<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Control Device admin users login location using IP address in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/control-device-admin-users-login-location-using-ip-address/m-p/3954281#M442167</link>
    <description>&lt;P&gt;You would need to figure out which Radius/TACACS+ AVP holds that information and test it out.&amp;nbsp; But again, different hardware, IOS, protocol, etc could provide different results.&amp;nbsp; I wouldn't trust it for all devices unless you test each use case in the lab first.&amp;nbsp; Key is to test extensively first.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 06 Nov 2019 19:53:35 GMT</pubDate>
    <dc:creator>Colby LeMaire</dc:creator>
    <dc:date>2019-11-06T19:53:35Z</dc:date>
    <item>
      <title>Control Device admin users login location using IP address</title>
      <link>https://community.cisco.com/t5/network-access-control/control-device-admin-users-login-location-using-ip-address/m-p/3954011#M442107</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Can ISE (device administration) controls device admin users location (IP address) so that user can login NAD (router/switch) from specific IP address?&lt;/P&gt;
&lt;P&gt;As per my understanding, ISE can't restrict device admin users based on IP Address as ISE communicates with NAD (as TACACS+ client) and not endpoint.&amp;nbsp; Second point, AAA client (NAD) sends only user name to TACACS+ server.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kindly confirm my understanding.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 19:11:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/control-device-admin-users-login-location-using-ip-address/m-p/3954011#M442107</guid>
      <dc:creator>dngore</dc:creator>
      <dc:date>2020-02-21T19:11:37Z</dc:date>
    </item>
    <item>
      <title>Re: Control Device admin users login location using IP address</title>
      <link>https://community.cisco.com/t5/network-access-control/control-device-admin-users-login-location-using-ip-address/m-p/3954060#M442117</link>
      <description>&lt;P&gt;In TACACS Live Logs, you can open the details of an authentication/authorization event and see if you have any attribute that you can use to determine the location.&amp;nbsp; In my system, I just checked and see an attribute called "Remote Address" that appears to be the originating client's IP address.&amp;nbsp; But that is a Cisco IOS device using TACACS.&amp;nbsp; Results may be different with different device types, IOS levels, etc.&lt;/P&gt;&lt;P&gt;For a more reliable/secure way of controlling admin access to network devices, use infrastructure ACL's or management plane ACL's on the device to control what subnets can SSH, SNMP, etc. to the device.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Nov 2019 15:10:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/control-device-admin-users-login-location-using-ip-address/m-p/3954060#M442117</guid>
      <dc:creator>Colby LeMaire</dc:creator>
      <dc:date>2019-11-06T15:10:50Z</dc:date>
    </item>
    <item>
      <title>Re: Control Device admin users login location using IP address</title>
      <link>https://community.cisco.com/t5/network-access-control/control-device-admin-users-login-location-using-ip-address/m-p/3954121#M442141</link>
      <description>&lt;P&gt;Thx for reply.&lt;/P&gt;
&lt;P&gt;But this is not deployed solution. We are proposing it. Customer has below query. Hence want to confirm on same.&lt;/P&gt;
&lt;P&gt;So if remote client IP address is seen in log then does that mean we can control device admin user based on IP address in ISE?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are aware of access list restriction on NAD devices but customer is specifically asking for this feature support in ISE.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Nov 2019 16:01:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/control-device-admin-users-login-location-using-ip-address/m-p/3954121#M442141</guid>
      <dc:creator>dngore</dc:creator>
      <dc:date>2019-11-06T16:01:34Z</dc:date>
    </item>
    <item>
      <title>Re: Control Device admin users login location using IP address</title>
      <link>https://community.cisco.com/t5/network-access-control/control-device-admin-users-login-location-using-ip-address/m-p/3954281#M442167</link>
      <description>&lt;P&gt;You would need to figure out which Radius/TACACS+ AVP holds that information and test it out.&amp;nbsp; But again, different hardware, IOS, protocol, etc could provide different results.&amp;nbsp; I wouldn't trust it for all devices unless you test each use case in the lab first.&amp;nbsp; Key is to test extensively first.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Nov 2019 19:53:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/control-device-admin-users-login-location-using-ip-address/m-p/3954281#M442167</guid>
      <dc:creator>Colby LeMaire</dc:creator>
      <dc:date>2019-11-06T19:53:35Z</dc:date>
    </item>
    <item>
      <title>Re: Control Device admin users login location using IP address</title>
      <link>https://community.cisco.com/t5/network-access-control/control-device-admin-users-login-location-using-ip-address/m-p/3954569#M442183</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/186734"&gt;@dngore&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;yes this is very straightforward&lt;/P&gt;
&lt;P&gt;I have modified my lab as follows. I included a check to ensure that the user may not come from IP address 192.168.0.212 or else he will be dropped into read-only mode. If the user comes from any other address, then he will be in privilege level 15 (super admin).&amp;nbsp; The key thing is that the attribute TACACS: Remote-Address is what you're after.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="comm07.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/48786i53452A361D896775/image-size/large?v=v2&amp;amp;px=999" role="button" title="comm07.PNG" alt="comm07.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Nov 2019 08:12:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/control-device-admin-users-login-location-using-ip-address/m-p/3954569#M442183</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2019-11-07T08:12:06Z</dc:date>
    </item>
  </channel>
</rss>

