Introduction:
This document helps in achieving intigration between Junioer Netscreen and ACS 5.2.
Problem:
Do the vsys and privilege attribute are required to be added seperately or together?
Solution:
The advice is to add it to the group as follows:
ervice = netscreen {
vsys = root
privilege = read-write
}
This problem can be fixed by making different device groups and shell profiles mapped to different authorization profiles.
Setup for juniper:
Step 1:

Step 2:

Source Discussion:
ACS 5.2 - Adding Custom Attributes for Juniper Netscreen TACACS+ Authentication