Admani
*Please rate helpful posts*
09-11-2012 04:10 PM
I figure out that I need to login twice in the ASA, now for have working well the authorization I am not sure where is the wrong configuration in the ASA or in the ACS.
Thanks.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide