I was able to read through the CPPM User Deployment guide and find how to build a basic Authentication Service that looks for membership in my device group for Routers and Switches, using the TACACS+ Protocol, and then uses AD Pass through to look for AD Group Membership to allow access to my Cisco gear. Now I am looking to add in Tacacs Enforcment (I believe) to support command authorization. I have seen a number of posts here that list troubles they have, but not how they even got that far? Is there a "How-To" for building up the bits needed in to get started? Say I wanted the user to come in with Priv=15, yet only be able to run commands " show .* "?
I figure just one example would set me loose on the rest of the variations I need.
Nick