Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations gkittelson on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

TACACS+ with Windows ACS

Status
Not open for further replies.

North323

Technical User
Jan 13, 2009
966
US
shot in the dark here...

can you give a user only certain commands in TACACS+? then how do i integrate that into ACS and Windows?

anyone...anyone...

 
The easy answer is privilege level...15 is root, 1 is show commands only, and then levels in between...

user bla privilege 5 secret blabla.

Burt
 
You are asking a question that is a mile wide and 3 feet deep. You can create a group and assign privileges to a group and then assign users to said group. Or you can merely configure them on a per user basis and leave them in the default group.

In all honesty its way too much to type, but it is clearly outlined in the configuration guide.
 
thats the problem...its not outlined in the config guide. i want to only provide 'show' commands for certain people. the config guide actually is pretty nub. i'll keep at it
 
90 trial version 4.2 i think i totally figured it out

i see in ACS where you configure command sets and then realized i didnt have:
aaa authorization config-commands
aaa authorization commands 0 default group tacacs+ local
aaa authorization commands 1 default group tacacs+ local
aaa authorization commands 15 default group tacacs+ local

in my switch...

scrolling down helps!
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top