<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Migrate TACACS from ACS to a live ISE deployment in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/migrate-tacacs-from-acs-to-a-live-ise-deployment/m-p/3429761#M518910</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A href="https://community.cisco.com//u1/38995"&gt;hslai&lt;/A&gt;,&lt;/P&gt;&lt;P&gt;Regarding 2 and 3 - this is excellent!&amp;nbsp; Thanks.&lt;/P&gt;&lt;P&gt;I needed pages 11 and 12 of the lab guide. I don't know how to find GOLD labs since they shut down the PEC.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think this might be the information on the "hidden slides" that Krishnan mentioned in the video&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't quite understand your information about #1 but maybe I am not ready for the answer.&lt;/P&gt;&lt;P&gt;I will come back to this one if need be.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 03 Jan 2018 13:35:53 GMT</pubDate>
    <dc:creator>tgraham</dc:creator>
    <dc:date>2018-01-03T13:35:53Z</dc:date>
    <item>
      <title>Migrate TACACS from ACS to a live ISE deployment</title>
      <link>https://community.cisco.com/t5/network-access-control/migrate-tacacs-from-acs-to-a-live-ise-deployment/m-p/3429754#M518894</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There is a lot of documentation about ACS -&amp;gt; ISE migration but my situation is that we have a live ISE to migrate to not a fresh standalone deployment. I only care about the TACACS part of the deployment and I am hitting some roadblocks.&lt;/P&gt;&lt;P&gt;1. I have the additional attributes problem the Krishnan &lt;A href="https://community.cisco.com//u1/137107"&gt;kthiruve&lt;/A&gt;&amp;nbsp; introduces in his very informative video series. He references some "hidden slides" that go into more detail. Does anyone know where the slide deck for the videos is so I can look over the hidden slides?&lt;/P&gt;&lt;P&gt;2. I run into the problem that there is already an AD defined in ISE so none of the ACS AD configuration comes over. I try to manually create the authenticate rule that I think should take care of this but when I go to choose the condition the little wheel comes up and spins indefinitely. I would like to at least get part of the rule so I can have a model to build from.&lt;/P&gt;&lt;P&gt;3. The main part of the additional attributes has to do with RSA SecurID. I have the RSA document for how to build the policy set but the way they do it puts it in "simple" mode which would wipe out the rest of the ISE configuration (currently ISE is used for dot1x authc/authz). So what is a RSA authorization rule supposed to look like in compound mode? (We authenticate to RSA and draw additional attributes, i.e. group membership, from AD) Does anyone know how to do a rule like this? I am sure if I just saw one I would be good to go.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for any advice, experience, links and pointers you may be able to share.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Dec 2017 22:32:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/migrate-tacacs-from-acs-to-a-live-ise-deployment/m-p/3429754#M518894</guid>
      <dc:creator>tgraham</dc:creator>
      <dc:date>2017-12-28T22:32:20Z</dc:date>
    </item>
    <item>
      <title>Re: Migrate TACACS from ACS to a live ISE deployment</title>
      <link>https://community.cisco.com/t5/network-access-control/migrate-tacacs-from-acs-to-a-live-ise-deployment/m-p/3429755#M518897</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;All the tutorials and links are in the link here - &lt;A href="https://community.cisco.com/docs/DOC-63880"&gt;ACS to ISE Migration&lt;/A&gt;&lt;/P&gt;&lt;P&gt;I will check with our SME regarding your other queries. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Nidhi&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 29 Dec 2017 12:16:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/migrate-tacacs-from-acs-to-a-live-ise-deployment/m-p/3429755#M518897</guid>
      <dc:creator>Nidhi</dc:creator>
      <dc:date>2017-12-29T12:16:38Z</dc:date>
    </item>
    <item>
      <title>Re: Migrate TACACS from ACS to a live ISE deployment</title>
      <link>https://community.cisco.com/t5/network-access-control/migrate-tacacs-from-acs-to-a-live-ise-deployment/m-p/3429756#M518900</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for your reply. I have gone through everything on the page your linked (bookmarked in fact).&amp;nbsp; The third video has the mention of the "hidden slides" I am asking about. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All of this information assumes we are migrating to a clean standalone ISE deployment. My ISE has been doing dot1x for years so I need to learn how to "merge" more than "migrate".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please let me know what you find out.&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 29 Dec 2017 12:24:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/migrate-tacacs-from-acs-to-a-live-ise-deployment/m-p/3429756#M518900</guid>
      <dc:creator>tgraham</dc:creator>
      <dc:date>2017-12-29T12:24:54Z</dc:date>
    </item>
    <item>
      <title>Re: Migrate TACACS from ACS to a live ISE deployment</title>
      <link>https://community.cisco.com/t5/network-access-control/migrate-tacacs-from-acs-to-a-live-ise-deployment/m-p/3429757#M518902</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;you might want to look at how to document&amp;nbsp; - &lt;A href="https://community.cisco.com/docs/DOC-65715"&gt;How to Migrate ACS 5.x to ISE 2.x&lt;/A&gt;&lt;/P&gt;&lt;P&gt;This has detail steps for plan/prepare and Migrate (3rd step). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will keep you posted as I hear anything for our SME. &lt;/P&gt;&lt;P&gt;Also, just to let you know, its year end shutdown in Cisco and response will be little slow.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Nidhi&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 29 Dec 2017 12:32:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/migrate-tacacs-from-acs-to-a-live-ise-deployment/m-p/3429757#M518902</guid>
      <dc:creator>Nidhi</dc:creator>
      <dc:date>2017-12-29T12:32:11Z</dc:date>
    </item>
    <item>
      <title>Re: Migrate TACACS from ACS to a live ISE deployment</title>
      <link>https://community.cisco.com/t5/network-access-control/migrate-tacacs-from-acs-to-a-live-ise-deployment/m-p/3429758#M518904</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;On 1, please provide the link to the particular video and the approximate timing in the video where Krishnan mentioned about the hidden slides.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On 2, are you having this issue only after running ACS migration? If so, please open a TAC case to troubleshoot.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On 3, you may either create a new policy set or configure the RSA rules under the default policy set. In case of ISE 2.3, please see the video on Cisco ISE 2.3 Policy User Interface Walkthrough @ &lt;A href="https://community.cisco.com/docs/DOC-74808"&gt;What's New in ISE 2.3?&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 01 Jan 2018 09:41:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/migrate-tacacs-from-acs-to-a-live-ise-deployment/m-p/3429758#M518904</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-01-01T09:41:52Z</dc:date>
    </item>
    <item>
      <title>Re: Migrate TACACS from ACS to a live ISE deployment</title>
      <link>https://community.cisco.com/t5/network-access-control/migrate-tacacs-from-acs-to-a-live-ise-deployment/m-p/3429759#M518906</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the followup &lt;A href="https://community.cisco.com//u1/38995"&gt;hslai&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. The reference to the hidden slides is at: 19:20 in&lt;/P&gt;&lt;P&gt;ACS to ISE Migration - Part III - Migration process and demonstrationv2-Chapter 2.mp4&lt;/P&gt;&lt;P&gt;You can find a link to video at &lt;A href="https://community.cisco.com/docs/DOC-70450"&gt;ACS to ISE Migration - Part III - Migration Process and Demonstration&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. I am not sure I am creating the Policy Set correctly. The ISE/TACACS guide I have is for ISE 2.0 and I am using v2.1. The menus have changed. I am using &lt;A href="https://community.cisco.com/docs/DOC-68194"&gt;How To: ISE TACACS+ Configuration for IOS Network Devices&lt;/A&gt; (DOC-68194).&amp;nbsp; Is there a guide compatible with v2.1 (or just an example)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3. I am running v2.1 so I cannot use the ver 2.3 what's new. I am not sure how to configure/modify the policy set. I will look through the what's new to see if it gives me a clue how to do it in v2.1.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Jan 2018 13:04:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/migrate-tacacs-from-acs-to-a-live-ise-deployment/m-p/3429759#M518906</guid>
      <dc:creator>tgraham</dc:creator>
      <dc:date>2018-01-02T13:04:08Z</dc:date>
    </item>
    <item>
      <title>Re: Migrate TACACS from ACS to a live ISE deployment</title>
      <link>https://community.cisco.com/t5/network-access-control/migrate-tacacs-from-acs-to-a-live-ise-deployment/m-p/3429760#M518908</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;On 2 and 3, the web UI in ISE 2.0 and 2.1 are not that much different. If you registered as a partner, you may take a look at &lt;A _jive_internal="true" href="https://community.cisco.com/docs/DOC-76362"&gt;[ISE Lab Guide] ISE Device Administration Services (TACACS+)&lt;/A&gt;, which is based on ISE 2.1. ISE T+ is using policy sets since it added in ISE 2.0. &lt;A _jive_internal="true" href="https://community.cisco.com/docs/DOC-64031#jive_content_id_Demos"&gt;ISE T+ Demos&lt;/A&gt;&lt;SPAN style="font-size: 10pt;"&gt; has some videos to show how to set things up.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;On 1, are you referring to what Krishnan said about in-line conditions? If so, it's how ISE policy engine working differently from ACS one, such that ISE using the ID source sequence for authentications, and that, during authorization, ISE checks the attributes of the ID stores in the conditions, regardless they used in authentications. Unless pre-pending a condition using "&lt;STRONG style="color: #000000; font-family: Verdana, sans-serif; font-size: 14px;"&gt;Network Access:AuthenticationIdentityStore&lt;/STRONG&gt;" to limit the queries.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Jan 2018 20:44:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/migrate-tacacs-from-acs-to-a-live-ise-deployment/m-p/3429760#M518908</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-01-02T20:44:17Z</dc:date>
    </item>
    <item>
      <title>Re: Migrate TACACS from ACS to a live ISE deployment</title>
      <link>https://community.cisco.com/t5/network-access-control/migrate-tacacs-from-acs-to-a-live-ise-deployment/m-p/3429761#M518910</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A href="https://community.cisco.com//u1/38995"&gt;hslai&lt;/A&gt;,&lt;/P&gt;&lt;P&gt;Regarding 2 and 3 - this is excellent!&amp;nbsp; Thanks.&lt;/P&gt;&lt;P&gt;I needed pages 11 and 12 of the lab guide. I don't know how to find GOLD labs since they shut down the PEC.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think this might be the information on the "hidden slides" that Krishnan mentioned in the video&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't quite understand your information about #1 but maybe I am not ready for the answer.&lt;/P&gt;&lt;P&gt;I will come back to this one if need be.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Jan 2018 13:35:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/migrate-tacacs-from-acs-to-a-live-ise-deployment/m-p/3429761#M518910</guid>
      <dc:creator>tgraham</dc:creator>
      <dc:date>2018-01-03T13:35:53Z</dc:date>
    </item>
  </channel>
</rss>

