<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Radius authentication with ISE and Nexus 7k in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/radius-authentication-with-ise-and-nexus-7k/m-p/2181010#M137838</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i am trying to assign a right role for a user who authenticates to nexus 7k switch via radius. i am using cisco ISE version 1.1.1.268 and the nexus version is&amp;nbsp;&amp;nbsp;&amp;nbsp; 5.0.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have created a role on nexus &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;role name network-XXX&lt;/P&gt;&lt;P&gt;&amp;nbsp; rule 2 permit read&lt;/P&gt;&lt;P&gt;&amp;nbsp; rule 1 permit command show running-config&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;on the ise , i have created an authorization profile :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cisco:cisco-av-pair= shell:roles*"network-XXX"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;on the ise authentication result , i can see that the "network-XXX" is passed on to Nexus, but the switch fails to understand it and doesnt allow me to issue the command show running-config.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i have tried various iterations on ISE attribute. i.e &lt;/P&gt;&lt;P&gt;shell:roles*"network-operator network-XXX"&lt;/P&gt;&lt;P&gt;shell:roles=network-XXX&lt;/P&gt;&lt;P&gt;shell:roles*"network-XXX vdc-admin"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;none of them seem to work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any one with any ideas?&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 03:14:05 GMT</pubDate>
    <dc:creator>Manish Patel</dc:creator>
    <dc:date>2019-03-11T03:14:05Z</dc:date>
    <item>
      <title>Radius authentication with ISE and Nexus 7k</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-authentication-with-ise-and-nexus-7k/m-p/2181010#M137838</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i am trying to assign a right role for a user who authenticates to nexus 7k switch via radius. i am using cisco ISE version 1.1.1.268 and the nexus version is&amp;nbsp;&amp;nbsp;&amp;nbsp; 5.0.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have created a role on nexus &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;role name network-XXX&lt;/P&gt;&lt;P&gt;&amp;nbsp; rule 2 permit read&lt;/P&gt;&lt;P&gt;&amp;nbsp; rule 1 permit command show running-config&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;on the ise , i have created an authorization profile :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cisco:cisco-av-pair= shell:roles*"network-XXX"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;on the ise authentication result , i can see that the "network-XXX" is passed on to Nexus, but the switch fails to understand it and doesnt allow me to issue the command show running-config.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i have tried various iterations on ISE attribute. i.e &lt;/P&gt;&lt;P&gt;shell:roles*"network-operator network-XXX"&lt;/P&gt;&lt;P&gt;shell:roles=network-XXX&lt;/P&gt;&lt;P&gt;shell:roles*"network-XXX vdc-admin"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;none of them seem to work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any one with any ideas?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 03:14:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-authentication-with-ise-and-nexus-7k/m-p/2181010#M137838</guid>
      <dc:creator>Manish Patel</dc:creator>
      <dc:date>2019-03-11T03:14:05Z</dc:date>
    </item>
    <item>
      <title>Radius authentication with ISE and Nexus 7k</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-authentication-with-ise-and-nexus-7k/m-p/2181011#M137872</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Manish,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The switch that you hev deployed i.e Nexus 7k series, does not support the features of ISE 1.1.1. For your reference please go through the link below:-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/ise/1.1/compatibility/ise_sdt.html"&gt;http://www.cisco.com/en/US/docs/security/ise/1.1/compatibility/ise_sdt.html&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 06 Apr 2013 02:53:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-authentication-with-ise-and-nexus-7k/m-p/2181011#M137872</guid>
      <dc:creator>harvisin</dc:creator>
      <dc:date>2013-04-06T02:53:47Z</dc:date>
    </item>
    <item>
      <title>Hello Harvisin,</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-authentication-with-ise-and-nexus-7k/m-p/2181012#M137909</link>
      <description>&lt;P&gt;Hello Harvisin,&lt;/P&gt;
&lt;P&gt;Do Nexus support radius authentication with ISE 1.3??. All the access switches we have integrated for&lt;/P&gt;
&lt;P&gt;for AAA/Radius authentication with ISE.&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/security/ise/1-3/compatibility/ise_sdt.html&lt;/P&gt;
&lt;P&gt;Nexus are not reflecting in the above ISE 1.3 compatibility matrix chart.&lt;/P&gt;
&lt;P&gt;Regards,&lt;BR /&gt;Deepu&lt;/P&gt;</description>
      <pubDate>Wed, 13 Apr 2016 08:29:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-authentication-with-ise-and-nexus-7k/m-p/2181012#M137909</guid>
      <dc:creator>deepuvarghese1</dc:creator>
      <dc:date>2016-04-13T08:29:54Z</dc:date>
    </item>
  </channel>
</rss>

