<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic CLI Access control with Radius only in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cli-access-control-with-radius-only/m-p/3866997#M472505</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Are we able to do CLI access control with Radius only? I have seen 3rd party examples on ise 1.x but nothing for 2.x and nothing official. Goal would be to control exec level access to Catalyst, ISR, and nexus devices with Radius only. No TACACS license required.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-Eliott&lt;/P&gt;</description>
    <pubDate>Mon, 03 Jun 2019 18:47:18 GMT</pubDate>
    <dc:creator>estidd</dc:creator>
    <dc:date>2019-06-03T18:47:18Z</dc:date>
    <item>
      <title>CLI Access control with Radius only</title>
      <link>https://community.cisco.com/t5/network-access-control/cli-access-control-with-radius-only/m-p/3866997#M472505</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Are we able to do CLI access control with Radius only? I have seen 3rd party examples on ise 1.x but nothing for 2.x and nothing official. Goal would be to control exec level access to Catalyst, ISR, and nexus devices with Radius only. No TACACS license required.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-Eliott&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jun 2019 18:47:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cli-access-control-with-radius-only/m-p/3866997#M472505</guid>
      <dc:creator>estidd</dc:creator>
      <dc:date>2019-06-03T18:47:18Z</dc:date>
    </item>
    <item>
      <title>Re: CLI Access control with Radius only</title>
      <link>https://community.cisco.com/t5/network-access-control/cli-access-control-with-radius-only/m-p/3867086#M472506</link>
      <description>&lt;P&gt;Hello Eliot,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;of course you should be able to do this,&lt;/P&gt;
&lt;P&gt;please check this document&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/secure-access-control-system/115926-tacacs-radius-devices-00.html#asr" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/secure-access-control-system/115926-tacacs-radius-devices-00.html#asr&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;i know its for ACS but very much same concept, the idea is to use cisco-av pair on the authorization result and mention the attribute you would like to&amp;nbsp; push.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;take a look and if you faced some challenges feel free to ask.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Wishes.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jun 2019 21:53:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cli-access-control-with-radius-only/m-p/3867086#M472506</guid>
      <dc:creator>yalbikaw</dc:creator>
      <dc:date>2019-06-03T21:53:43Z</dc:date>
    </item>
    <item>
      <title>Re: CLI Access control with Radius only</title>
      <link>https://community.cisco.com/t5/network-access-control/cli-access-control-with-radius-only/m-p/3867362#M472508</link>
      <description>&lt;P&gt;&amp;nbsp;I can confirm that as long as the network device allows Device Admin using the Radius protocol, then ISE will happily oblige. Cisco WLC and IOS devices all support this.&amp;nbsp; For ISE it's just a PAP authentication.&amp;nbsp; You need to figure out what attributes the NAS will include in its Access-Request and then catch that in your Policy Set Authorization Rules.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Below is what I figured out recently when I had to do this.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ISE-Radius.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/37989iD03874E902230C3B/image-size/large?v=v2&amp;amp;px=999" role="button" title="ISE-Radius.PNG" alt="ISE-Radius.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Jun 2019 12:46:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cli-access-control-with-radius-only/m-p/3867362#M472508</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2019-06-04T12:46:52Z</dc:date>
    </item>
  </channel>
</rss>

