Use ACE/Server RADIUS to control enable access to Cisco Router
Originally Published: 2002-01-10
Article Number
Applies To
RADIUS
Cisco Router
Issue
Not able to give enable access privileges to users authenticating via RADIUS
Cause
Resolution
This configuration would be enabled using this command on the router:
aaa authorization exec default radius
On the ACE/Server administration interface:
Profile--> Add Profile
Name the profile appropriately
Add the attribute(s):
1. Service-Type
This attribute can be set to login (Regular User) or administrative-user
2. For further granularity of enable privileges add:
Vendor-Specific
Set the value to: 9 1 "shell:priv-lvl=15" (the 15 can range from 1 to 15 depending on your router enable privilege config)
Related Articles
Radius Client Authentication failed For PIN+Token profile (New PIN Mode) with Cisco Anyconnect VPN 603Number of Views RSA ACE/Server RADIUS authentication fails when coming from Cisco Router 26Number of Views Radius Client Authentication failed For PIN+Token profile (New PIN Mode) with Cisco Anyconnect VPN 125Number of Views Errors: ?User not in database? and 'User not on Agent Host' in ACE/Server activity log when trying to authenticate via RAD… 77Number of Views "Invalid authentication handle" reported by the Cisco AnyConnect client when using RSA SecurID Access Cloud Authentication… 242Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Step 3: Test with Your Identity Source and All Applications Microsoft Entra ID - SCIM Client for Cloud Authentication Service - RSA Ready Implementation Guide Disable multi-factor authentication (MFA) prompt for "Run as" on machine on which the RSA MFA Agent for Microsoft Windows … RSA MFA Agent 3.0 for Microsoft AD FS Administrator's Guide
Don't see what you're looking for?