Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

Ploblem with 2950 and ACS

Hi all,

I've configured the 2950 as below and configured ACS correctly and I can login to the 2950 using this config, the problem lies after I go into enable and try any command I get the following error Command authorization failed.

What have I missed out of the config that will allow me to run any commands?

aaa new-model

aaa authentication login default group tacacs+ local

aaa authorization exec default group tacacs+ local if-authenticated

aaa authorization commands 15 default group tacacs+ if-authenticated

aaa authorization network default group tacacs+ local if-authenticated

aaa accounting exec default start-stop group tacacs+

aaa accounting commands 15 default start-stop group tacacs+

aaa accounting network default start-stop group tacacs+

tacacs-server host ***.***.***

tacacs-server key 7 ***********

Thanks in advance.

Bruno

1 ACCEPTED SOLUTION

Accepted Solutions
Bronze

Re: Ploblem with 2950 and ACS

Hi friend,

The switch's AAA looks ok, maybe you need to take a look at your ACS.

Check the following info, where you might need to apply it into your ACS config:

http://www.cisco.com/en/US/products/sw/secursw/ps5338/products_configuration_guide_chapter09186a00801fd6fc.html#wp676529

If it helps, please rate or ask another question.

Regards,

Rafael Lanna

2 REPLIES
Bronze

Re: Ploblem with 2950 and ACS

Hi friend,

The switch's AAA looks ok, maybe you need to take a look at your ACS.

Check the following info, where you might need to apply it into your ACS config:

http://www.cisco.com/en/US/products/sw/secursw/ps5338/products_configuration_guide_chapter09186a00801fd6fc.html#wp676529

If it helps, please rate or ask another question.

Regards,

Rafael Lanna

New Member

Re: Ploblem with 2950 and ACS

You may want to check the account's assigned privilege level.

123
Views
0
Helpful
2
Replies