tacacs AAA and privilege level 7

Unanswered Question
Sep 1st, 2011
User Badges:

I've setup a group on tacacs server called acsrestricted and mapped it to AD security group. I've set this group to privilege level 7 on tacacs server.

I need this group to view the "show run" config on a router. Privilege level 7 allows the user to use some other show commands but not "show run". How can i configure this on tacacs?

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Richard Burts Mon, 09/05/2011 - 17:54
User Badges:
  • Super Silver, 17500 points or more
  • Hall of Fame,

    Founding Member

  • Cisco Designated VIP,

    2017 LAN, WAN


I am not sure that I am understanding your post correctly. As I understand it you have created a group for some users who would operate at privilege level 7. I gather that this works and that users in this group do authenticate and are assigned to privilege level 7. You say that some show commands are assigned to them but not the show run command. This would seem to be simple to solve - you make sure that show with a parameter of run is assigned to them. But there is something not simple that makes this not work. Part of the Cisco implementation of privilege levels is that in show run a user can not view any parameter that they do not have permission to change.

Perhaps it might work for your situation if you give those users access to show config. show config does not have the same restriction as show run.



Sent from Cisco Technical Support iPad App

mike.hemingway@... Tue, 09/06/2011 - 06:56
User Badges:


I meant to say earlier that some of show commands are assigned this acsrestricted group using privilege level 7 are enabled by default. I didn't make any changes in the " shell command authorization set " in ACS group settings.

The only change i've made so far is check the shell (exec) and privilege level 7 in group setup>acsrestricted>edit settings on the ACS 4.2. However, i'm unclear as to how to assign the show command with the parameter config (i like this better then the parameter run) on ACS 4.2. Can you help me with with syntex on ACS 4.2. Your help would be greatly appreciated.



This Discussion