Security

last person joined: 18 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

creating a TACACS read-only user and not able to permit the "show run" command

This thread has been viewed 20 times
  • 1.  creating a TACACS read-only user and not able to permit the "show run" command

    Posted Aug 25, 2017 12:03 PM

    We use CPPM with Cisco switches. I'm trying to create a local user with TACACS that has the ability to do the "show run" command on the switch. For some reason I can't seem to get any "show" commands to work. Any other command I've specified, works. I've even assigned the user a privilege level of 15 with no dice. 



  • 2.  RE: creating a TACACS read-only user and not able to permit the "show run" command

    EMPLOYEE
    Posted Aug 25, 2017 12:09 PM

    Did you try using privilege level 1?



  • 3.  RE: creating a TACACS read-only user and not able to permit the "show run" command

    Posted Aug 25, 2017 12:10 PM

    I've tried, 1,2,3,6,7,8,9,14, and 15. 



  • 4.  RE: creating a TACACS read-only user and not able to permit the "show run" command

    Posted Aug 25, 2017 12:30 PM
      |   view attached

    This is the only way I've been able to get it to work, give the user privilege level 15, and permit the "show" command. Only problem is that I don't want to permit every show command. Apparently I can't lock this down enough. 



  • 5.  RE: creating a TACACS read-only user and not able to permit the "show run" command

    EMPLOYEE
    Posted Aug 25, 2017 12:33 PM
    If you want to limit individual commands, you'll have to do command authorization.


  • 6.  RE: creating a TACACS read-only user and not able to permit the "show run" command

    Posted Aug 25, 2017 12:34 PM

    Isn't that what I'm doing in the commands tab of the Enforcement Profile? Setting which commands are allowed or denied? 



  • 7.  RE: creating a TACACS read-only user and not able to permit the "show run" command
    Best Answer

    Posted Aug 25, 2017 02:03 PM
      |   view attached

    This is what I do. I allow 'show run interface blah' but not 'sh run', etc.

     

    I deny by default and then specify what I want to allow but you can allow by default and list what you want to restrict.



  • 8.  RE: creating a TACACS read-only user and not able to permit the "show run" command

    Posted Aug 25, 2017 02:26 PM

    Thanks. That's pretty much what I've come to the conclusion of doing. I used yours as a template to clean up how I had mine though. Thanks.