Connectrix Brocade:在交換器上執行命令時,TACACS 認證失敗「RBAC permission denied」
Summary: 在交換器上執行命令時,TACACS 驗證失敗,並出現錯誤「RBAC permission denied」。
This article applies to
This article does not apply to
This article is not tied to any specific product.
Not all product versions are identified in this article.
Symptoms
已成功在交換器上設定 TACACS 伺服器。
AAA 使用者的命令在交換器上執行失敗。
收到的錯誤訊息:
Switch:AAA_User> chassisshow RBAC permission denied. Switch:AAA_User> psshow RBAC permission denied.
根據有權訪問 RBAC 類「身份驗證」的角色是:
Switch:> classconfig --showroles authentication Role name Permission --------- ---------- Admin OM Root OM Security Admin OM
Cause
在 TACACS Server 的 shell 設定檔中,觀察到 brcd 角色已對應至「zoneAdmin」:
螢幕擷取畫面供參考:
Resolution
在 TACACS+ 伺服器上,已使用正確的角色修改 「tac_plus.cfg 檔案」 中的屬性,以解決此問題:
屬性集:
- brcd-role=admin
- Brcd-AV-Pair1=homeLF=128;LFRoleList=admin:1-128
- Brcd-AV-Pair2=chassisRole=admin
Affected Products
Connectrix B-Series HardwareProducts
Connectrix B-SeriesArticle Properties
Article Number: 000224122
Article Type: Solution
Last Modified: 15 Apr 2025
Version: 2
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.