06-18-2020 05:11 AM
Hello, we are currently in the migration phase to a catalyst 9800 wlc. I am currently working on the tacacs configuration and I making no progress with setting up the lobby admins tacacs profile.
With the old airos wlc you could simply select "Lobby Admin" in the tacacs profile, but with the new IOSXE-based wlc the profile don't work.
A profile for admin access is working fine at privilege level 15. Can anyone help me with that?
Best regards Jan
Solved! Go to Solution.
06-18-2020 11:15 PM
Set the TACACS to return the following:
Default Privilege: priv-lvl=15
Custom attributes: Type= Mandatory, Name=user-type, Value= lobby-admin
On WLC, configure the username:
aaa remote username <remote-lobby-admin-username>
06-18-2020 09:42 AM
Check if you are running into below issue:
https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvs87163
If the lobby admin user is getting full access?
06-18-2020 10:44 PM
Thanks, I have checked the aaa config and reconfigure the authorization and authentication settings.
But my problem is to configure the tacacs profile and command sets. For admin access it works fine with priv level 15. But for lobby admin access I don´t know what I must configure. For the old airos wlc it was easy to choose the right value, but his won´t work for catalyst 9800 wlc.
If I add a local lobby admin account on the wlc, I see that the user has the following settings.
user-name lobby view LobbyAdminView type lobby-admin
But when I configure this as custom attributes in the tacacs profiles it won´t work.
06-18-2020 11:15 PM
Set the TACACS to return the following:
Default Privilege: priv-lvl=15
Custom attributes: Type= Mandatory, Name=user-type, Value= lobby-admin
On WLC, configure the username:
aaa remote username <remote-lobby-admin-username>
06-19-2020 01:09 AM
Thanks, that works, but I point the authorization policy in the ise config to an active directory group. Must I configure for each user in the group the "aaa remote username"?
06-19-2020 01:36 AM
06-19-2020 01:39 AM
Okay, thanks for your help! Greetings Jan
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide