<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ise 2.4 command sets for nexus access in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-2-4-command-sets-for-nexus-access/m-p/3672809#M508652</link>
    <description>&lt;P&gt;Hi Experts,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;i was trying to configure tacacs for nexus access using ise 2.4. on the command sets for readonly access i only allowed a few commands for testing but after logging in, i can also use the other commands although they were not set on the tacacs command sets. only show int status and exit was set but other command like show vlan can be excuted. i can even execute "conf t" . any guide on how to configure the command sets for nexus ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;tia,&lt;/P&gt;
&lt;P&gt;chris&lt;/P&gt;</description>
    <pubDate>Tue, 24 Jul 2018 08:48:22 GMT</pubDate>
    <dc:creator>Meuserid1979</dc:creator>
    <dc:date>2018-07-24T08:48:22Z</dc:date>
    <item>
      <title>ise 2.4 command sets for nexus access</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-command-sets-for-nexus-access/m-p/3672809#M508652</link>
      <description>&lt;P&gt;Hi Experts,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;i was trying to configure tacacs for nexus access using ise 2.4. on the command sets for readonly access i only allowed a few commands for testing but after logging in, i can also use the other commands although they were not set on the tacacs command sets. only show int status and exit was set but other command like show vlan can be excuted. i can even execute "conf t" . any guide on how to configure the command sets for nexus ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;tia,&lt;/P&gt;
&lt;P&gt;chris&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jul 2018 08:48:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-command-sets-for-nexus-access/m-p/3672809#M508652</guid>
      <dc:creator>Meuserid1979</dc:creator>
      <dc:date>2018-07-24T08:48:22Z</dc:date>
    </item>
    <item>
      <title>Re: ise 2.4 command sets for nexus access</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-command-sets-for-nexus-access/m-p/3672919#M508654</link>
      <description>&lt;P&gt;Will this work for you? This will allow all show commands, but will not allow configuration commands. I have not tried limiting to specific commands.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2018-07-24 06_18_17-Identity Services Engine - Internet Explorer.png" style="width: 232px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/15023i8F5049C1833AA461/image-size/large?v=v2&amp;amp;px=999" role="button" title="2018-07-24 06_18_17-Identity Services Engine - Internet Explorer.png" alt="2018-07-24 06_18_17-Identity Services Engine - Internet Explorer.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jul 2018 10:22:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-command-sets-for-nexus-access/m-p/3672919#M508654</guid>
      <dc:creator>Alex Pfeil</dc:creator>
      <dc:date>2018-07-24T10:22:51Z</dc:date>
    </item>
    <item>
      <title>Re: ise 2.4 command sets for nexus access</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-command-sets-for-nexus-access/m-p/3672933#M508656</link>
      <description>&lt;P&gt;Hi Alex,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks for the reply. yes i tried this and applied for each authz as per my screenshot. there are difference when loggin in as "administrator" and "readonly" but seems like limiting the commands(for read only access) which is applied on the command set portion of the authz doesnt work? coz i still can execute lots of commands which should be filtered by command sets. not sure whether its a normal nexus behavior? thanks&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;chris&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jul 2018 10:32:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-command-sets-for-nexus-access/m-p/3672933#M508656</guid>
      <dc:creator>Meuserid1979</dc:creator>
      <dc:date>2018-07-24T10:32:30Z</dc:date>
    </item>
    <item>
      <title>Re: ise 2.4 command sets for nexus access</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-command-sets-for-nexus-access/m-p/3673491#M508658</link>
      <description>&lt;P&gt;Make sure that the correct authorization commands are enabled on the Nexus device and check out the PDF of the guide available here:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;A href="https://community.cisco.com/t5/security-documents/how-to-ise-tacacs-configuration-for-cisco-nx-os-network-devices/ta-p/3631609" target="_self"&gt;https://community.cisco.com/t5/security-documents/how-to-ise-tacacs-configuration-for-cisco-nx-os-network-devices/ta-p/3631609&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Thanks,&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Alex&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jul 2018 17:03:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-command-sets-for-nexus-access/m-p/3673491#M508658</guid>
      <dc:creator>Alex Pfeil</dc:creator>
      <dc:date>2018-07-24T17:03:08Z</dc:date>
    </item>
  </channel>
</rss>

