Default Device Admin (Tacacs+)

ACS 5.1
Default Device Admin
Identity:
Single Result (internal list and AD1)
Group Mapping:
Rule1:(anyone in AD/Administrators=Group/AdminGroup)
Default: Standard user
Authorization:
Rule1: (anyone in Group/AdminGroup, permit all commands)
Default: Deny All Commands
Here's my situation:
User1 (AD/Administrator)
UserBob (NOT in AD/Administrator)
User1 Logs into a switch, types "enable" is asked to authenticate again, and can then run all commands (this is what i'm looking for, though i dislike the second login)
UserBob Logs into a switch, types "enable" is asked to authenticate again, but gets error "% Error in Authentication" (i do not want UserBob to even be able to log into the switch to begin with)
So my question is:
How do i keep UserBob from being able to log into the switch?
How do I get User1 to enter level 15 (Switch# instead of Switch>) automatically without being prompted to enter their password a second time after typing "enable"?
As i understand it, "Default Device Admin" is different than "Default Network Access" which i liken to "logging into switches" vs. "authenticating against VPN server or Wireless" respectively.  So i should be able to restrict users from logging into switches, but still allow them to authenticate for access to things like VPN, so i don't think what i'm asking above will keep me from being able to do that.
Ideas?

Hello
Q1 : How do i keep UserBob from being able to log into the switch?
     Configure NAR [network access restriction] and restrict the user to "not-to" access switch.
Q2 : How do I get User1 to enter level 15 (Switch# instead of Switch>)  automatically without being prompted to enter their password a second  time after typing "enable"?
     You need to configure exec authorization on switch and push "privlege level = 15" to make User1 fall on switch# mode.
The command on switch will be :
     aaa authorization exec default group tacacs local
Let me know if it helps.
thanks
Devashree

Similar Messages

  • Aaa-reports! v2.1 supports TACACS+ Device Admin Audit Reporting

    extraxi is proud to announce a new release of aaa-reports! with support for TACACS+ Device Admin (TDA) reports for audit compliance.
    Previous versions had the ability to import the Cisco Secure ACS database dump file and generate reports for group summaries, inactive users, expired and disabled user accounts.
    But in v2.1 we've gone much deeper. In this release we provide new reports to more fully document your TACACS+ Device Administration (TDA) config:
    * Group level Network Access Restrictions (NARs)
    * Shared NARs
    * Group level service & protocol authorization
    * Group level enable authorization
    * Group level shell command authorization
    * Shared Device Command Sets (DCS) for shell & pixshell
    * Network Device Group (NDG) content
    With these additions you will at last be able to document your "policy intent" without having to either take screen dumps of the ACS Admin web pages, or write it down by hand!!
    And the reports don't stop at config documentation... they can also show you
    * Which groups/users have permit access to specific devices (or device group)
    * What commands a group/user is authorised to execute against a specific device (or device group)
    * What groups/users make reference to a given Shared Network Access Restriction (NAR) or Shared Device Command Set (DCS)
    * Which Shared NARs and DCSs are not referenced at all
    aaa-reports! v2.1 now supports several methods for importing the ACS Database:
    * acsdb.cab - via extraxi "getacsdb" utility for v3.x
    * package.cab - via 4.x cssupport/support admin page
    All in all, aaa-reports! v2.1 is what ACS users have been crying out for to make network security auditing less painful!
    Visit http://www.extraxi.com to download a working 60 day trial

    .

  • EA6350 not accept the default password "admin" no matter I reset the router device.

    Hello, 
    I just brought a new router EA6350 and it does not accept the 'admin' to login the router. I did reset the router and can ping 192.168.1.1. Also able to go into the login screen. But the default password: admin was not success to login.
    Please help
    Solved!
    Go to Solution.

    To isolate the issue:
    Disconnect everything from the EA6350
    Connect your computer to the EA6350 LAN Port
    Make sure your computer wireless is disconnected or disabled
    Connect to the router using this link http://192.168.1.1
    If the router was reset to factory default you should be present a setup screen instead of a login screen
    Info Link:
    How can I reset the Linksys Smart Wi-Fi Router, EA6350 to factory defaults?
    Please remember to Kudo those that help you.
    Linksys
    Communities Technical Support

  • "media" and "watchers" default device folder is missing after install

    Hi everyone,
    I begin an installation of Final cut server and i meet an issue. At the end of the installation, Final cut server don’t create three default devices folders « library », « watchers », and « media ». Final cut server only create the « library » folder. Furthermore, Final cut server don’t create « default permission sets » during the install. I just have « admin » permission set.
    I’m working on an Xserve 2 X 2,66 Ghz Quad-core intel Xeon, 12 Go 1066 Mhz RAM, with OSX server v 10.6.4 :
    - First I install Final cut server v1.0. During this install, I choose « Video production » customer profile selection. Then, I set my « proxy media location » and my « Production media location » in a SAN device’s folder (Active RAID using Metasan). I choose the internal hard drive to install Final cut server software. Everything means Ok, Install succeeded
    - I update to Final cut server v1.1, and I start my « Final cut server »
    - Then, I upgrade to Final cut server v 1.5, Install succeeded.
    - At the end, I update to Final cut server 1.5.2
    Final cut server is working fine but there are something wrong compare to « setup and admin guide » :
    - My « proxy media location » and my « Production media location » are in my internal hard drive, not in my SAN device’s folder like my settings during the first install.
    - « watchers » and « media » default devices haven’t been created. I only have the « library » folder. Instead, if I set up manually all my « device folder », is it OK ? Is there any potential issue ?
    - Final cut server don’t create « default permission sets » during the install. I just have « admin » permission set
    If, someone could explain me what’s wrong in my install…. Thanks a lot
    Best regards
    Elka
    Message was edited by: Elka75

    Since you haven't added any content or customizations yet, I would just do a clean reinstall.
    First uninstall everything. See "Best Practices for uninstalling Final Cut Server" at <http://support.apple.com/kb/ht1764>.
    Then, install Final Cut Server 1.5 and update that to 1.5.2.
    (Don't install 1.0, update to 1.1, and update to 1.5--there is no reason to if you have an empty database. If your 1.5 license is an upgrade license that's OK, it will install without any previous installations--it just asks you for the 1.0 license key to authenticate.)

  • Can no longer set non-default device with QT 7

    In Quicktime 6, I could choose a specific device to play through. I use this feature to play iTunes through a second soundcard and out to my stereo. I leave my default device set to the system soundcard where I have just headphones hooked up. This way no system beeps or sounds come through the stereo.
    Now with Quicktime 7, I can no longer do this. Can anyone suggest a workaround? Why on earth would Apple remove this feature that was working before?

    Is there an answer to this dilemma yet? I run an htpc with multiple sound cards, and I definitely need to get this working. I hate to have to go back down to a previous version, if that is possible. Thanks.

  • Is it possible to open photo in the default device photo viewer application ?

    Is it possible to open photo with the default
    device photo viewer ?

    Thanks for your quick reply. I think I have tried but I cannot.
    There are no any options to let you choose "rename" in Windows 7 if you connect the iphone via USB
    I have tried to rename the photo directly in iPhone Explorer but it will make the photo cannot be read in iphone and just got nothing to show on its screen until I rename it into the previos name again then the picture will show properly.
    May be it can but I do not know how to rename them in Windows 7, could you please show me step by step?

  • HT204380 How to set my iPad as a default device while my iPhone and iPad share a same email address?

    How to set my iPad as a default device while my iPhone and iPad share a same email address?

    Shiv1611 wrote:
    Though i am still gona try using the same Itunes. Will same Itunes support two apple ids.
    That depends on what you mean. If you mean two iTunes Store accounts, no. Only one Apple ID can be logged into the iTunes Store at a time and if automatic download, iTunes Match or re-downloading of content is used the ID can not be changed for 90 days.
    Shiv1611 wrote:
    So i guess if i solve my goof up on creating different apple IDs and setting her phone as a new one .. according to you that shall do the trick.
    But i have a question here in that case what happens to all the applications that have been purchased on my Id ? Wont i be needing them to be purchased/downloaded again in the new id?
    If you previously had been using the same Apple ID for iTunes Store purchases for both of you there is no reason to change what you've been doing. If this is your wife's first iPhone, and you want to share the iTunes Store account just don't use the new Apple ID you created. As long as there are no purchases on it there's nothing to worry about.

  • Audio Problems when setting default device

    Everytime I try to set my headphones as the default sound device, my computer won't allow me to. I even tried to troubleshoot it, and it came up with the resolution of setting my headphones as the default device, but it failed to due to an error.
    It only occurs whenever I use the program Mumble, as I am a gamer and I use it to communicate with my fellow gamers. So whenever I fire up the program, all other sound except what comes from it, goes to my speakers. I don't know if this has to do with the program Mumble itself, or the fact that I LITERALLY cannot change my default device. Please help?

    What version of Windows are you using? 
    Also, could you please give me the exact model number of your notebook?
    You can use the following document if you need assistance in finding it.
    http://h10025.www1.hp.com/ewfrf/wc/document?tmp_renderType=findModel&cc=us&dlc=en&docname=c00033108&...
    -------------How do I give Kudos? | How do I mark a post as Solved? --------------------------------------------------------

  • Default device type configuration of controlfile autobackup ?

    1. configure controlfile autobackup format for device type disk to 'E:\oracle\oradata\oid\bk\%F';
    2. backup current controlfile;
    rman first use default device type ORA_DISK_1 and backup the file at "E:\ORACLE\ORA92\DATABASE\0AEU5OQL_1_1" (windows 2000)
    then backup file at "E:\ORACLE\ORADATA\OID\BK\C-804947643-20030807-00"
    when i backup database , rman can backup the controlfile at "E:\ORACLE\ORADATA\OID\BK\"
    when i backup controlfile manully , why rman first backup it at the default device ??
    thanks:)

    One more cogent point for auto backup on will always get automized backup whenever you made any physical structural change in yours database ,whenver you make any physical structural changes in yours database it goes to be highlight in control file,auto backup on will take this new highlighted control file backup at the spot,needn't to take control file backup after any structural changes It will be backed up itself in yours FRA (Flash recovery area).
    Khurram

  • Qemu-kvm: default devices and qcow2 overlays

    I'm considering migrating a critical VM from VBox to qemu-kvm.  I've already played around with qemu a bit, but I have two questions I can't find answers to.
    The first is about the default devices that are 'created' when using a basic qemu command (such as qemu <qemu_image>).  I'd like to find out exactly what would be the commands to create those devices to help me create an optimal VM for my needs.  But I can't find any information about what's created, much less how it would be created manually.  The qemu monitor command info <subcommand> doesn't help much here, not least because I can't figure out how to page the output or send it to a file.
    Second, I have several VMs which have three or more discrete 'states' as far as the contents of the virtual HDD.  IOW, I install the OS, shutdown, and take a snapshot.  Then I install some s/w, shutdown, and take another ss.  Then I revert to the first ss, install some other s/w, shutdown, and take a third ss.  Rinse, repeat.  I'm only interested in the contents of the virtual HDD, 'differencing images' in VBox terms I think.  The hardware config does not change, and I take snapshots when shutdown, so I'm not looking to duplicate h/w config save or 'state save' features of VBox snapshots.  Are qcow2 and the associated 'overlays' the right tool for this job?
    Thanks.
    Last edited by alphaniner (2012-12-13 19:52:25)

    As I understand it, host:bus.addr is an alternative to host:vendor_id:product_id. So if I wanted to pass both of these thumb drives:
    $ lsusb
    Bus 001 Device 002: ID 1e3d:2093 Chipsbank Microelectronics Co., Ltd CBM209x Flash Drive (OEM)
    Bus 001 Device 003: ID 1e3d:2093 Chipsbank Microelectronics Co., Ltd CBM209x Flash Drive (OEM)
    I would use host:001.002 and host:001.003 . Note I said would use, because I've never tried it.
    And usb_add is a qemu monitor command. See sections 3.4 and 3.5 of the doc you linked for info on the monitor.
    All this being said, I don't use libvirt stuff so I don't know if it has the capability to specify USB devices by bus.addr or whether or not it enables the monitor.

  • Changing phone button template on default device profile?

    I have a default device profile for 7941 that is currently using a phone button template that is one line. What is the impact of changing that to two-line phone button template? Can this be done live, on the fly?

    so if i change the default device profile for my 7941's, nothing will happen to the phones until they are reset?

  • ALSA: Setting default device (Not card, but device)

    This seems to be a riddle that nobody can solve;
    - The system only has one card by the name of 'Intel'
    - That card is the regular 6 3.5mm jack soundcard.
    - I have a mic plugged into the red microphone plug
    - I open up Audacity and go to preferences, there are two microphone plugs, 'hw:0,0' and 'hw:0,2'
    - I have no idea where 0,0 is and it doesnt make any sound, I plugged the mic into every plug on the board and nothing records.
    - i can set Audacity to use 0,2 and then it will record my voice just fine
    When I open up xfce's mixer I see that there are two mic plugs:
    Apparently "Front Mic" is the device that is hw:0,0 right now/
    Now when I play Savage2 I don't have an option to choose the device, I can choose the soundcard but that doesn't help. How do I set the default Device so that the game uses hw:0,2 in push-to-talk?

    from the alsa archwiki:
    "Setting the default Microphone/Capture Device
    Some applications (Pidgin, Adobe Flash) do not provide an option to change the capture device. It becomes an issue if your microphone is on a separate device (i.e. USB webcam or microphone) than your internal sound card. To change only the default capture device, leaving the default playback device as is, you can modify your ~/.asoundrc file to include the following:
    pcm.usb
        type hw
        card U0x46d0x81d
    pcm.!default
        type asym
        playback.pcm
            type plug
            slave.pcm "dmix"
        capture.pcm
            type plug
            slave.pcm "usb"
    Replace "U0x46d0x81d" with your capture device's card name in ALSA. You can use 'arecord -L' to list all the capture devices detected by ALSA."
    EDIT: maybe i didn't read your post well enough.. im just guessing here but maybe you can replace card U0x46d0x81d with
    device name_of_device..
    maybe..
    Last edited by test1000 (2010-10-24 17:06:36)

  • Make headphones default device for all sounds

    HP Pavilion p7-1240 Desktop PC
    Running Windows 7
    I just got this computer within the last month. Ever since I got it I've been having trouble with my sound. I will be playing a game or watching a video and the song randomly routes from my headphones to the speakers and then back. Also when I get a call in Skype, all the other sounds route to my speakers instead of my headphones. I tried disabling the speakers, and it just won't play sound at all instead of routing it to the headphones. I tried making my headphones the default device, but when I choose this option nothing happens. I also tried changing settings in Skype but that does not help.

    Hello Nightfeathers,
    It seems like your headphones are losing connection to computer and thus the sound is being rerouted since it can't find the headphones (temporarily).
    Does the sound ever go the other way? Like does it play on your speakers and then route to your headphones back to the speakers?
    To me it sounds like
    It does this
    Headphones --> Speakers --> Headphones
    However it doesn't do this
    Speakers --> Headphones --> Speakers
    Please clarify.
    What kind of Headphones are you using? Are they USB headphones or are they connected to the audio port on the computer? Have you tried using the other (e.g. if you are using headphones plugged into the audio port instead try using USB headphones to see if the problem replicates)
    If I have helped you in any way click the Kudos button to say Thanks.
    The community works together, click Accept as Solution on the post that solves your issue for other members of the community to benefit from the solution.
    - Friendship is magical.

  • Default ldap Admin user

    Hi,
    We are using ldap for creating oracle retail store inventory management users and creating store as well.
    I need to know that where can i find ldap admin user and what is the default ldap admin user after installing ldap ?
    Thanks
    Edited by: user11969485 on Jun 28, 2011 3:23 AM

    Hello,
    You can look at the list of forums at:
    http://forums.oracle.com/forums/main.jspa?categoryID=84
    (the link is at the top left of this forum as well)
    and locate the one that looks like the best fit for your question.
    Thank you,
    Sandra

  • How can I get my sound settings back to where they were initially. I lost my default device somehow.

    I was trying to listen to my music via my Bluetooth Bose speaker and I could not make that work. I went to Control Panel>Sound>Playback, and chose my default device, selected Properties, then Don't Use This Device, at which time my default device disappeared and all of the sound from my computer stopped.  Please help.

    Hi,
    Check the link below and use Microsoft Fix it:
    Diagnose and fix sound playback and audio problems automatically
    ** Say thanks by clicking the "Thumb up" icon which is on the left. **
    ** Make it easier for other people to find solutions, by marking my answer with "Accept as Solution" if it solves your issue. **

Maybe you are looking for