Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Community Member

TACACS

OK here we go. I took over a network that when you log into a device (router or switch) through TACACS you end up at the enable prompt.

I need it to be at the user prompt and have to type en and your password for enable. I can not find this in my CiscoSecure ACS server. Is this just a level? Right now my group level is 15.

Thanks in advance.

jp

2 REPLIES
Hall of Fame Super Gold

Re: TACACS

Joel

There are a couple of things that can cause this behavior. First I would suggest that you check the configuration of the routers and switches and look for the command privilege level 15. That would send anyone who logs in directly to privilege mode. If you find this command remove it and your problem probably is over.

If it is not privilege level specified on the vty lines it is probably configured in ACS to authorize privilege mode. The more complete solution is to configure the user profiles and remove the privilege access. A quicker way would be to remove the authorization in aaa which will effectively remove the capability from everyone.

HTH

Rick

Community Member

Re: TACACS

The option that you need to disable is configured on your ACS server. Go to:

ACS -> Group Setup -> (edit the group your a member of) -> Enable options

Set this to 'no enable privilege'. If you want enable privilege set to: 'Max Privilege for any AAA Client'= Level 15

HTH

116
Views
0
Helpful
2
Replies
CreatePlease to create content