SCP

Unanswered Question
Oct 23rd, 2006

Greetings,

I'm trying to get Secure Copy (SCP) working to a Cisco switch configured to authenticate access via TACACS+ off Cisco ACS.

I've read the SCP documentation (http://www.cisco.com/en/US/customer/products/sw/iosswrel/ps1839/products_feature_guide09186a0080087b18.html) and enabled SSH and SCP as described. I can SSH into the switch without a problem.

However, when I try and use scp from a unix workstation to copy startup-config (scp craig@192.168.100.20:nvram/startup-config startup-config) I get the error "Privilege denied."

I assume that this is because the user "craig" (configured in Cisco ACS) needs to "enable" to get to privilege 15 in order to access the file "nvram:startup-config".

The examples in the SCP configuration document uses a local privilege 15 user (username superuser privilege 2 password 0 superpassword) which does not need to "enable".

How do you achieve this using Cisco ACS? I can't find anywhere is Cisco ACS to configure a user to have privilege 15 by default. Am I missing something?

Any help would be greatly appreciated.

Craig

I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
cbalfour Mon, 10/23/2006 - 03:20

About 10 minutes after posting this problem I figured out the solution myself.

In Cisco ACS | Group Setup | Edit Settings | TACACS Settings check Privilege level and set it to 15.

This only works if the following AAA configuration line is also present on the Catalyst device:

aaa authorization exec default group tacacs+

Actions

Login or Register to take actions

This Discussion

Posted October 23, 2006 at 2:49 AM
Stats:
Replies:1 Overall Rating:
Views:1199 Votes:0
Shares:0
Tags: No tags.
 

Discussions Leaderboard

Rank Username Points
1
Jon Marshall
16,581
2
Reza Sharifi
9,309
3
Giuseppe Larosa
8,202
4
Peter Paluch
7,599
5
Leo Laohoo
7,591
Rank Username Points
Jon Marshall
532
Reza Sharifi
116
Joseph W. Doherty
114
Peter Paluch
71
Bilal Nawaz
64