cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
525
Views
0
Helpful
1
Replies

TACACS+ authorization & pix6.3

matt.walls
Level 1
Level 1

I would like to use TACACS+ authorization for allowing some limited allowed commands for a particular group, on a TACACS+ authenticated user. When i allow the group enable, i can't seem to limit the command level.

aaa-server TACACS_SVR protocol tacacs+

aaa authentication ssh console TACACS_SVR LOCAL

aaa authentication enable TACACS_SVR

aaa authorization command TACACS_SVR

ssh x.x.x.x x.x.x.x outside

ssh timeout 5

1 Reply 1

smahbub
Level 6
Level 6

aaa accounting command level helps enable accounting for all commands at the specified privilege level.Refer the URL

http://www.cisco.com/en/US/products/sw/secursw/ps4911/products_user_guide_chapter09186a00803deb15.html#wp1017641