<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Actually I tried the to point in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/using-otp-for-authentication-and-ise-for-authorization-in-cisco/m-p/3045278#M24323</link>
    <description>&lt;P&gt;Actually I tried the to point the Authorization to the ISE but my users kept login in to the switch with privilege 15 (sadly :d).&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;You are right. I'm gonna test it and get back to you with the results. Thanks.&lt;/P&gt;</description>
    <pubDate>Tue, 31 Jan 2017 17:38:17 GMT</pubDate>
    <dc:creator>mesarasimth1</dc:creator>
    <dc:date>2017-01-31T17:38:17Z</dc:date>
    <item>
      <title>using OTP for Authentication and ISE for Authorization in Cisco Switches</title>
      <link>https://community.cisco.com/t5/network-access-control/using-otp-for-authentication-and-ise-for-authorization-in-cisco/m-p/3045274#M24310</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I was wondering if it is possible to Authenticate users with radius server and Authorize them with ISE when they want to login to my switch through VTY lines. (my radius server is OTP and it does not support tacacs so i need to authenticate my secondary admins with my OTP server and authorize them with ISE tacacs so they&amp;nbsp;login with lower privilege). Can i do this?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 07:23:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/using-otp-for-authentication-and-ise-for-authorization-in-cisco/m-p/3045274#M24310</guid>
      <dc:creator>mesarasimth1</dc:creator>
      <dc:date>2019-03-11T07:23:35Z</dc:date>
    </item>
    <item>
      <title>If you are just looking to</title>
      <link>https://community.cisco.com/t5/network-access-control/using-otp-for-authentication-and-ise-for-authorization-in-cisco/m-p/3045275#M24314</link>
      <description>&lt;P&gt;If you are just looking to assign privilege levels to the user, you don't need to use TACACS - you can use RADIUS to do that using Cisco A/V pairs. The Radius auth can be forwarded to a token server on ISE and the subsequent Authorization can send Access-Accept with the right shell-privilege. A good example of that is here:&lt;/P&gt;
&lt;P&gt;https://www.youtube.com/watch?v=VH98hTMeEvk&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jan 2017 14:48:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/using-otp-for-authentication-and-ise-for-authorization-in-cisco/m-p/3045275#M24314</guid>
      <dc:creator>Rahul Govindan</dc:creator>
      <dc:date>2017-01-24T14:48:06Z</dc:date>
    </item>
    <item>
      <title>Thanks for you reply.</title>
      <link>https://community.cisco.com/t5/network-access-control/using-otp-for-authentication-and-ise-for-authorization-in-cisco/m-p/3045276#M24317</link>
      <description>&lt;P&gt;Thanks for you reply. Actually i should've mentioned that I'm using a radius server which is an OTP and I'm authenticating my users via that server not ISE. and also the users on my OTP&amp;nbsp;server are local which means they have not been fetched from Active Directory. My question is, can i connect the OTP to ISE(with this condition that my OTP users have different password when they login to sitches and ISE that just check the username and not their password), so when my users authenticate with OTP the ISE authorization be assigned to them?&lt;/P&gt;
&lt;P&gt;* My OTP server is webadm openotp.&lt;/P&gt;
&lt;P&gt;Sorry, but i'm new to aaa servers and I'm trying to learn...&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jan 2017 08:38:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/using-otp-for-authentication-and-ise-for-authorization-in-cisco/m-p/3045276#M24317</guid>
      <dc:creator>mesarasimth1</dc:creator>
      <dc:date>2017-01-27T08:38:16Z</dc:date>
    </item>
    <item>
      <title>I really haven't tried this,</title>
      <link>https://community.cisco.com/t5/network-access-control/using-otp-for-authentication-and-ise-for-authorization-in-cisco/m-p/3045277#M24321</link>
      <description>&lt;P&gt;I really haven't tried this, but you could try changing the "aaa authorization exec" command to point to the ISE&amp;nbsp;server and leave the "aaa authentication" commands the same.&lt;/P&gt;
&lt;P&gt;Another suggestion is what I mentioned earlier, point both to ISE using radius. Authentication is forwarded to your OTP server and proceeds as usual. ISE server then does the authorization for the same user.&lt;/P&gt;</description>
      <pubDate>Sat, 28 Jan 2017 03:15:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/using-otp-for-authentication-and-ise-for-authorization-in-cisco/m-p/3045277#M24321</guid>
      <dc:creator>Rahul Govindan</dc:creator>
      <dc:date>2017-01-28T03:15:56Z</dc:date>
    </item>
    <item>
      <title>Actually I tried the to point</title>
      <link>https://community.cisco.com/t5/network-access-control/using-otp-for-authentication-and-ise-for-authorization-in-cisco/m-p/3045278#M24323</link>
      <description>&lt;P&gt;Actually I tried the to point the Authorization to the ISE but my users kept login in to the switch with privilege 15 (sadly :d).&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;You are right. I'm gonna test it and get back to you with the results. Thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 31 Jan 2017 17:38:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/using-otp-for-authentication-and-ise-for-authorization-in-cisco/m-p/3045278#M24323</guid>
      <dc:creator>mesarasimth1</dc:creator>
      <dc:date>2017-01-31T17:38:17Z</dc:date>
    </item>
    <item>
      <title>Hi, Sorry for delay. i just</title>
      <link>https://community.cisco.com/t5/network-access-control/using-otp-for-authentication-and-ise-for-authorization-in-cisco/m-p/3045279#M24327</link>
      <description>&lt;P&gt;Hi, Sorry for delay. i just wanted you to know that I solved the problem using,"External Radius Server" and configuring sequence rules and external servers.&lt;/P&gt;</description>
      <pubDate>Mon, 15 May 2017 07:21:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/using-otp-for-authentication-and-ise-for-authorization-in-cisco/m-p/3045279#M24327</guid>
      <dc:creator>mesarasimth1</dc:creator>
      <dc:date>2017-05-15T07:21:46Z</dc:date>
    </item>
  </channel>
</rss>

