<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic About Tacacs authorization and authentication in ExtremeSwitching (EXOS/Switch Engine)</title>
    <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/about-tacacs-authorization-and-authentication/m-p/50085#M13393</link>
    <description>Hello,&lt;BR /&gt;
&lt;BR /&gt;
We got demo Extreme network switch to our company for trying it. Actually we have all Cİsco switch and we manage them but we want to try extreme network switch. &lt;BR /&gt;
&lt;BR /&gt;
We worked commands of Tacacs by demo extreme switch and i logged in with my username and password. But i cannot do nothing in the switch, i just readonly it. why ?&lt;BR /&gt;
&lt;BR /&gt;
And you can see below about CİSCO command and EXTREME command. What's the different please help me about that ?&lt;BR /&gt;
.&lt;BR /&gt;
CİSCO:&lt;BR /&gt;
&lt;BR /&gt;
tacacs-server host X.X.X.X key yyyy&lt;BR /&gt;
tacacs-server host X.X.X.X key yyyy&lt;BR /&gt;
tacacs-server directed-request&lt;BR /&gt;
&lt;BR /&gt;
aaa new model&lt;BR /&gt;
aaa authentication login use-tacacs group tacacs+ local enable&lt;BR /&gt;
aaa authentication enable default group tacacs+ enable&lt;BR /&gt;
aaa authorization exec use-tacacs group tacacs+ local&lt;BR /&gt;
aaa accounting commands 0 default start-stop group tacacs+&lt;BR /&gt;
aaa accounting commands 1 default start-stop group tacacs+&lt;BR /&gt;
aaa accounting commands 15 default start-stop group tacacs+&lt;BR /&gt;
&lt;BR /&gt;
EXTREME:&lt;BR /&gt;
&lt;BR /&gt;
configure tacacs primary server X.X.X.X client-ip Z.Z.Z.Z vr "VR-Default"&lt;BR /&gt;
configure tacacs primary shared-secret yyyy&lt;BR /&gt;
configure tacacs secondary server T.T.T.T client-ip Z.Z.Z.Z vr "VR-Default"&lt;BR /&gt;
configure tacacs secondary shared-secret yyyy&lt;BR /&gt;
enable tacacs&lt;BR /&gt;
&lt;BR /&gt;
configure tacacs-accounting primary server X.X.X.X client-ip Z.Z.Z.Z vr "VR-Default"&lt;BR /&gt;
configure tacacs-accounting primary shared-secret yyyy&lt;BR /&gt;
configure tacacs-accounting secondary server T.T.T.T client-ip Z.Z.Z.Z vr "VR-Default"&lt;BR /&gt;
configure tacacs-accounting secondary shared-secret yyyy&lt;BR /&gt;
enable tacacs-accounting&lt;BR /&gt;
&lt;BR /&gt;
Thanks for your support</description>
    <pubDate>Sun, 04 Mar 2018 18:19:00 GMT</pubDate>
    <dc:creator>Nusraddin</dc:creator>
    <dc:date>2018-03-04T18:19:00Z</dc:date>
    <item>
      <title>About Tacacs authorization and authentication</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/about-tacacs-authorization-and-authentication/m-p/50085#M13393</link>
      <description>Hello,&lt;BR /&gt;
&lt;BR /&gt;
We got demo Extreme network switch to our company for trying it. Actually we have all Cİsco switch and we manage them but we want to try extreme network switch. &lt;BR /&gt;
&lt;BR /&gt;
We worked commands of Tacacs by demo extreme switch and i logged in with my username and password. But i cannot do nothing in the switch, i just readonly it. why ?&lt;BR /&gt;
&lt;BR /&gt;
And you can see below about CİSCO command and EXTREME command. What's the different please help me about that ?&lt;BR /&gt;
.&lt;BR /&gt;
CİSCO:&lt;BR /&gt;
&lt;BR /&gt;
tacacs-server host X.X.X.X key yyyy&lt;BR /&gt;
tacacs-server host X.X.X.X key yyyy&lt;BR /&gt;
tacacs-server directed-request&lt;BR /&gt;
&lt;BR /&gt;
aaa new model&lt;BR /&gt;
aaa authentication login use-tacacs group tacacs+ local enable&lt;BR /&gt;
aaa authentication enable default group tacacs+ enable&lt;BR /&gt;
aaa authorization exec use-tacacs group tacacs+ local&lt;BR /&gt;
aaa accounting commands 0 default start-stop group tacacs+&lt;BR /&gt;
aaa accounting commands 1 default start-stop group tacacs+&lt;BR /&gt;
aaa accounting commands 15 default start-stop group tacacs+&lt;BR /&gt;
&lt;BR /&gt;
EXTREME:&lt;BR /&gt;
&lt;BR /&gt;
configure tacacs primary server X.X.X.X client-ip Z.Z.Z.Z vr "VR-Default"&lt;BR /&gt;
configure tacacs primary shared-secret yyyy&lt;BR /&gt;
configure tacacs secondary server T.T.T.T client-ip Z.Z.Z.Z vr "VR-Default"&lt;BR /&gt;
configure tacacs secondary shared-secret yyyy&lt;BR /&gt;
enable tacacs&lt;BR /&gt;
&lt;BR /&gt;
configure tacacs-accounting primary server X.X.X.X client-ip Z.Z.Z.Z vr "VR-Default"&lt;BR /&gt;
configure tacacs-accounting primary shared-secret yyyy&lt;BR /&gt;
configure tacacs-accounting secondary server T.T.T.T client-ip Z.Z.Z.Z vr "VR-Default"&lt;BR /&gt;
configure tacacs-accounting secondary shared-secret yyyy&lt;BR /&gt;
enable tacacs-accounting&lt;BR /&gt;
&lt;BR /&gt;
Thanks for your support</description>
      <pubDate>Sun, 04 Mar 2018 18:19:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/about-tacacs-authorization-and-authentication/m-p/50085#M13393</guid>
      <dc:creator>Nusraddin</dc:creator>
      <dc:date>2018-03-04T18:19:00Z</dc:date>
    </item>
    <item>
      <title>RE: About Tacacs authorization and authentication</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/about-tacacs-authorization-and-authentication/m-p/50086#M13394</link>
      <description>Hello,&lt;BR /&gt;
&lt;BR /&gt;
I don't see the line&lt;BR /&gt;
   enable tacacs-authorization&lt;BR /&gt;
in your config. Could that be it?&lt;BR /&gt;
&lt;BR /&gt;
If you have that line, then I think you might lack the appropriate "allow commands" lines on the tacacs server configuration. Since you mention you're used to run Cisco, I'm assuming you're using Cisco's TACACS+ server (or whatever it's called), and I don't know much about that one.&lt;BR /&gt;
I'm using one of the open tacacs+ implementations, so my config will be different from yours.&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Mon, 05 Mar 2018 16:31:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/about-tacacs-authorization-and-authentication/m-p/50086#M13394</guid>
      <dc:creator>Frank</dc:creator>
      <dc:date>2018-03-05T16:31:00Z</dc:date>
    </item>
    <item>
      <title>RE: About Tacacs authorization and authentication</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/about-tacacs-authorization-and-authentication/m-p/50087#M13395</link>
      <description>Hello Frank,&lt;BR /&gt;
&lt;BR /&gt;
i did "enable tacacs-authorization" but its still not working... I dont know what can i do about that ? Thanks for reply</description>
      <pubDate>Tue, 06 Mar 2018 13:07:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/about-tacacs-authorization-and-authentication/m-p/50087#M13395</guid>
      <dc:creator>Nusraddin</dc:creator>
      <dc:date>2018-03-06T13:07:00Z</dc:date>
    </item>
    <item>
      <title>RE: About Tacacs authorization and authentication</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/about-tacacs-authorization-and-authentication/m-p/50088#M13396</link>
      <description>In that case I think there's something missing on the TACACS server.&lt;BR /&gt;
In my config the "can do everything" user has these entries:&lt;BR /&gt;
&lt;BR /&gt;
        &lt;B&gt;default service = permit&lt;/B&gt;&lt;BR /&gt;
        &lt;I&gt;service = shell {&lt;/I&gt;&lt;BR /&gt;
                &lt;B&gt;default command = permit&lt;/B&gt;&lt;BR /&gt;
                &lt;B&gt;default attribute = permit&lt;/B&gt;&lt;BR /&gt;
                set priv-lvl = 15&lt;BR /&gt;
                set cvp-roles="network-admin"&lt;BR /&gt;
        } &lt;BR /&gt;
But I'm also not using cisco-tacacs, so your syntax might be different. I think the "set priv-lvl" and "cvp-roles" entries are not used by Extreme, they are for other devices. I don't think Extreme has the "priv-lvl" concept in the way that cisco has it.&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Tue, 06 Mar 2018 17:22:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/about-tacacs-authorization-and-authentication/m-p/50088#M13396</guid>
      <dc:creator>Frank</dc:creator>
      <dc:date>2018-03-06T17:22:00Z</dc:date>
    </item>
    <item>
      <title>RE: About Tacacs authorization and authentication</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/about-tacacs-authorization-and-authentication/m-p/50089#M13397</link>
      <description>Hi Frank,&lt;BR /&gt;
&lt;BR /&gt;
This script has worked and problem solved..  &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;
&lt;BR /&gt;
Thanks for your support.</description>
      <pubDate>Tue, 06 Mar 2018 17:58:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/about-tacacs-authorization-and-authentication/m-p/50089#M13397</guid>
      <dc:creator>Nusraddin</dc:creator>
      <dc:date>2018-03-06T17:58:00Z</dc:date>
    </item>
    <item>
      <title>Re: RE: About Tacacs authorization and authentication</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/about-tacacs-authorization-and-authentication/m-p/97199#M22079</link>
      <description>&lt;P&gt;Hi Frank,&lt;/P&gt;&lt;P&gt;I am using the open tacacs+ implementation (tac_plus) too. I configured it as you showed within this thread but unfortunately it is not working for our Extreme switches running EXOS, they are always logging with user/exec level instead of admin/privileged level. Do you have any hint for me how to debug/solve this?&lt;/P&gt;</description>
      <pubDate>Tue, 19 Sep 2023 08:15:36 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/about-tacacs-authorization-and-authentication/m-p/97199#M22079</guid>
      <dc:creator>Mike84</dc:creator>
      <dc:date>2023-09-19T08:15:36Z</dc:date>
    </item>
  </channel>
</rss>

