cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2565
Views
265
Helpful
18
Replies

Unable to do changes - Current privilege level: -1

ziqex
Level 4
Level 4

Hi,

 

I authenticate with the switch with ACS.

Authentication is successful but I am unable to run show run or make change in configure terminal.

sh privilege
User name: testacc
Current privilege level: -1
Feature privilege: Disabled

sh run
% Permission denied for the role

 

Hardware
cisco Nexus5548 Chassis

Reason: Reset Requested by CLI command reload
System version: 7.3(7)N1(1b)

 

 

Please advise how can I resolve it. Thank you.

Regards,

Daniel

 

 

2 Accepted Solutions

Accepted Solutions

IOS works, nexus have network-admin role  

 

check the below config guide and add necessary action :

 

https://www.cisco.com/c/en/us/support/docs/security/secure-access-control-system/115925-nexus-integration-acs-00.html

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

View solution in original post

I managed to add the new rule. I had to switch to the internet explorer as it did not like chrome for some reason. Thank you for all information provided.

View solution in original post

18 Replies 18

balaji.bandi
Hall of Fame
Hall of Fame

Current privilege level: -1 

 

change level to 15

 

https://www.cisco.com/c/en/us/support/docs/security/secure-access-control-system/116236-configure-acs-00.html

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Exactly the same account has privilege 15 on different devices. Thank you.

 

show privilege
Current privilege level is 15

Then what prompt are you in nexus : (another device is nexus ? or IOS ?)

 

> or #

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

On nexus and ios I'm getting logged in directly to #.

 

Whereas for nexus I cannot execute sh run command.

 

Thank you

IOS works, nexus have network-admin role  

 

check the below config guide and add necessary action :

 

https://www.cisco.com/c/en/us/support/docs/security/secure-access-control-system/115925-nexus-integration-acs-00.html

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

ziqex
Level 4
Level 4

I've been following the guide but on the step 5 ACS I cannot create new authorization rule I have only Default rule available and cannot add new one.  Create add below and above is blank. Please advise. Thank you

 

5. Create a new authorization rule, or edit an existing rule, in the correct access policy. By default, TACACS+ requests are processed by the Default Device Admin access policy.

I managed to add the new rule. I had to switch to the internet explorer as it did not like chrome for some reason. Thank you for all information provided.

glad working all good, yes IE is good with ACS, some how cisco ACS not work with chrome as expected (forgot to mentioned)

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

I managed to view the running config after correct value to the shell profile (Value: shell:roles*"network-admin vdc-admin").

Unfortunately, I cannot make any configuration changes as getting the AAA authorisation error.

 

Error: AAA authorization failed AAA_AUTHOR_STATUS_METHOD=16(0x10)

 

Any advice how to resolve it? Thanks

how does your AAA config looks like in nexus add below command :  ( Do not lockup yourself. make sure you have fall back to Locla account)

 

aaa authorization config-commands default group radius_servers  (radisu_servers your group)

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

the current aaa config is as below

 

sh run aaa

!Command: show running-config aaa

version 7.3(7)N1(1b)
aaa authentication login default group ACS_Servers local
aaa authentication login console local
aaa authorization config-commands default group ACS_Servers

Thanks

Can you post ACS_Servers  information

 

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

aaa group server tacacs+ ACS_Servers
server 10.94.1.28
server 10.94.2.30

 

thanks

We have also tried stopping ACS authentication and using local account (authentication was successful but could not make changes) but still could not make changes to the configuration.

 

The local account has role network-admin assigned to it. 

 

Thanks,

Daniel

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: