04-21-2013 04:07 AM - edited 03-10-2019 08:20 PM
Hi, All~
Our customer is using ACS 4.2.
They would like to restriction shell command(session) in ACS 4.2.
For examples,
MSFC => 'session slot [slot #] processor [processor #]' => Command authorization failed.
Is this possible to deny for shell 'session' command?
Have a nice weekend.
Thanks.
Bruce Lee
04-21-2013 11:25 PM
Bruce:
If you are running Cisco IOS then yes it is possible.
AFAIK the MSFC runs on 5600 hardware and that runs IOS so I think it is possible for you
look into this example
please rate if useful and let us know if you got any problem with the configuration.
Regards,
Amjad
Rating useful replies is more useful than saying "Thank you"
04-22-2013 05:27 AM
Could you please duplicate the problem and attach/paste the output of
debug tacacs
debug aaa authorization
Jatin Katyal
- Do rate helpful posts -
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide