<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: This user does not have permissions for this command. in ExtremeCloud IQ- Site Engine Management Center</title>
    <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/this-user-does-not-have-permissions-for-this-command/m-p/82710#M9094</link>
    <description>Would you share example to show steps from both switch &amp;amp; radius server ?</description>
    <pubDate>Wed, 30 Mar 2022 15:54:29 GMT</pubDate>
    <dc:creator>JASU</dc:creator>
    <dc:date>2022-03-30T15:54:29Z</dc:date>
    <item>
      <title>This user does not have permissions for this command.</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/this-user-does-not-have-permissions-for-this-command/m-p/82693#M9077</link>
      <description>Good Afternoon,&lt;BR /&gt;&lt;BR /&gt;X440 connected to XMC/NAC used to autheticate the user for management login.&lt;BR /&gt;&lt;BR /&gt;IF I try to connect to the switch with ssh the prompt is this :&lt;BR /&gt;&lt;BR /&gt;X440_UP &amp;gt; and for any command I do I receive this error:&lt;BR /&gt;&lt;BR /&gt;"This user does not have permissions for this command."&lt;BR /&gt;&lt;BR /&gt;The problem is the connection to radius ( XMC/NAC ) but I do not know where ( I only upgraded to the last release XMC and NAC )&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;BR /&gt;Giuseppe</description>
      <pubDate>Thu, 16 Dec 2021 18:23:58 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/this-user-does-not-have-permissions-for-this-command/m-p/82693#M9077</guid>
      <dc:creator>Giuseppe_Montan</dc:creator>
      <dc:date>2021-12-16T18:23:58Z</dc:date>
    </item>
    <item>
      <title>Re: This user does not have permissions for this command.</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/this-user-does-not-have-permissions-for-this-command/m-p/82694#M9078</link>
      <description>check what radius attributes are sent from NAC to EXOS. For Admin access the EXOS you should receive Service Type = 6&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="c569b42c87a64cdbaacfebc98001c23e.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/3085iB1709FE34F4EF2BA/image-size/large?v=v2&amp;amp;px=999" role="button" title="c569b42c87a64cdbaacfebc98001c23e.png" alt="c569b42c87a64cdbaacfebc98001c23e.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;here is my NAC rule:&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="2ba31c98cda1463a939c42fa98611cf2.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/290i9B1EBEDB08AE83BD/image-size/large?v=v2&amp;amp;px=999" role="button" title="2ba31c98cda1463a939c42fa98611cf2.png" alt="2ba31c98cda1463a939c42fa98611cf2.png" /&gt;&lt;/span&gt;&lt;BR /&gt;Administrator NAC Profile uses &lt;STRONG&gt;Enterprise User (Administrator)&amp;nbsp;&lt;/STRONG&gt;policy&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="69e89a27e5e54519ad2ea45961dca627.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/4402i83B258AB902963D5/image-size/large?v=v2&amp;amp;px=999" role="button" title="69e89a27e5e54519ad2ea45961dca627.png" alt="69e89a27e5e54519ad2ea45961dca627.png" /&gt;&lt;/span&gt;&lt;BR /&gt;Policy Mapping for &lt;STRONG&gt;Enterprise User (Administrator)&lt;/STRONG&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="1d0f2bd046ea462f97a6fa5d6e5e3e4d.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/4723i9CA4DF362D151220/image-size/large?v=v2&amp;amp;px=999" role="button" title="1d0f2bd046ea462f97a6fa5d6e5e3e4d.png" alt="1d0f2bd046ea462f97a6fa5d6e5e3e4d.png" /&gt;&lt;/span&gt;&lt;BR /&gt;The switch:&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="6fd478f9722648b5b904776c5858c86a.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/899i78A8D954861023E9/image-size/large?v=v2&amp;amp;px=999" role="button" title="6fd478f9722648b5b904776c5858c86a.png" alt="6fd478f9722648b5b904776c5858c86a.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;Good luck&lt;BR /&gt;</description>
      <pubDate>Fri, 17 Dec 2021 11:03:12 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/this-user-does-not-have-permissions-for-this-command/m-p/82694#M9078</guid>
      <dc:creator>Zdeněk_Pala</dc:creator>
      <dc:date>2021-12-17T11:03:12Z</dc:date>
    </item>
    <item>
      <title>Re: This user does not have permissions for this command.</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/this-user-does-not-have-permissions-for-this-command/m-p/82695#M9079</link>
      <description>Thanks for your reply.&lt;BR /&gt;this is my configuration and it does not work &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;Giuseppe&lt;BR /&gt;&lt;BR /&gt;
&lt;DIV class="media" style="overflow: hidden"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="zXEAvPKTAukYhy5KiubA_Image 1.jpeg"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/2756i61B14F7FAE4E222C/image-size/large?v=v2&amp;amp;px=999" role="button" title="zXEAvPKTAukYhy5KiubA_Image 1.jpeg" alt="zXEAvPKTAukYhy5KiubA_Image 1.jpeg" /&gt;&lt;/span&gt;
&lt;DIV class="media" style="overflow: hidden"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="lGbmLLdjTntX12uKyvFM_Image 2.jpeg"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/1768i69F115D24268474C/image-size/large?v=v2&amp;amp;px=999" role="button" title="lGbmLLdjTntX12uKyvFM_Image 2.jpeg" alt="lGbmLLdjTntX12uKyvFM_Image 2.jpeg" /&gt;&lt;/span&gt;&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Fri, 17 Dec 2021 14:28:21 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/this-user-does-not-have-permissions-for-this-command/m-p/82695#M9079</guid>
      <dc:creator>Giuseppe_Montan</dc:creator>
      <dc:date>2021-12-17T14:28:21Z</dc:date>
    </item>
    <item>
      <title>Re: This user does not have permissions for this command.</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/this-user-does-not-have-permissions-for-this-command/m-p/82696#M9080</link>
      <description>hi Giuseppe.&lt;BR /&gt;&lt;BR /&gt;I can not read anything from your picture.</description>
      <pubDate>Fri, 17 Dec 2021 15:48:58 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/this-user-does-not-have-permissions-for-this-command/m-p/82696#M9080</guid>
      <dc:creator>Zdeněk_Pala</dc:creator>
      <dc:date>2021-12-17T15:48:58Z</dc:date>
    </item>
    <item>
      <title>Re: This user does not have permissions for this command.</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/this-user-does-not-have-permissions-for-this-command/m-p/82697#M9081</link>
      <description>Here my configuration.&lt;BR /&gt;&lt;BR /&gt;Giuseppe</description>
      <pubDate>Fri, 17 Dec 2021 16:10:38 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/this-user-does-not-have-permissions-for-this-command/m-p/82697#M9081</guid>
      <dc:creator>Giuseppe_Montan</dc:creator>
      <dc:date>2021-12-17T16:10:38Z</dc:date>
    </item>
    <item>
      <title>Re: This user does not have permissions for this command.</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/this-user-does-not-have-permissions-for-this-command/m-p/82698#M9082</link>
      <description>The AAA rule looks ok&lt;BR /&gt;The policy mapping looks ok.&lt;BR /&gt;&lt;BR /&gt;what about the rest of the config? I shared NAC rules, NAC profile, Switch config</description>
      <pubDate>Fri, 17 Dec 2021 16:23:01 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/this-user-does-not-have-permissions-for-this-command/m-p/82698#M9082</guid>
      <dc:creator>Zdeněk_Pala</dc:creator>
      <dc:date>2021-12-17T16:23:01Z</dc:date>
    </item>
    <item>
      <title>Re: This user does not have permissions for this command.</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/this-user-does-not-have-permissions-for-this-command/m-p/82699#M9083</link>
      <description>XMC Configuration and Switch configuration&lt;BR /&gt;&lt;BR /&gt;Giuseppe</description>
      <pubDate>Fri, 17 Dec 2021 16:42:17 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/this-user-does-not-have-permissions-for-this-command/m-p/82699#M9083</guid>
      <dc:creator>Giuseppe_Montan</dc:creator>
      <dc:date>2021-12-17T16:42:17Z</dc:date>
    </item>
    <item>
      <title>Re: This user does not have permissions for this command.</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/this-user-does-not-have-permissions-for-this-command/m-p/82700#M9084</link>
      <description>still missing the NAC rule that should match.&lt;BR /&gt;Can you share PCAP of the radius access accept?</description>
      <pubDate>Fri, 17 Dec 2021 17:07:21 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/this-user-does-not-have-permissions-for-this-command/m-p/82700#M9084</guid>
      <dc:creator>Zdeněk_Pala</dc:creator>
      <dc:date>2021-12-17T17:07:21Z</dc:date>
    </item>
    <item>
      <title>Re: This user does not have permissions for this command.</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/this-user-does-not-have-permissions-for-this-command/m-p/82701#M9085</link>
      <description>Hi, on NAC and XMC I have only tcpdump, is possible to install tshark ?&lt;BR /&gt;&lt;BR /&gt;Giuseppe</description>
      <pubDate>Fri, 17 Dec 2021 18:42:09 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/this-user-does-not-have-permissions-for-this-command/m-p/82701#M9085</guid>
      <dc:creator>Giuseppe_Montan</dc:creator>
      <dc:date>2021-12-17T18:42:09Z</dc:date>
    </item>
    <item>
      <title>Re: This user does not have permissions for this command.</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/this-user-does-not-have-permissions-for-this-command/m-p/82702#M9086</link>
      <description>&lt;P&gt;you can execute this command:&lt;BR /&gt;tcpdump -ni eth0 port 1812 -w /tmp/mypcap.pcap&lt;BR /&gt;&lt;BR /&gt;then you can download the pcap file.&lt;BR /&gt;other option is to use GUI of the NAC engine and start the packet capture there&lt;BR /&gt;---&lt;BR /&gt;regarding your screenshots:&lt;/P&gt;
&lt;P&gt;- is your user part of the user group condition&lt;BR /&gt;- is your switch part of the location condition&lt;/P&gt;</description>
      <pubDate>Fri, 17 Dec 2021 18:58:27 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/this-user-does-not-have-permissions-for-this-command/m-p/82702#M9086</guid>
      <dc:creator>Zdeněk_Pala</dc:creator>
      <dc:date>2021-12-17T18:58:27Z</dc:date>
    </item>
    <item>
      <title>Re: This user does not have permissions for this command.</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/this-user-does-not-have-permissions-for-this-command/m-p/82703#M9087</link>
      <description>Thanks for your help,&lt;BR /&gt;this evening I did a restore from a previous version and everything works apart that the rule that permit a login is not a rule "management login " but is the Default-Catch-rule.&lt;BR /&gt;I will check the next day&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;BR /&gt;Giuseppe</description>
      <pubDate>Sat, 18 Dec 2021 00:44:29 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/this-user-does-not-have-permissions-for-this-command/m-p/82703#M9087</guid>
      <dc:creator>Giuseppe_Montan</dc:creator>
      <dc:date>2021-12-18T00:44:29Z</dc:date>
    </item>
    <item>
      <title>Re: This user does not have permissions for this command.</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/this-user-does-not-have-permissions-for-this-command/m-p/82704#M9088</link>
      <description>I have the same issue but I am authenticating my users through Freeradius in linux. Below is attribute configuration.&lt;BR /&gt;How would I allow this user to run " Show configuration" for sake of taking regular backup ?&lt;BR /&gt;&lt;BR /&gt;USER1 Cleartext-password := password&lt;BR /&gt;Filter-id = "Enterasys:version=1:mgmt=ro"</description>
      <pubDate>Wed, 30 Mar 2022 10:04:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/this-user-does-not-have-permissions-for-this-command/m-p/82704#M9088</guid>
      <dc:creator>JASU</dc:creator>
      <dc:date>2022-03-30T10:04:00Z</dc:date>
    </item>
    <item>
      <title>Re: This user does not have permissions for this command.</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/this-user-does-not-have-permissions-for-this-command/m-p/82705#M9089</link>
      <description>&lt;SPAN&gt;&lt;SPAN&gt;The MGMT access level to different OS depends on the radius attributes. The picture in my first response shows what attributes and what values should be used. Different response is expected by different OS.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;</description>
      <pubDate>Wed, 30 Mar 2022 10:13:33 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/this-user-does-not-have-permissions-for-this-command/m-p/82705#M9089</guid>
      <dc:creator>Zdeněk_Pala</dc:creator>
      <dc:date>2022-03-30T10:13:33Z</dc:date>
    </item>
    <item>
      <title>Re: This user does not have permissions for this command.</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/this-user-does-not-have-permissions-for-this-command/m-p/82706#M9090</link>
      <description>Thanks for your answer. However, I am not expert in this area of attribute interpretation into acceptable script by radius server. So can you guide me how the script should look like in the Users file for read-only user, and read-write user ? &lt;BR /&gt;I have ExtremeXOS version 16.2.2.4 &amp;amp; ExtremeXOS version 15.3.1.4 switches.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;By the way, when I used below syntax with 16.2 in the Users file, it was assigning the right privilege, ro/rw/su. But with 15.3, it always authorize user with read-only regardless of the keyword I use.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;USER1 Cleartext-password := password&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Filter-id = "Enterasys:version=1:mgmt=ro"&lt;/SPAN&gt;</description>
      <pubDate>Wed, 30 Mar 2022 11:35:15 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/this-user-does-not-have-permissions-for-this-command/m-p/82706#M9090</guid>
      <dc:creator>JASU</dc:creator>
      <dc:date>2022-03-30T11:35:15Z</dc:date>
    </item>
    <item>
      <title>Re: This user does not have permissions for this command.</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/this-user-does-not-have-permissions-for-this-command/m-p/82707#M9091</link>
      <description>You are correct. this feature was enhanced in 16.x code and EXOS now supports both the original EXOS and EOS options.&lt;BR /&gt;&lt;BR /&gt;This should give you Admin:&lt;BR /&gt;&lt;CODE&gt;&lt;SPAN&gt;USER1 Cleartext-password := password&lt;/SPAN&gt;&lt;/CODE&gt;&lt;BR /&gt;&lt;SPAN&gt;&lt;CODE&gt;Service-Type = Administrative&lt;/CODE&gt;&lt;BR /&gt;&lt;BR /&gt;This should give you Read Only:&lt;BR /&gt;&lt;CODE&gt;USER2 Cleartext-password := password&lt;/CODE&gt;&lt;BR /&gt;&lt;CODE&gt;Service-Type = Login&lt;/CODE&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;</description>
      <pubDate>Wed, 30 Mar 2022 12:42:17 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/this-user-does-not-have-permissions-for-this-command/m-p/82707#M9091</guid>
      <dc:creator>Zdeněk_Pala</dc:creator>
      <dc:date>2022-03-30T12:42:17Z</dc:date>
    </item>
    <item>
      <title>Re: This user does not have permissions for this command.</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/this-user-does-not-have-permissions-for-this-command/m-p/82708#M9092</link>
      <description>Is there a way to grant the user with read-only privilege to run "Show configuration" ? Or any equivalent command to show complete configuration ?</description>
      <pubDate>Wed, 30 Mar 2022 14:32:51 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/this-user-does-not-have-permissions-for-this-command/m-p/82708#M9092</guid>
      <dc:creator>JASU</dc:creator>
      <dc:date>2022-03-30T14:32:51Z</dc:date>
    </item>
    <item>
      <title>Re: This user does not have permissions for this command.</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/this-user-does-not-have-permissions-for-this-command/m-p/82709#M9093</link>
      <description>The per-command authorization can be used for this purpose. The EXOS needs to be configured to request permission for each command. the Radius needs to approve/reject each command.</description>
      <pubDate>Wed, 30 Mar 2022 14:43:16 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/this-user-does-not-have-permissions-for-this-command/m-p/82709#M9093</guid>
      <dc:creator>Zdeněk_Pala</dc:creator>
      <dc:date>2022-03-30T14:43:16Z</dc:date>
    </item>
    <item>
      <title>Re: This user does not have permissions for this command.</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/this-user-does-not-have-permissions-for-this-command/m-p/82710#M9094</link>
      <description>Would you share example to show steps from both switch &amp;amp; radius server ?</description>
      <pubDate>Wed, 30 Mar 2022 15:54:29 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/this-user-does-not-have-permissions-for-this-command/m-p/82710#M9094</guid>
      <dc:creator>JASU</dc:creator>
      <dc:date>2022-03-30T15:54:29Z</dc:date>
    </item>
    <item>
      <title>Re: This user does not have permissions for this command.</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/this-user-does-not-have-permissions-for-this-command/m-p/82711#M9095</link>
      <description>Sorry. It is more complex. Here is the documentation for EXOS 16.1 = https://documentation.extremenetworks.com/exos_16.1/downloads/GUID-D14940D6-7F4E-4084-A9BD-069AA223D632.pdf&lt;BR /&gt;What you need is the Security section, pages 951+&lt;BR /&gt;&lt;BR /&gt;In general you need to authenticate the user through Radius with Extreme-CLI-Authorization = enabled.&lt;BR /&gt;then you will receive each command through radius request and Access-accept means the command can be executed. Access-reject means the command execution is rejected.</description>
      <pubDate>Thu, 31 Mar 2022 00:10:50 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/this-user-does-not-have-permissions-for-this-command/m-p/82711#M9095</guid>
      <dc:creator>Zdeněk_Pala</dc:creator>
      <dc:date>2022-03-31T00:10:50Z</dc:date>
    </item>
  </channel>
</rss>

