02-05-2016 10:33 AM - edited 03-10-2019 11:27 PM
Hi friends!
I'm trying to block users to use the command "configure terminal" using the ACS 5.3, but so far it's not working properly.
On the same Command-Set, if I put any other command (like reload, telnet) and choose Deny, it works fine, but to block the user to enter in configuration mode I'm not able to block yet.
I really appreciate if someone here can help me or if already have passed for this situation.
Thank you!
MOV
Solved! Go to Solution.
02-09-2016 07:32 AM
On the ACS, please use "Deny Configure" and leave the field argument blank. Delete other similar command sets.
On the IOS side, make sure you have
aaa authorization config-commands
02-10-2016 06:35 AM
02-09-2016 07:32 AM
On the ACS, please use "Deny Configure" and leave the field argument blank. Delete other similar command sets.
On the IOS side, make sure you have
aaa authorization config-commands
02-10-2016 02:28 AM
Hi Jatin Katyal!!
I did the test and it is working perfect!!
Really the debug, I could see that router sends the command "configure" when I type "conf, conf t or config", but how I had these parameters inside de command set, I thought it could work.
I really appreciate your help and I hope you've a great day!!
02-10-2016 06:35 AM
Yw & you've a great day too.
~ Jatin
06-15-2020 07:09 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide