Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements
Webcast-Catalyst9k
New Member

ACS 4.0 command authorization set

Hi

i want to deny the command "clear ip route *" only but not the other command like "clear ip route 1.1.1.1" how do we do it ?

It seem that ACS don't take the asterisk !!

thanks

8 REPLIES

Re: ACS 4.0 command authorization set

Hi,

I suspect you may have tried to enter "clear ip route *" all at once and then hit "add command", which won't work.

Make sure you only have a single word in the box when you enter "add command". After that, enter "permit ip route *" in the right-hand box when clear is highlighted.

HTH

Andrew.

New Member

Re: ACS 4.0 command authorization set

hi andrew

i have following:

Unmatched Commands: permit

add command: clear

permit unmatched arg:crossed

argument: deny ip route *

it seem that acs don't take the asterisk

Re: ACS 4.0 command authorization set

Hi,

Just tried it - works ok my on my test acs box. Your description looks good - so might be worth creating a new command authorisation set.

Do you get an error message?

Andrew.

New Member

Re: ACS 4.0 command authorization set

hi,

same result, can you do a clear ip route x.x.x.x ?

my goal is just to deny the clear all route but you should be able to deny a specific route.

With this setting it deny all commande after the route word.

Re: ACS 4.0 command authorization set

Hi,

What error message are you actually getting? Is it a pop-up one, or does a specific error appear in the GUI?

Andrew.

New Member

Re: ACS 4.0 command authorization set

hi

i dont have any error message on ACS.

it symply deny both command

clear ip route *

clear ip route x.x.x.x

gregor

Re: ACS 4.0 command authorization set

Hi,

Do you see anything in the ACS logs, especially the "failed attempts" log file?

Andrew.

New Member

Re: ACS 4.0 command authorization set

Hi,

yes in this file it say

Command denied service=shell cmd=clear ip route 138.187.250.36

our your system when you specifie this command can you do the specific clear ip route 1.1.1.1 ?

regards

gregor

128
Views
0
Helpful
8
Replies
CreatePlease to create content