01-12-2016 05:10 AM
So we are running into an issue where applying the task list (tacacs) from prime to ACS works for some but not others. What I mean is applying the list to a group within ACS. When I have the admin task applied to my group I can log in but not perform administration. If I remove it I cannot login. When Applying the settings to my individual account I can perform administration. Does anyone have an explanation for this behavior?
virtual-domain0=ROOT-DOMAIN
role0=Admin
task0=Run Job
task1=Device Reports
task2=Raw NetFlow Reports
task3=Network Summary Reports
task4=Discovery View Privilege
task5=Configure ACS View Servers
task6=View Audit Logs Purge Settings Access
task7=Administration Menu Access
task8=Network Topology Edit
task9=Compliance Reports Read Only
task10=Configure Lightweight Access Point Templates
task11=Config Archive Read Task
task12=Monitor Chokepoints
task13=Virtual Domains List
task14=View Compute Devices
task15=Monitor Third Party Controllers and Access Point
task16=Edit Device Access
task17=View Group Members
task18=Migration Templates
task19=Monitor Spectrum Experts
task20=Configure Autonomous Access Point Templates
task21=Audit Trails
task22=Client Location
task23=Delete Device Access
task24=TrustSec Readiness Assessment
task25=PnP Profile Deploy Read-Write Access
task26=Monitor Access Points
task27=Data Collection Management Access
task28=CleanAir Reports
task29=Configure Ethernet Switch Ports
task30=Mobility Service Management
task31=Swim Upgrade Analysis
task32=Help Menu Access
task33=Product Feedback
task34=MSAP Reports
task35=Search Access
task36=Details Dashboard Access
task37=Scheduled Configuration Tasks
task38=Configure WIPS Profiles
task39=Client Reports
task40=Services Menu Access
task41=Report Launch Pad
task42=Latest Config Audit Report
task43=Mesh Reports
task44=Swim Info Update
task45=View Audit Logs Access
task46=Design Monitoring Template Access
task47=Monitor Controllers
task48=Deploy Configuring Access
task49=View Job
task50=Software Updates UBF Upload
task51=Autonomous AP Reports Read Only
task52=Design Configuration Template Access
task53=PnP Preferences Read Access
task54=Security Reports Read Only
task55=SSO Servers
task56=Configure Switch Location Configuration Templates
task57=Configure WiFi TDOA Receivers
task58=Maps Menu Access
task59=Discovery CRUD Privilege
task60=Voice Audit Report
task61=Admin Dashboard Access
task62=Global SSID Groups
task63=PnP Deploy History Read-Write Access
task64=Wireless Dashboard Access
task65=WIPS Service
task66=Security Reports
task67=Application Server Management Access
task68=Monitoring Policies
task69=View Security Index Issues
task70=Swim Access Privilege
task71=Device Bulk Import Access
task72=Home Menu Access
task73=Approve Job
task74=Guest Reports
task75=Logging
task76=Device View configuration Access
task77=Swim Preference Save
task78=Delete and Clear Alerts
task79=Identity Search Engine
task80=Rogue Location
task81=Delete Group Members
task82=PnP Profile Read-Write Access
task83=Tools Menu Access
task84=Configure ISE Servers
task85=Config Audit Dashboard
task86=Virtual Domain Management
task87=Incidents Alarms Events Access
task88=Monitor Ethernet Switches
task89=CleanAir Reports Read Only
task90=Monitor Mobility Devices
task91=Configure Choke Points
task92=MSE Analytics
task93=Swim Delete
task94=Theme Changer Access
task95=Import Policy Update
task96=Design Endpoint Site Association Access
task97=Planning Mode
task98=Configure Menu Access
task99=Deploy Monitoring Template Access
task100=Ack and Unack Alerts
task101=View Alerts and Events
task102=RADIUS Servers
task103=Credential Profile Delete Access
task104=Edit Audit Logs Purge Settings Access
task105=Saved Reports List Read Only
task106=Run Reports List
task107=View CAS Notifications Only
task108=Monitor Clients
task109=Monitor Media Streams
task110=Maps Read Write
task111=Configure Access Points
task112=Mesh Reports Read Only
task113=Users and Groups
task114=Saved Reports List
task115=Swim Collection
task116=Device WorkCenter
task117=Configure Ethernet Switches
task118=Raw NetFlow Reports Read Only
task119=TACACS+ Servers
task120=Edit Job
task121=Autonomous AP Reports
task122=Performance Reports Read Only
task123=Delete Groups
task124=Performance Reports
task125=Configure Controllers
task126=Packet Capture Access
task127=Credential Profile Add_Edit Access
task128=WorkflowsReadWriteAccess
task129=Monitor Tags
task130=Scheduled Tasks and Data Collection
task131=MSAP Reports Read Only
task132=View Groups
task133=Delete Job
task134=Network Topology
task135=Troubleshoot
task136=Configure Templates
task137=System Jobs Tab Access
task138=System Settings
task139=Remove Clients
task140=Performance Dashboard Access
task141=Configure Config Groups
task142=Application and Services Access
task143=Inventory Menu Access
task144=Export Device Access
task145=High Availability Configuration
task146=License Center
task147=Add Group Members
task148=Manage and Monitor Servers Page Access
task149=mDNS Policy Admin
task150=Monitor Security
task151=Monitor Menu Access
task152=Track Clients
task153=Network Summary Reports Read Only
task154=Schedule Job
task155=Export Audit Logs Access
task156=Monitor Interferers
task157=Add Groups
task158=Guest Reports Read Only
task159=Swim Distribution
task160=Cancel Job
task161=PnP Preferences Read-Write Access
task162=Credential Profile View Access
task163=Modify Groups
task164=Report Run History
task165=Maps Read Only
task166=Compliance Reports
task167=Custom NetFlow Reports
task168=Disable Clients
task169=PnP Profile Deploy Read Access
task170=Configure Spectrum Experts
task171=Appliance
task172=Configure Mobility Devices
task173=Custom NetFlow Reports Read Only
task174=Monitor WiFi TDOA Receivers
task175=Health Monitor Details
task176=View Alert Condition
task177=Add Device Access
task178=User Preferences
task179=Config Archive Read-Write Task
task180=Configuration Templates Read Access
task181=Automated Feedback
task182=Configure Third Party Controllers and Access Point
task183=Email Notification
task184=License Check
task185=SSO Server AAA Mode
task186=Device Reports Read Only
task187=Swim Recommondation
task188=Identify Unknown Users
task189=Reports Menu Access
task190=TAC Case Management Tool
task191=Pause Job
task192=Discovery Schedule Privilege
task193=Client Reports Read Only
task194=Context Aware Reports
task195=ContextAware Reports Read Only
task196=Voice Diagnostics
task197=RRM Dashboard
task198=PnP Deploy History Read Access
task199=PnP Profile Read Access
task200=Ack and Unack Security Index Issues
task201=Pick and Unpick Alerts
task202=Auto Provisioning
01-20-2016 02:24 PM
We were successfully able to get Prime 2.2 working with tac_plus without issues. We utilized the task list at https://supportforums.cisco.com/sites/default/files/attachments/discussion/pi_tasks_for_tacacs.txt
You will need to put every task in quotation marks, and adjust domain, role, etc.
Edit: also some of the tasks are mispelled (i.e. acces vs access)
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide