TACACS Custom Attributes

Unanswered Question
Sep 24th, 2008

I am trying to configure a user to authenticate using a Cisco ACS v4.1. The user will require access to a Cisco ACE module using a specific role and domain. In order to do this I need to add the following to the TACACS custom attribuets: "shell:development=Server-Maintenance dba". The user also should be able to authenticate and access routers and switches at privilege level 15.

If I leave the custom attributes out, the user can access the router/switches, but not the ACE. If I add the custom attributes in, the user can access the ACE but not the routers/switches.

What do I need to do to be able to access both with the same account??

I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
bclough Wed, 09/24/2008 - 07:24

Unfortunately that solution does not work for me. On some of the IOS devices I get logged in at privilege level 0 and can then change to level 15. On other IOS devices I get an "authorization failed" message and then the session closes. Without the ACE attributes set both systems log me in with privilege level 15.

The TACACS configuration appears to be identical on both systems.

Any ideas??

bclough Wed, 09/24/2008 - 08:30

I found the solution to the problem. The custom attributes for the ACE must be configured as optional (using *) rather than mandatory (using =). Therefore, this will work:

shell:development*Admin default-domain

But this will not:

shell:development=Admin default-domain

Actions

This Discussion