Using ACS to deny show tech-support

I am trying to deny the show tech-support command using Cisco Secure ACS command authorization sets (picture included). All other deny commands are working (is show running-config) but no matter what I do the show tech is un-successful. Any ideas?

Do you have these authorization commands configured?
aaa new-model
aaa authentication login default group tacacs+ local
aaa authorization exec default group tacacs+ local
aaa authorization commands 0 default group tacacs+ local
aaa authorization commands 1 default group tacacs+ local
aaa authorization commands 15 default group tacacs+ local
tacacs-server host 10.1.1.1 key cisco123
Debug aaa author should display:
AAA/AUTHOR/CMD: tty2 (2846421758) user='switchuser'
AAA/AUTHOR/CMD (2846421758): send AV service=shell
AAA/AUTHOR/CMD (2846421758): send AV cmd=show
AAA/AUTHOR/CMD (2846421758): send AV cmd-arg=tech-support
AAA/AUTHOR/CMD (2846421758): send AV cmd-arg=
AAA/AUTHOR/CMD (2846421758): found list "default"
AAA/AUTHOR/CMD (2846421758): Method=tacacs+ (tacacs+)
AAA/AUTHOR/TAC+: (2846421758): user=switchuser
AAA/AUTHOR/TAC+: (2846421758): send AV service=shell
AAA/AUTHOR/TAC+: (2846421758): send AV cmd=show
AAA/AUTHOR/TAC+: (2846421758): send AV cmd-arg=tech-support
AAA/AUTHOR/TAC+: (2846421758): send AV cmd-arg=
TAC+: Using default tacacs server-group "tacacs+" list.
TAC+: Opening TCP/IP to 10.1.1.1/49 timeout=5
TAC+: Opened TCP/IP handle 0x2E8FEA4 to 10.1.1.1/49
TAC+: 10.1.1.1 (2846421758) AUTHOR/START queued
TAC+: (2846421758) AUTHOR/START processed
TAC+: (-1448545538): received author response status = FAIL
Make sure to modify the original ACS Shell Command Authorization...
deny tech-support instead of deny tech.

Similar Messages

  • Nexus 7000 show tech-support

    Is there a way to do a show tech-support and pipe it to a file or tftp so that I can send it to a vendor?  If so, what would the command be?
    Thanks.
    Jeff

    You can use the redirect feature
    show tech-support > bootflash:tsupport_file
    http://www.cisco.com/en/US/partner/docs/switches/datacenter/sw/4_2/nx-os/fundamentals/command/reference/fnd_commands.html#wp1136081
    Thanks
    Hatim

  • Show Tech-support

    I ran the command show tech-support without page and other options on IDS, output is just going on from last 2 hours. I phave pressed ^c many times but it's not coming to prompt and not stopping.
    If any one have solution please update..

    You should be able to stop it using 'CTRL+C'.

  • Show tech support hanging at initiating.

    Hi all,
    UCS blade M3 200 is showing RAM Degraded.
    Confirmed RAM inventory was identic in the OS and BIO.
    Acknowladge the error
    reset the bmc
    None of these resolve the issue.
    I decided to collect collect the show tech support but this is stuck at initiating
    How can I clear this process and re-issue the show tech support to see if this run

    Rami,
    What version of UCSM??
    If the system is still sitting at initializing the tech bundle you can try to force a switchover. 
    connect local-management
    cluster lead b
    A RAM degraded message means the system has detected a correctable error but is still being used.  This isn't something you can clear by acknowledging the error.  It could indicate a problem DIMM.  If the OS and BIOS display the max memory amount this means it has not mapped out - which is good.  Have a look at the blade's memory stats and see how frequently the CE memory errors are happening.  If they happen as a one-time event they may eventually clear.  If they continue to occur you should open a TAC case and replace the DIMM.
    Regards,
    Robert

  • Is it possible to limit the output of "show tech-support" to the data from a single switch in a cluster?

    I need to provide the output for one 3750x switch out of a cluster of 7.
    With all of the various stats, the entire log will be fairly large.

    From the master switch open a session to that switch and than run "sh tech-support"
    session 7
    sh tech
    HTH

  • Show tech-support from Nexus

    Is there a way to disable the pager on the Nexus5k so that I don't need to continuously hit the "space" when doing "show tech"?

    You can then copy the file off to a FTP/TFTP/SCP server.  The no-more works as well, but this is a handy trick.
    I agree.  I've never seen the "no-more" before.
    There's another one:  sh tech | redirect tftp:///filename.txt"

  • We have router 7609s,so we need to know,router RAM,so how it will get i have show tech-support configuration.can you tell me pls

    how will get ram of router 7609s and 7206 ,can you tell whats bydefault RAM of both routers,please give me response ASAP.

    Hello
    Do you want to know how much RAM you have in 7600, Show version command can be use to find it
    Cisco 7206VXR (NPE400) processor (revision A) with 245760K/16384K bytes of memory.
    Above router has 245760K+16384K/1024 = 256MB of RAM.
    Thanks
    Kunal

  • ACE 20 Modular - show tech too large

    Hi
    A Client sent me a show tech of this ACE 20, is inserted into a VSS, but this file is very large, the reason is a command "show acl-merge merged-list vlan 93".. Somebody can tell me is this information is normal, or not, I think that is possible attack point to the farm server. the service is up, in the other ace20. the symptom is can not reach the VIP of the service.
    `show acl-merge merge vlan 93 in`
    All ACEs in merged list 5 Total:6377 Non-redundant:5608
    Priority:164, Lineno:0, ACE-id:61470 Action:PERMIT, Path-id:0x81/0x0/0x0:6/0[6/]
    Pmap:0x5, Log:FALSE/FALSE[FALSE][FALSE], Interval:0/0[0][0]
    Hash1:0x0 Hash2:0x0
    Generated:TRUE, need-to-add-in-comp:NO_ACT_NEEDED, redundant:FALSE
    Parent:: feature:SECURITY ace-lineno:8 ACL priority:0[G:0,P:0,C:0,ACL:0]
    Parent:: feature:TO CP ace-lineno:2 ACL priority:16779265[G:0,P:1,C:8,ACL:1]
    Feature:SECURITY Policy:1[1][1] sec-level:0x0 Intratype:SKIP
    Feature:TO CP Policy:1[1][1] sec-level:0x0 Intratype:TERMINATE
    Intertype:TERMINATE     
    IP address SRC:0.0.0.0/0.0.0.0 DST:172.23.98.20/255.255.255.255
    Ports SRC:RANGE 8 8 DST:RANGE 0 0       
    Protocol:1
    Hit Count:0 Active:TRUE Timerange:0
    Priority:326, Lineno:0, ACE-id:61471 Action:PERMIT, Path-id:0x81/0x0/0x0:6/0[6/]
    Pmap:0x5, Log:FALSE/FALSE[FALSE][FALSE], Interval:0/0[0][0]
    Hash1:0x0 Hash2:0x0
    Generated:TRUE, need-to-add-in-comp:NO_ACT_NEEDED, redundant:FALSE
    Parent:: feature:SECURITY ace-lineno:8 ACL priority:0[G:0,P:0,C:0,ACL:0]
    Parent:: feature:TO CP ace-lineno:2 ACL priority:16781313[G:0,P:1,C:16,ACL:1]
    Feature:SECURITY Policy:1[1][1] sec-level:0x0 Intratype:SKIP
    Feature:TO CP Policy:1[1][1] sec-level:0x0 Intratype:TERMINATE
    Intertype:TERMINATE     
    IP address SRC:0.0.0.0/0.0.0.0 DST:165.183.93.51/255.255.255.255        
    Ports SRC:RANGE 8 8 DST:RANGE 0 0       
    Protocol:1
    Hit Count:0 Active:TRUE Timerange:0
    Priority:487, Lineno:0, ACE-id:61472 Action:PERMIT, Path-id:0x81/0x0/0x0:6/0[6/]
    Pmap:0x5, Log:FALSE/FALSE[FALSE][FALSE], Interval:0/0[0][0]
    Hash1:0x0 Hash2:0x0
    Generated:TRUE, need-to-add-in-comp:NO_ACT_NEEDED, redundant:FALSE
    Parent:: feature:SECURITY ace-lineno:8 ACL priority:0[G:0,P:0,C:0,ACL:0]
    Parent:: feature:TO CP ace-lineno:2 ACL priority:16783361[G:0,P:1,C:24,ACL:1]
    Feature:SECURITY Policy:1[1][1] sec-level:0x0 Intratype:SKIP
    Feature:TO CP Policy:1[1][1] sec-level:0x0 Intratype:TERMINATE
    Intertype:TERMINATE     
    IP address SRC:0.0.0.0/0.0.0.0 DST:165.183.93.51/255.255.255.255        
    Ports SRC:RANGE 8 8 DST:RANGE 0 0       
    Protocol:1
    Hit Count:0 Active:TRUE Timerange:0
    Priority:647, Lineno:0, ACE-id:61473 Action:PERMIT, Path-id:0x81/0x0/0x0:6/0[6/]
    Pmap:0x5, Log:FALSE/FALSE[FALSE][FALSE], Interval:0/0[0][0]
    Hash1:0x0 Hash2:0x0
    Generated:TRUE, need-to-add-in-comp:NO_ACT_NEEDED, redundant:FALSE
    Parent:: feature:SECURITY ace-lineno:8 ACL priority:0[G:0,P:0,C:0,ACL:0]
    Parent:: feature:TO CP ace-lineno:2 ACL priority:16785409[G:0,P:1,C:32,ACL:1]
    Feature:SECURITY Policy:1[1][1] sec-level:0x0 Intratype:SKIP
    Feature:TO CP Policy:1[1][1] sec-level:0x0 Intratype:TERMINATE
    Intertype:TERMINATE     
    IP address SRC:0.0.0.0/0.0.0.0 DST:165.183.93.61/255.255.255.255        
    Ports SRC:RANGE 8 8 DST:RANGE 0 0       
    Protocol:1
    Hit Count:0 Active:TRUE Timerange:0

    Hi.
    We reboot the ACE20, and let one contex in this module..  The services is OK now, but my only doub is why the show tech-support is too large and appear the out of command show acl-merge merged-list vlan 93, with a lot of line.. 
    I try to run command "show tech-support" again and submit.

  • For those of you with a Windows computer and the iOS device is not syncing or showing up in iTunes. here is a known solution that has been working for tech support!

    I know this seems to be an emerging issue ever since the update to iTunes 11.1.4, some iPhones or other iOS devices are not showing up in iTunes or syncing. I'm not sure if Apple really knowns of this issue, but tech support has a (mostly) sure fire way of resolcing this issue. It's only for Windows computers though.
    Go to the article http://support.apple.com/kb/ts1538 and follow the Section 5 Verify Apple Mobile Device USB driver is installed. When you clik on that section, go to your version of Windows (it seems to be happening mostly across Windows 8) . And then to the section: If Apple iPod, Aple iPhone, or Apple iPad is listed.
    The gist of what you need to do:
    Windows 8 (since it seems to be the most affected) move your cursor to the upper ight corner of your screen) and click on the Magnifying glass. Type in devmgmt.msc and this should bring up the Device Manager. Onc eyou are in the device manager, look for the "Portable device" or "Universial Serial bus Controller" list, and you should see the "Apple iPhone/iPad/iPod" listed. Onc eyou see it, right click it, choose "Update software driver." Now, IT WILL SAY THE DRIVER IS UPDATED. I CANNOT STRESS THIS ENOUGH. Select "Browse my computer for driver software." Onc eyou choose that, select "Let me pick from a lsit of drivers on my computer." You should see the option "Have Disk." Choose that. Again, I KNOW you do not have a physical disk, but the file we need is already on your computer. After Hard Disk, choose Browse again. Follow this file path to the file we need: C:\Program Files\Common Files\Apple\Mobile Device Support\Drivers.. In the Driver's folder, you should see the "usbaaple" or "usbappl64" (if you have the 64 bit for Windows). Double click on that file, and hit OK. The file should install, and once it's finished check your iTunes!!! You may want to unplug your device and plug it back it before doing all of this. I REALLY hope this works for you all as well!

    How can I change my file extension from m4p to something else? I have had no success being able to play or burn my purchased music. I keep getting error 2122. If I can change the format I should be able to move it to another player or at least burn it in Nero. Thanks.
    Angie

  • I've just discovered that with the newest version of iTunes you can no longer delete apps you don't want.  You used to be able to do so by connecting to to desktop computer and delete them.  Tech support said you can't delete apps anymore.  Not Good!

    I've just discovered that with the newest version of iTunes you can no longer delete iPod Touch/iPhone apps you don't want.  You used to be able to do so by going onto iTunes on your desktop computer and deleting them.   Not Good!  I just called tech support and they said that in this version there is no way to delete them. They also said there have been numerous complaints about this.  You can't even delete them from your applications folder.  It's as though you're being held hostage to apps you tried, but do not want.
    While we're on the subject, I don't like the fact the the iPod touch comes with unistalable apps such as: Passbook, Nike & iPod, Newsstand, and Game Center. Don't want them, will never use them.  Give customers the option to delete apps that we don't want.  Call Apple's corporate customer care. escalation, and complain untill they fix this.

    Actually,
    Step 1:
    Step 2.
    Step 3.
    Step 4.
    Step 5.
    One of us must be wrong.

  • TS1292 Hey, im facing a problem while im using the purchesing , its showing me that: contact with apple support itunes???? Please help

    Hey, im facing a problem while im using the purchesing , its showing me that: contact with apple support itunes???? Please help

    Use the link below to contact iTunes support.
    http://www.apple.com/emea/support/itunes/contact.html

  • Use this link to send iTunes Store tech support email

    I finally found the page to email Apple for tech support re: iTunes Store not connecting this weekend:
    http://www.apple.com/support/itunes/store/connect/
    (the web form to send for tech support for iTunes store connection problems is at bottom of page)
    Everyone with the iTunes Store not loading using 7.0.1, please take the time to email Apple and request help.
    I just did...
    thanks
    Powerbook G4 17   Mac OS X (10.4.8)   itunes 7.0.1

    After spending the better part of the morning on the phone with my ISP Comcast, in Memphis, TN they swear it is not their issue. They had me run several tests to the modem, internet speed and browswer and according to them, it was all fine.
    Because the the music store is the only feautue I cannot open
    (no problems accessing other websites), they feel it is an Apple issue, with iTunes in particular. I am inclined to agree since I was able to access the music store briefly this morning.
    I would encourage everyone to contact Apple by email. If enough people do so, they will have to fix the issue if it is an Apple problem (imagine how much business they lost this weekend from people being across the country being unable to buy music), If it is not an Apple issue, they can certainly exert some pressure on the ISP's regarding the connections.
    In general I have not liked the new version of iTunes and noticed slower connections when I downloaded it even when I could get to the music store.
    iMac   Mac OS X (10.4.8)  

  • Do not use Tech Support via chat - 2 hours of down time resulted.

    Verizon:
    Today, I got on Chat with technical support since my internet connection was sluggish the last couple days.  In the beginning, Maria asked not only for one phone number, but another (in case we got disconnected?).After about 20 minutes of chatting with Maria, she said there didn't seem to be any issues, but she was going to run tests, or see what she could do on her side.  Shortly after, the chat window stopped responding, and the internet connection was lost.
    I waited 15 minutes or so (no call from Maria), and the internet still had not came back up.
    I reset the router by unplugging for 5 seconds and plugging back in.  Let it reboot for ten mintures...Nothing... Repeated this process again, nothing. 
    I decided to call customer service, since I did not have an internet connection, waited on hold for 25 minutes just to be transferred to technical support another ten minutes.  Dean from tech support troubleshooted the issues, ran tests, and got the internet up and working again (it was something on Verizon end, since he never even had me reset the router...).
    Moral of story, please teach the tech folks to call back if a connection is lost.  Almost 2 hours of time is lost just because I decided to use the chat service (which I will not use again).
    - Matt

    Well I called the website tech support to fix an issue with the phone button on the website giving me a service unavailable error... They completely wiped out my account and now I can't re-register.... Granted I could NOT understand what the woman was saying... I am trying via chat again....

  • Hello.  I upgraded my MIFI 2200 (had no contract on it) to a Jetpack (with a contract) when customer service told me this 4G device would use less data because it was faster.  This was not correct.  Anyway, I got the device, had problems, did tech support

    I upgraded my MIFI 2200 (had no contract on it) to a Jetpack (with a contract) when customer service told me this 4G device would use less data because it was faster.  This was not correct.  Anyway, I got the device, had problems, did tech support, re-activated my MIFI.  1.  Decided to return the device. Spent hours with Customer Service, then finally up to Management, they agreed to take it back and void the contact, I sent it back immediately – and instead of voiding the contact they transferred it to my MIFI! Please cancel the contract on the MIFI. 2.  During the short time I had the Jetpack I continually received overage alerts, took it all the way up to 30 GB, each time I backdated the new data plan except twice when customer service did and failed to back date the increase, and once the computer locked customer service out and could not increase.  The end result is I have a $495 bill, many of these alerts were false since I ended up with only 14 MG for the month, etc.  I am asking that my bill be reduced significantly to reflect no overage and to compensate for these problems. Please open up a ticket for this.

    I had Verizon JetPak and you will find it will eat data like crazy. I opted to sign on to ATT Uverse and configured my phones and other devices to the WiFi on the Uverse system. It took about 5 minutes to completed the configuration.  I was using 10 to 12 GB monthly to support 5 devices. Even if you use Verizon DSL, you are still subjected to same GB allotment.  In my area, Verizon DSL is not available. With Uverse, I have 250 GB monthly to use, and I have not even come close to using anything of that magnitude. I reduced my GB package with Verizon to 2 GB per month and since having ATT Uverse, I never use more than 1GB a month with Verizon.
    I have no problem with Verizon cell phone service as we get a much stronger signal where we live than you can with ATT or any others.  It is just my opinion, but if you are running multiple devices off Verizon Jetpak, you will eventually spend a fortune to keep pace.  I pay $60 a month for 18 Mbps speed, although ATT have packages that cost much less. But, it saves me a bundle each month. The cost of Uverse alone is worth not having to run everything through a Jetpak.  
    If you have the  option to use another DSL service provider in your area, I recommend dumping the Jetpak and sign on with another carrier.

  • Hi i have just bought a used ibook from goodwill and need to reset the id and password.is there anyway to do this? i called tech support and they said to try here because our ibook is considered opsolete and they can't help me. thanks

    hi before i start i did not steal it, i bought a used ibook and need to know if there is a way to reset or get past the old user id and pass word. we bought it from goodwil so no way to ask old owner and i called tech support and it is conciderd opsolete so no help from them and know one in this area works on mac. so what can i do?  this is for my daughter and we are not rich thats why we bought used. thanks for any help.

    Here are the instructions, as I have them:
    Press the Command + s key during startup. This takes you to Single User Mode, where you will see a command line.
    Type this when the command-line prompt (>) appears:
    mount -uw /
    rm /var/db/.AppleSetupDone
    shutdown -h now
    When the iBook restarts, you will see the setup screen. This allows you to create a new account. BE SURE to give yourself administrative privileges. You can now use this new account and set it to log in automatically with this new account if you don't want to be bothered with the login screen every time you start up.
    You can also delete the old account if you want to free up some hard drive space.
    Good luck!
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    However, it is desirable to do it with the disc, if it is available, which is why I waited to see if the user has the disc before supplying the instructions for doing it via Single User Mode.

Maybe you are looking for