cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
492
Views
0
Helpful
1
Replies

How to limit config actions with ACS 5.3

howlingthunder
Level 1
Level 1

Seems to me that regardless of the command set that once you allow a user into Config mode all bets are off. I want to allows certain users only certain actions (like assinging ports to a different vlan) but once in Config mode none of them matter, and the user has free reign.

1. Is it even possible to restrict which commands a users has under Config mode?

2. If so, is there a specific way withing ACS 5.3 or on the router/switch itself that this needs to be defined?

Thanks for any help

1 Reply 1

Amjad Abdullah
VIP Alumni
VIP Alumni

Mike - you can create command sets and apply that command sets to whatever user or group of users.

The command sets contains commands that you want to permit and/or deny to the user/group.

Have a look into this:

http://www.cisco.com/en/US/products/ps9911/products_configuration_example09186a0080bc8514.shtml

HTH,

Amjad

Rating useful replies is more useful than saying "Thank you"

Rating useful replies is more useful than saying "Thank you"