<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Two questions about Tacacs: Local Password handling and log anonymization in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/two-questions-about-tacacs-local-password-handling-and-log/m-p/3437987#M518256</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Best to ask separate questions so we can manage them and mark accordingly&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don’t think you can anonymize tacacs It defeats the purpose of tracking who and what is done on a new device can you please explain the use case&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 29 Jan 2018 15:41:49 GMT</pubDate>
    <dc:creator>Jason Kunst</dc:creator>
    <dc:date>2018-01-29T15:41:49Z</dc:date>
    <item>
      <title>Two questions about Tacacs: Local Password handling and log anonymization</title>
      <link>https://community.cisco.com/t5/network-access-control/two-questions-about-tacacs-local-password-handling-and-log/m-p/3437984#M518250</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;Hi all,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;my customer is looking to deploy ISE for device administration and got two questions:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;1) They want to use the local database as an idendity store. Now the question came up about&amp;nbsp; &lt;/SPAN&gt;password handling for local users. The question here is if ISE has some kind of self-service portal where the local user could change/manage her/his password. I am&amp;nbsp; &lt;SPAN style="font-size: 10pt;"&gt;not aware about such a portal. The only posbillity I am aware of is the usage of tacacs+ password change to do that or to use the mydevices-portal to build workaround. Am I correct?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;2) Customer is asking if it is possible to anonymize TACACS accounting to hide which user actually did made a change?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;Thanks in advance.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;Roland&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Jan 2018 10:35:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/two-questions-about-tacacs-local-password-handling-and-log/m-p/3437984#M518250</guid>
      <dc:creator>rmueller@cisco.com</dc:creator>
      <dc:date>2018-01-29T10:35:28Z</dc:date>
    </item>
    <item>
      <title>Re: Two questions about Tacacs: Local Password handling and log anonymization</title>
      <link>https://community.cisco.com/t5/network-access-control/two-questions-about-tacacs-local-password-handling-and-log/m-p/3437985#M518253</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Rolland-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;as for your questions, there is no "portal" to change passwords, but int ISE 2.x there are settings to allow pw changes via CLI.&amp;nbsp; You will find them under the "Device Administration" workcenter (TACACS) then go to settings.&lt;/P&gt;&lt;P&gt;The changes made by each account, can only be abused if users share their passwords.&amp;nbsp; as for the changes, these are the aaa accounting that records every change&lt;/P&gt;&lt;P&gt;aaa accounting exec ISE-LOCAL start-stop group TACACS&lt;/P&gt;&lt;P&gt;aaa accounting commands 0 ISE-LOCAL start-stop group TACACS&lt;/P&gt;&lt;P&gt;aaa accounting commands 15 ISE-LOCAL start-stop group TACACS&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;these will capture the whole session as well as the changes.&amp;nbsp; I use a syslog server to collect all these events, bu tyou can also see them in the log buffer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Vince&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Jan 2018 15:18:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/two-questions-about-tacacs-local-password-handling-and-log/m-p/3437985#M518253</guid>
      <dc:creator>vrostowsky</dc:creator>
      <dc:date>2018-01-29T15:18:49Z</dc:date>
    </item>
    <item>
      <title>Re: Two questions about Tacacs: Local Password handling and log anonymization</title>
      <link>https://community.cisco.com/t5/network-access-control/two-questions-about-tacacs-local-password-handling-and-log/m-p/3437986#M518255</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can use my device or sponsor portal for password change portal&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;https://communities.cisco.com/thread/73087?start=0&amp;amp;tstart=0&amp;amp;mobileredirect=true&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Jan 2018 15:31:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/two-questions-about-tacacs-local-password-handling-and-log/m-p/3437986#M518255</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-01-29T15:31:46Z</dc:date>
    </item>
    <item>
      <title>Re: Two questions about Tacacs: Local Password handling and log anonymization</title>
      <link>https://community.cisco.com/t5/network-access-control/two-questions-about-tacacs-local-password-handling-and-log/m-p/3437987#M518256</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Best to ask separate questions so we can manage them and mark accordingly&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don’t think you can anonymize tacacs It defeats the purpose of tracking who and what is done on a new device can you please explain the use case&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Jan 2018 15:41:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/two-questions-about-tacacs-local-password-handling-and-log/m-p/3437987#M518256</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-01-29T15:41:49Z</dc:date>
    </item>
  </channel>
</rss>

