cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1935
Views
0
Helpful
10
Replies

TACACS

naqibsafi
Level 1
Level 1

hi everyone 

i configure AAA all command deny and permit working will but the specific interface not be deny 

 

10 Replies 10

marce1000
VIP
VIP

 

              - On which platform(/model) are you trying this ?

 M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

i use ISE 3.1

balaji.bandi
Hall of Fame
Hall of Fame

That should work, what ISE version, waht Device is this :

 

check other example as below :

How do you create TACACS+ policies that can be applied to the Network device?

 

https://ciscocustomer.lookbookhq.com/iseguidedjourney/ISE-device-admin-policy-sets

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

i use ISE version 3.1

hslai
Cisco Employee
Cisco Employee

The argument for the interface should replace / with a space character and G should be in capital, like this:

 

GigabitEthernet 1 0 1

 

I try that command also but not work 

Check the T+ livelog or reports and see how the command is coming in as. You may also try capturing the packets and then AskF5: K40341514: How to decrypt the encrypted portion of TACACS+ traffic.

T+ live log

Try 

GigabitEthernet 1\/0\/1

 

marce1000 asked you earlier

> On which platform(/model) are you trying this ?

 

I tried it in one of our lab pods with a Cisco Catalyst 3650 on IOS-XE 3.6.10E and ISE able to reject a command as expected.

I used two command sets when the user logged-in:

1) helpDeskCmds

Screen Shot 2022-06-05 at 15.50.47.png

2) iosSecCmds

Screen Shot 2022-06-05 at 15.52.22.png

When the user issued a command like "interface g1/0/2" and the authZ failed.

3k-access#conf t
Enter configuration commands, one per line.  End with CNTL/Z.
3k-access(config)#interface g1/0/2
Command authorization failed.

The switch I tested sent the command as "interface GigabitEthernet 1 0 2"

 

i try that command in switch 3850 and 3750