Thank you, was a setting on OpenGear that needed to be made. They had a a netgrp that automatically provided admin permissions, once group was disabled authorization was working.
Original Message:
Sent: May 18, 2023 01:58 PM
From: ahollifield
Subject: Authorization using TACACS+
Based on that screenshot, ClearPass is responding with the Deny. So the OpenGear seems not to be listening to that or doesn't know what to do with it. What do the OpenGear logs say? What TACACS+ attributes does the OpenGear require?
Original Message:
Sent: May 18, 2023 12:16 PM
From: afasanella
Subject: Authorization using TACACS+
Service is enabled and just realized I am getting authorization to work for the group I want it to but when a user who should not be able to access device attempts to they are getting authenticated and though authorization is failing, and they are able to access the device. They get assigned [other] role and TACACS+ deny Profile should be enforced.

Original Message:
Sent: May 18, 2023 10:03 AM
From: ahollifield
Subject: Authorization using TACACS+
Is the Service not enabled?