<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: TACACS+ with EXOS 16.2.5 in ExtremeSwitching (EXOS/Switch Engine)</title>
    <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/tacacs-with-exos-16-2-5/m-p/97110#M22059</link>
    <description>&lt;P&gt;Ensure your TACACS+ server provides the correct attributes that EXOS understands to elevate user permissions. On the TACACS+ server side, you might need to adjust the service or priv-lvl attributes for proper interpretation by EXOS. Consider reviewing the EXOS documentation or reaching out to Extreme Networks' support for specific TACACS+ attributes they use for privilege levels.&lt;/P&gt;</description>
    <pubDate>Thu, 07 Sep 2023 09:38:43 GMT</pubDate>
    <dc:creator>Meganbond</dc:creator>
    <dc:date>2023-09-07T09:38:43Z</dc:date>
    <item>
      <title>TACACS+ with EXOS 16.2.5</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/tacacs-with-exos-16-2-5/m-p/97105#M22058</link>
      <description>&lt;P&gt;Good afternoon,&lt;/P&gt;&lt;P&gt;we have some Extreme Networks swtiches with EXOS running that we would like to authenticate against our TACACS+ Server (tac_plus on Linux). I set up the authentication on the switches with&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier" size="2"&gt;configure tacacs primary server 192.168.224.69 49 client-ip 192.178.14.5 vr VR-Default&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;configure tacacs primary shared-secret encrypted ##REMOVED##&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;configure tacacs-accounting primary server 192.168.224.69 49 client-ip 192.178.14.5 vr VR-Default&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;configure tacacs-accounting primary shared-secret encrypted ##REMOVED##&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;enable tacacs&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;enable tacacs-accounting&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;enable tacacs-authorization&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On the tac_plus Server I have&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier" size="2"&gt;service = Extreme-XMC-Auth {&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;&amp;nbsp; &amp;nbsp;set local-user-name=remote-su&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;}&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;service = ppp {&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;&amp;nbsp; &amp;nbsp;set priv-lvl=15&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;&amp;nbsp; &amp;nbsp;set shell:roles=sysadmin&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;}&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are able to login with the TACACS+ users but they are always recognized as exec level users.&lt;BR /&gt;The admin users (priv-lvl=15) are ignored by EXOS. Unfortunately I can not find the required attributes to fix this at the forum or the EXOS manuals.&lt;/P&gt;&lt;P&gt;Could anyone help me with this?&lt;/P&gt;</description>
      <pubDate>Wed, 06 Sep 2023 14:33:26 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/tacacs-with-exos-16-2-5/m-p/97105#M22058</guid>
      <dc:creator>Mike84</dc:creator>
      <dc:date>2023-09-06T14:33:26Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS+ with EXOS 16.2.5</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/tacacs-with-exos-16-2-5/m-p/97110#M22059</link>
      <description>&lt;P&gt;Ensure your TACACS+ server provides the correct attributes that EXOS understands to elevate user permissions. On the TACACS+ server side, you might need to adjust the service or priv-lvl attributes for proper interpretation by EXOS. Consider reviewing the EXOS documentation or reaching out to Extreme Networks' support for specific TACACS+ attributes they use for privilege levels.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Sep 2023 09:38:43 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/tacacs-with-exos-16-2-5/m-p/97110#M22059</guid>
      <dc:creator>Meganbond</dc:creator>
      <dc:date>2023-09-07T09:38:43Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS+ with EXOS 16.2.5</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/tacacs-with-exos-16-2-5/m-p/97111#M22060</link>
      <description>&lt;P&gt;Maybe you need to add a command set permit all like mentioned in this article ?&lt;/P&gt;&lt;P&gt;&lt;A href="https://extreme-networks.my.site.com/ExtrArticleDetail?an=000078779" target="_blank"&gt;https://extreme-networks.my.site.com/ExtrArticleDetail?an=000078779&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Sep 2023 12:34:36 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/tacacs-with-exos-16-2-5/m-p/97111#M22060</guid>
      <dc:creator>OscarK</dc:creator>
      <dc:date>2023-09-07T12:34:36Z</dc:date>
    </item>
  </channel>
</rss>

