Hı All, I got the following info when debugging from radiator:
INFO: Authorization denied for tacuser7, group DEFAULT. No matching
AuthorizeGroup rule for args service=shell cmd=show cmd-arg=version
My Config is below. I give the name of the group to group 1 but still shows
group name DEFAULT when debugging.When I change the group name to DEFAULT it is
ok.Why can I not use the group name as group 1.
Thanks
<ServerTACACSPLUS>
# AddToRequest OSC-Environment-Identifier=Tacacs
AddToRequest NAS-Identifier=TACACS
# AuthorizeGroup tacuser3 permit service=shell cmd\* {priv-lvl=15}
GroupMemberAttr group1
AuthorizeGroupAttr group1 permit service=shell cmd=show cmd-args=.*
# AddToRequest OSC-Group-Identifier = tacuser3
# AddToRequest OSC-Group-Identifier = tac
AuthorizeGroup group1 permit service=shell cmd=show cmd-args=.*
AuthorizeGroup group1 permit .*
</ServerTACACSPLUS>
MURAT BİLAL
Services Engineer
Ericsson Turkey
CU Customer Support
Cyber Plaza C Blok Kat:1 No:146
Cyberpark 6800 Bilkent/Ankara
Mobile +90 554 898 98 43
[email protected]<mailto:[email protected]>
www.ericsson.com
[cid:[email protected]]<http://www.ericsson.com/>
This Communication is Confidential. We only send and receive email on the basis
of the terms set out at
www.ericsson.com/email_disclaimer<http://www.ericsson.com/email_disclaimer>
<<inline: image001.png>>
_______________________________________________ radiator mailing list [email protected] http://www.open.com.au/mailman/listinfo/radiator
