Privilege level not showing properly on 9800-CL
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-18-2024 09:32 PM
Hi,
I have issue in implementing privilege level command for non-admin user on our C9800-CL. We have 3 types of users:
- Super-admin level: it is level 15
- Admin level: it is level 7 for L2 support to do some users deauthentication, adding some commands, etc
- RO level: for monitoring purpose
I have issue when assigning this priv level command for admin level (level 7). CLI commands can works perfectly, but when L1 support want to access the webGUI, it doesn't show the graph anymore. But when I remove privilege level command, then they can see the graph again.
Before I implement the priv level command, the page for test_ro user (L1 user) shows as below:
but after i put the commands:
username test_ro secret 9 xxxxxxx
username test_rw privilege 7 secret 9 xxxxxxxx
privilege configure level 7 user-name
privilege exec level 7 configure terminal
privilege exec level 7 configure
privilege exec level 7 show aaa local guest_user
privilege exec level 7 show aaa local
privilege exec level 7 show aaa
privilege exec level 7 show
privilege exec level 7 wireless client mac-address
privilege exec level 7 wireless client username
privilege exec level 7 wireless client
privilege exec level 7 wireless
privilege exec level 7 wireless deauthenticate
privilege user-name level 7 wlan-profile-name
then the page for test_ro shows as follow:
the overview page just keep loading and i cannot do anything. If I click one of the "box" (example here, i clicked access points), then it shows:
but no issue with Super-Admin (level 15) or admin (level 7) account:
any help will be appreciated.
Thanks,
Pribadi
- Labels:
-
Wireless LAN Controller
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-19-2024 12:01 AM
- What software version is the C9800-CL running ?
- Have a checkup of it's configuration using the CLI command show tech wireless ; and feed the output into :
Wireless Config Analyzer
M.
-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-19-2024 12:32 AM
Hi @marce1000,
- it is running 17.9.5
- did that and found nothing related with setting up the privilege level config. find attached the result.
regards,
pribadi
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-19-2024 02:38 AM
- For the time being I can only give a general answer to go for the advisory release : 17.9.4a
and check if that can help ,
M.
-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-19-2024 03:30 AM
Hi @marce1000,
tested it and same issue there. 17.9.4a also has an issue in LobbyAdmin (ref: https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwh37783). This is the reason I open a discussion here.
Regards,
Pribadi
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-19-2024 04:29 AM
This from Cisco doc.
When TACACS+ or RADIUS is used for 9800 WebUI authentication, these restrictions exist:
- Users with privilege level 0 exist but have no access to the GUI
-
Users with privilege levels 1-14 can only view the Monitor tab (this is equivalent to the privilege level of a read-only locally authenticated user)
-
Users with privilege level 15 have full access
-
Users with privilege level 15 and a command set that allows specific commands only are not supported. The user can still be able to execute configuration changes through the WebUI
I.e. you can not make each user get it gui according to privilege' there are fix modes
MHM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-19-2024 04:35 AM
Hi @MHM Cisco World,
Read that. But I'm not using TACACS+ or RADIUS for the authentication. I'm using local authentication.
Pribadi.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-19-2024 04:41 AM
Friend it same'
The privilege either return from aaa server after success auth or the wlc use it local database to authc and authz the privilege of local user.
MHM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-19-2024 06:38 AM
@MHM Cisco World is correct - 9800 GUI does not support multiple priv levels - only 0, 1 and 15 as per that guide.
There's an enhancement request for full RBAC https://bst.cisco.com/bugsearch/bug/CSCwd66510 but I've not heard about any intention to implement it yet so for now the workaround, as per the bug details, is "Use CLI instead of GUI" <smile>
Please click Helpful if this post helped you and Select as Solution (drop down menu at top right of this reply) if this answered your query.
------------------------------
TAC recommended codes for AireOS WLC's and TAC recommended codes for 9800 WLC's
Best Practices for AireOS WLC's, Best Practices for 9800 WLC's and Cisco Wireless compatibility matrix
Check your 9800 WLC config with Wireless Config Analyzer using "show tech wireless" output or "config paging disable" then "show run-config" output on AireOS and use Wireless Debug Analyzer to analyze your WLC client debugs
Field Notice: FN63942 APs and WLCs Fail to Create CAPWAP Connections Due to Certificate Expiration
Field Notice: FN72424 Later Versions of WiFi 6 APs Fail to Join WLC - Software Upgrade Required
Field Notice: FN72524 IOS APs stuck in downloading state after 4 Dec 2022 due to Certificate Expired
- Fixed in 8.10.196.0, latest 9800 releases, 8.5.182.12 (8.5.182.13 for 3504) and 8.5.182.109 (IRCM, 8.5.182.111 for 3504)
Field Notice: FN70479 AP Fails to Join or Joins with 1 Radio due to Country Mismatch, RMA needed
How to avoid boot loop due to corrupted image on Wave 2 and Catalyst 11ax Access Points (CSCvx32806)
Field Notice: FN74035 - Wave2 APs DFS May Not Detect Radar After Channel Availability Check Time
Leo's list of bugs affecting 2800/3800/4800/1560 APs
Default AP console baud rate from 17.12.x is 115200 - introduced by CSCwe88390
