Cisco AAA/Identity/Nac :: Enable Parser View Command On ACS 5.X

Mar 11, 2013

Would like to check out is it possible  binding Cisco secure ACS 5.x to support router/switch ios feature view -  superview and parser command
 
Busines objective is assigning administrative roles, with different role based CLI access, using ACS5.X as backend server.  a. Admin (allow all) b. network monitor (privlege # 7, enable view that can doing various show command and configure) c. support (privlege #1, read only)

View 2 Replies


ADVERTISEMENT

AAA/Identity/Nac :: Use Cisco Secure ACS 4.2 To Enable Command Authorization Using TACACS?

Nov 5, 2011

provide a sample configuration to use Cisco Secure ACS 4.2 to enable command authorization using TACACS.

View 8 Replies View Related

Cisco :: Show Command To View Ram Modules

Nov 30, 2011

Looking for a show command to display the actual physical Ram modules inside a 2911 router. I believe they come with 2x ram slots and I need to know if it has 1 ram stick or 2.show version displays the total amount of ram, but not if its 2x128 or 1x256 etc.This is also production gear so I cannot open it up and have a look until the scheduled downtime.

View 3 Replies View Related

Cisco WAN :: Command To View What Type Of SFP Module Installed In Catalyst 3750 Switch?

Jan 20, 2013

Is there a command that can be used  to view what type of SFP module that is installed in Catalyst 3750 switch?

View 6 Replies View Related

Cisco Switching/Routing :: 2950 - DHCP Server With Command To Enable It

May 4, 2012

I am wondering if it has its own DHCP router and if theres a command to enable it?Also Random side question. it hands out ip addresses to other devices (the 2950 im using infront of a router) but when I hook up another switch to this switch it doesnt initialize the port or try to connect? why.

View 1 Replies View Related

Cisco VPN :: 5520 Configure Intra Interface Command To Enable Connectivity Between Remote Clients

Feb 3, 2013

I'm working with AnyConnect for the first time (my prior experience is with IPSec client) and I have multiple remote users who connect to a 5520 via AnyConnect client; they need to print to each others' shared printers but currently have no connectivity between each other.
 
Can I configure the 'intra-interface' command to enable connectivity between remote clients, or is there more that needs to be done to enable this, presuming that it can be done at all?

View 3 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.3 View-logprocessor Not Monitored

Jan 25, 2012

After an upgrade from ACS 5.1 to 5.3 the view-logprocessor are not running any more. I also installed the newest patch 5.3.0.40.1. The installations are success but the view-logprocessor steal are not working.

View 2 Replies View Related

Cisco AAA/Identity/Nac :: Errors In ACS View Server In ACS 5.2?

May 30, 2011

I have deployed 7 appliances 5.2.0.26.4 CSACS-1121-K9 whose 6 are performing AAA authentications while the last one is is the primary and is the master for configuration and log collector.
 
Since this morning, I cannot access anymore the view where I can see all Radius authentication for today. I obtain the following message:The server workspace storage for on demand transient reports is full, please try again later or contact administrator to increase on demand transient report storage capacity?

Moreover, if I generate other report, I have the message:18002: iPortal generate report failed.I could find some information which makes references to a Cisco bug CSCtb98071, as below:

Launching a shared report in the ACS 5.1 Monitoring and Report Viewer displays an iportal error for a particular scenario.
#Symptom: You will see the following iportal error message when you launch a shared report:
#iPortal generate report failed.
#
#Conditions: This error occurs when you add a report to a group in the interactive viewer and save it as a shared report.
#Workaround: Avoid using the option Add Group from the interactive viewer for hyperlinked column entries when you save the report as shared
 
However, I am not adding any report to any group, so I don't understand why this error appears and how to solve it.

View 8 Replies View Related

Cisco AAA/Identity/Nac :: No ACS View Dashboard After 5.2.0.26 Upgrade

Apr 24, 2011

After upgrading to 5.2.0.26 I no longer seem to have a dashoard on the ACS View/Monitoring section.

View 5 Replies View Related

Cisco Switching/Routing :: Catalyst 2950 - Release For Snmp-server Enable Traps Errdisable Command?

May 16, 2013

We have a catalyst 2950 switch running:
 
IOS (tm) C2950 Software (C2950-I6K2L2Q4-M), Version 12.1(22)EA6, RELEASE SOFTWARE (fc1)
 
This release doesnt have the snmp-server enable traps errdisable command.
  
Where to look on the cisco site for the next available release for me that would have this command in place?

View 2 Replies View Related

Cisco AAA/Identity/Nac :: Windows Domain Account To View Reports Acs 5.2

Oct 5, 2012

We have a Cisco ACS 5.2 deployment (appliance).  It has an existing integration with Active Directory.  We utilize this with RADIUS to authenticate our wireless users and TACACS for managing our network equipment.The RADIUS reports are useful for other teams (outside my own) to be able to troubleshoot password and account lockouts (everyone forgets to change the password on their phone).I would like to allow this team and other access to view the RADIUS authentications report.

View 2 Replies View Related

Cisco AAA/Identity/Nac :: ACS Version 5.2.0.26 View Backup Stopped Working From GUI?

Jul 27, 2011

We have an issue with View db (Monitoring & Reports) backup on ACS, version 5.2.0.26. We have scheduled incremental backup daily and full backup monthly. Everything has been working well, but since yesterday following errors have appeared, and full and incremental backup stopped working:

Alarm Name
System Alarm [Incremental Backup]
Cause/Trigger
On-demand Full Backup failed
Alarm Details
CARS_BR_BACKUP_CREATE : -405 : Internal error: couldn't create backup file
Alarm Name

[code]....

We use same repository as always. Backup to the same repository works from CLI.

View 2 Replies View Related

AAA/Identity/Nac :: ACS V5.1 View Not Showing Full Admin Logs?

May 18, 2011

I am having trouble viewing all the Administration logs in ACS View. I have my Local Log Target set to a Maximum log retention period of 90 days. In ACS View I can display authentications that go back 90 days + However when I try and display the "ACS_Configuration_Audit" in View and perform a Custom query that goes back 90 days it will only display about 35 days of Admin logs.I know the logs are there because when I go into CLI and do a search like "show logging | i "ObjectType=Administrator Account" the Administration logs go back over a year.why ACS View cannot display all the Admin logs?The ACS is running v5.1.0.44 Patch 6 (Also experiencing this in a v5.2 ACS as well)

View 2 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.1 View Application Exceeded Its Maximum Allowed Disk Size

Apr 6, 2011

This is the error message I am getting on our ACS 5.1 appliance - is there anyway to purge the database or compact the file?

View 1 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.1 / This Command Is Not Authorized

Feb 5, 2013

We have an issue with ACS server 5.1.0.44.X. We want make a one user with few commands: show ip route static-table(deny other show commands)configure terminal, terminal length 0 ip route (with all possible arguments). All works fine except ip route command, when i try to type it I see - "This command is not authorized".

View 1 Replies View Related

Cisco AAA/Identity/Nac :: (command Set) Not Working In ACS 5.3?

Mar 4, 2013

I have to created command set under "Policy Elements>Authorization and Permissions>Device Administration" for limited access user in ACS 5.3. Like i triyed to give them permission to only few show commands. I have set user priviledge 1, 7, 10 however either of the priviledge level user was able to run those commands. I works like the shell priviledge level.

View 1 Replies View Related

Cisco AAA/Identity/Nac :: What Is Command To Launch GUI On ACS 5.x

Mar 10, 2013

After logging in to the ACS, what is the command to launch the GUI on a Cisco ACS 5.x.

View 1 Replies View Related

Cisco AAA/Identity/Nac :: Setup A Command Set In ACS 5.3?

Nov 26, 2012

I'm trying to set up a command set in Cisco ACS 5.3, I can't get i to work no mather who I try What I'm trying to accomplish is that some users, say Bob can run every priv. level 1 command + show run, or just to specify which commands Bob will be able to run, whatever is easiest to set up.
 
In my switch I have the commands:

aaa new-model
aaa authentication login default group tacacs+ local
aaa authentication enable default group tacacs+ enable
aaa authorization config-commands
aaa authorization commands 1 default group tacacs+ 
aaa authorization commands 15 default group tacacs+ <--- tried diffrent apporaches whith priv level..
(and specied a tacacs server)
  
is the "default" under "aaa authorization commands 1x default group tacacs+" the name of the command set?
 
In the ACS I have specied a Authorization group and binded it to the command set, should the user have priv 15 for this to work or priv 1?(I have also specied a user and an identity group and specied ip ranges under "Network Devices and AAA Clients")

View 2 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.2 - Command Set Is Empty

Jan 15, 2012

I have a problem with the ACS 5.2 configuration: I am trying to use the AAA authorization to centralize privileges and commands but only the privilege level is sent to router, the command set aren't sent.
 
The test cenary is this:
 
ACS 5.2Router 2900 family IOS 15.0 
The ACS is configured with:
 
Shell Profiles (to match with a privilege level), Command Sets (with the command list), Service Selection Rules (to set to one service) and Authorization (to assign one shell profile and one command set).
 
The router is configured with the follows commands:
 
[code]....

View 4 Replies View Related

Cisco AAA/Identity/Nac :: Enable Privilege On ACS 5.1.0.44

Jun 4, 2011

I have created internal user on internal identiy store --> users with password  & enable password  , Similarly i have enabled max privilige level 15 under policy elements , authorisation & permission ,Device administration , shell profile .But i am unable to login into device using enable password , I am finding following error on my logg report
 
Failuire reason : 13029 Requested privilige level is too high .

View 3 Replies View Related

AAA/Identity/Nac :: Enable Password In ACS 5.3?

Jan 28, 2013

How to configure authentication of enable password using acs 5.3. I have installed acs 5.3 and created user and gave relevant passwords. Following config is done on router
 
aaa new-model
aaa authentication login default group tacacs+ local
aaa authen enable default group tacacs+ enable
tacacs-server host x.x.x.x key xxxxx
 
Now when I telnet router, i can authenticate username/pass with acs5.3 but when i try to enter enable command and give password, it gives me error in authentication. What is the process of configuring enable passwords?

View 6 Replies View Related

Cisco AAA/Identity/Nac :: Command Accounting For Radius On ACS 5.2?

May 26, 2011

is command accounting for Radius supported on ACS 5.2 ? provided vendor's radius implementation supports this capability.

View 1 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.2 - Cannot Find Adflush Command

Feb 3, 2013

As advised by Bug Toolkit for bug # CSCub82913: "Workaround: adflush resolves the issue temporarily". But I can't find that command in the console or in the documentation.

View 2 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.1 -Allow Clear Counters Command Only

Oct 3, 2012

I have ACS 5.1, I have created a user with privilege 15. I need to allow a single command by command set. I have configured command set. in command set setting i have unchecked "Permit any command that is not in the table below"
and added command as below.
 
Grant      Command          Argument
Permit        clear               counters
 
its allowing me  to run clear counters, good is its not allowing to show run and configuration t commands. And problem is i can run reload command also even show interface commands.I just want to allow clear counters command only.

View 2 Replies View Related

AAA/Identity/Nac :: ACS 5.2 Command Set For Clear Counters

Sep 24, 2012

I am having ACS 5.2. I have to configure a user which would have privilege 7 access and addition to this, a user can run "clear counters" command.how to configure cammand set for "clear counters"?Can i run clear counters by privilege 7?

View 2 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.3 How To Enable Log On Secondary Server

Feb 28, 2013

We are using ACS 5.3 with two servers in a distributed solution.All logs are collected on primary server so when this server fails all logs are lost.How can I enable log on secondary server also?

View 2 Replies View Related

Cisco AAA/Identity/Nac :: How To Enable ACS 5.2.0.26 Configuration Audit

Oct 12, 2011

ACS and i would like to know how to enable the "Configuration Audit" for someone login to my network devices using their ACS login and i can monitor what they did on it.
  
ACS Version : 5.2.0.26

View 6 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.1 Is Refusing To Use Enable Password

Dec 21, 2012

I have migrated my ACS data from 4.1 to 5.1 and everything is working fine to test the connection I have configured a switch to get the authentication from the new Tacacs server, using my old username and password..i got in perfectly but when the switch asked my for enable which is the same password, it refused the password.(I have unchecked the <use a different password for enable> option) I deleted my switch from the Tacacs to enter locally, I went in with no problems..i thought that the problem may be from the old configuration.so I created a new username and password to check, and the problem still exist.

View 2 Replies View Related

Cisco AAA/Identity/Nac :: Enable Authentication Mode On ACS 4.2

Feb 8, 2012

how to Config the ACS 4.2 server runs in TACACS + mode (users accounts configured the ACS) mode  to authenticate enable mode  password on the asa using the same AD account?

View 10 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.2 Configure Command Set Only To Allow Interface Access?

Jul 6, 2011

I had insatalled the ACS 5.2 on Vmware . As per my requirement i need to configure a user to restricted privilege so that he should be able to execute only the below commands on the switch .
 
-Show ver
-Show interfaces
-Show ip Interface Brief
-Configure terminal
-Interface <interface name >
-Shutdown
-No shutdown
 
The users should not be authorized to execute any other commands than above listed one .After the configuration i was not able to restrict the config mode commands . Once the user is  authoized for  Configure terminal access  he will have full access on the device. How to configure the command set only to allow  interface access and he should be able to apply Shutdown and No shutdown command .

View 6 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.3 - Shell Command Set - Unable To Deny

May 30, 2012

Currently i deploy a ACS 5.3 at customer site. The issue i face currently is some command sets not able to deny. Example like below: 
 
i want to deny the AD user with priviledge level 15 to change the enable secret password and delete the enable secret password.
 
the command i issue at below: Code...

View 1 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.2 Command Set - How To Authorize Empty Arguments

May 19, 2011

after switching from a very old ACS 3.2 to ACS 5.2 I'm wondering on how to specify an empty argument in a command set.
 
Example:
 
I want to permit:
write 
but I don't want to permit:
write terminal
write erase
write network
write core
and so on.
 
If I specify command="write" and leave the argument field empty, every argument is allowed. This would also permit "write erase" what I don't want.
 
In ACS 3.2 I could specify command="write" and argument="^<cr>$". This does exacly what I want. The command write with an empty argument is allowed. If there is any argument, the command is denied.
 
In ACS 5.2 if I enter the same string in the argument field, the "<cr>" is filtered out and in the config is now only the string "^$" which is not working.
 
how to specify an empty argument?
 
BTW: ACS View shows only [ CmdAV=write  ] in the logs...

View 3 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.2 Command Set Policy Not Working On Console?

Nov 27, 2012

I configure my Cisco ACS5.2 using Command set policy and providing Shell access 15.I allow user only “show * ” command.It works fine with Telnet. User Group cannot execute any command apart from “Show * ”But when I connect the device using Console user group has full permission on the devices.I believe Command set policy is not working on Console. Is it normal behavior or do I need to update some changes in ACS or Network devices ?
 
My network device configuration is as below :
 
tacacs-server host 10.x.x.x key test123
tacacs-server host 10.y.y.y key test123
tacacs-server timeout 1
aaa authentication login default group tacacs+ local
aaa authentication enable default group tacacs+ enable
aaa accounting exec default start-stop group tacacs+
aaa accounting commands 1 default start-stop group tacacs+

[code].....

View 1 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved