<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: TACACS Live cut over from ACS to ISE in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/tacacs-live-cut-over-from-acs-to-ise/m-p/3805456#M485012</link>
    <description>&lt;P&gt;No need for "no aaa new-model"&lt;/P&gt;</description>
    <pubDate>Wed, 20 Feb 2019 03:44:33 GMT</pubDate>
    <dc:creator>pan</dc:creator>
    <dc:date>2019-02-20T03:44:33Z</dc:date>
    <item>
      <title>TACACS Live cut over from ACS to ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-live-cut-over-from-acs-to-ise/m-p/3805289#M484997</link>
      <description>&lt;P&gt;I am planning Live cut over from ACS to ISE for more than 1000+ devices globally.&lt;/P&gt;
&lt;P&gt;Currently they are configured in ACS: TACACS for Router/Switch/ASAs, RADIUS for WLC/AP/VPNs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The policy sets are all configured, Shared secret key are all matched between ISE and Routers/Switches/ASAs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just want to be cautious:&lt;/P&gt;
&lt;P&gt;If I simply change the network devices' TACACS server pointer from ACS to ISE, will it cause network outage ?&lt;/P&gt;
&lt;P&gt;should I do "no aaa new-model" first, and then re-enable "aaa new-model" .... any other issues I should be concerned ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Feb 2019 21:03:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-live-cut-over-from-acs-to-ise/m-p/3805289#M484997</guid>
      <dc:creator>j0liu001</dc:creator>
      <dc:date>2019-02-19T21:03:21Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS Live cut over from ACS to ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-live-cut-over-from-acs-to-ise/m-p/3805413#M485000</link>
      <description>&lt;P&gt;First add cisco ISE on router/switch/ASA and then run "test aaa" command to check if you are able to authenticate successfully.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Example:&lt;/P&gt;
&lt;P&gt;tacacs server TACACS-SERVER-IP-1&lt;BR /&gt;&amp;nbsp;address ipv4 &amp;lt;ISP PSN IP&amp;gt;&lt;BR /&gt;&amp;nbsp;key &amp;lt;Shared Key&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;aaa group server tacacs+ TACACS-GROUP&lt;BR /&gt;&amp;nbsp;server name TACACS-SERVER-IP-1&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;test aaa group TACACS-GROUP &amp;lt;username&amp;gt; &amp;lt;password&amp;gt; new-code&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Once you are able to authenticate then change the "aaa authentication", "aaa authorization" command and point ISE to it.&lt;/P&gt;
&lt;P&gt;Example:&lt;/P&gt;
&lt;P&gt;aaa authentication login VTY group TACACS-GROUP local&lt;/P&gt;
&lt;P&gt;aaa authorization commands 15 VTY group&amp;nbsp;TACACS-GROUP local if-authenticated&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Don't do write memory until everything works.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can also have "reload in 30"&amp;nbsp; so that device will reload automatically in 30 min if you lock yourself out. If everything goes well you can cancel reload&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;sw3850#reload in ?&lt;BR /&gt;Delay before reload (mmm or hhh:mm)&lt;/P&gt;</description>
      <pubDate>Wed, 20 Feb 2019 01:42:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-live-cut-over-from-acs-to-ise/m-p/3805413#M485000</guid>
      <dc:creator>pan</dc:creator>
      <dc:date>2019-02-20T01:42:45Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS Live cut over from ACS to ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-live-cut-over-from-acs-to-ise/m-p/3805455#M485007</link>
      <description>&lt;P&gt;Thanks a lot, Pan!&amp;nbsp; The "reload in 30" is an excellent tip !&lt;BR /&gt;&lt;BR /&gt;Since I changed the TACACS server pointer from ACS to ISE, should I do "no aaa new-model" first, and then re-enable "aaa new-model" ? ...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Wed, 20 Feb 2019 03:43:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-live-cut-over-from-acs-to-ise/m-p/3805455#M485007</guid>
      <dc:creator>j0liu001</dc:creator>
      <dc:date>2019-02-20T03:43:35Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS Live cut over from ACS to ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-live-cut-over-from-acs-to-ise/m-p/3805456#M485012</link>
      <description>&lt;P&gt;No need for "no aaa new-model"&lt;/P&gt;</description>
      <pubDate>Wed, 20 Feb 2019 03:44:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-live-cut-over-from-acs-to-ise/m-p/3805456#M485012</guid>
      <dc:creator>pan</dc:creator>
      <dc:date>2019-02-20T03:44:33Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS Live cut over from ACS to ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-live-cut-over-from-acs-to-ise/m-p/3805698#M485017</link>
      <description>&lt;P&gt;Hi, the first thing is to add devices to ISE if this is not done .&lt;/P&gt;&lt;P&gt;Second create a policy sets for device administration radius etc.&lt;/P&gt;&lt;P&gt;Third is to configure switch router etc.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Feb 2019 10:02:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-live-cut-over-from-acs-to-ise/m-p/3805698#M485017</guid>
      <dc:creator>ognyan.totev</dc:creator>
      <dc:date>2019-02-20T10:02:39Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS Live cut over from ACS to ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-live-cut-over-from-acs-to-ise/m-p/3805820#M485019</link>
      <description>To add to the helpful tips provided by &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/488930"&gt;@pan&lt;/a&gt;:&lt;BR /&gt;&lt;BR /&gt;Change your current reauthentication timers to 4 hours or however long you need to complete the cutover. Wait for hosts to auth. Then you will know that you have a 4 hour window until they need to reauth. This will help keep end users up during the cutover.&lt;BR /&gt;&lt;BR /&gt;HTH!</description>
      <pubDate>Wed, 20 Feb 2019 13:50:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-live-cut-over-from-acs-to-ise/m-p/3805820#M485019</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2019-02-20T13:50:22Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS Live cut over from ACS to ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-live-cut-over-from-acs-to-ise/m-p/3805868#M485021</link>
      <description>&lt;P&gt;Totally agree&amp;nbsp; :=)&amp;nbsp; Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 20 Feb 2019 14:29:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-live-cut-over-from-acs-to-ise/m-p/3805868#M485021</guid>
      <dc:creator>j0liu001</dc:creator>
      <dc:date>2019-02-20T14:29:45Z</dc:date>
    </item>
  </channel>
</rss>

