02-05-2016 07:15 PM - edited 03-10-2019 11:27 PM
Hi all,
I've been tasked with setting up ACS 5.6 to be able to authorize MS domain security groups members to have specific command access to our equipment. I've got the domain association and groups added, I have an Access Policy with a rule that is working so my domain test account can login to the switch and perform only the commands in my Command Set.
The issue is that when I assign a Shell Profile with privilege level 7 min/max to the rule, and the user logs in with this level, they are unable to see the commands that I've allowed in the Command Set. Is there a way to have ACS tell the IOS to automatically modify the commands visible to a specific privilege level when the user logs in, even though they aren't in that privilege level?
Any help greatly appreciated,
Chris Menuey
Solved! Go to Solution.
02-09-2016 07:34 AM
Since you're using command authorization and restricting user to certain commands, why are we using privilege 7 and not 15?
~Jatin
02-09-2016 07:34 AM
Since you're using command authorization and restricting user to certain commands, why are we using privilege 7 and not 15?
~Jatin
02-10-2016 08:22 PM
It was an attempt to limit the commands visible to the junior technicians to keep them from being inundated with commands that won't have prevalence to what they need to do, assign access vlan numbers to ports, use show commands, etc. We were under the assumption that ACS would be able to do this automatically with priv 7 based on the commands we put in the command set, since it doesn't appear possible I'll just be using priv 15 and doing additional training to let them know that even though they can see it, doesn't mean they can use it :D
Thanks for the confirmation of this Jatin, help is always appreciated :)
02-10-2016 10:19 PM
05-18-2016 08:27 AM
Hi,
I have a simular problem but using user authencation on the TACAS, cannt find were to associate the user with a specific profile.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide