<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Monitoring NAC? in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/monitoring-nac/m-p/3479390#M526582</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am making the assumption that "user ports" is referring to switch port configuration, or the ports on the network access device.&amp;nbsp; TACACS configuration on switch should be covered in the switch docs.&amp;nbsp; For example, to configure TACACS+ on a Catalyst 3850, you can quickly get links from Cisco.com search, or Google, example: &lt;A href="http://lmgtfy.com/?q=catalyst+3850+TACACS" title="http://lmgtfy.com/?q=catalyst+3850+TACACS"&gt;LMGTFY&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For ISE configuration of T+, this is covered in ISE documentation.&amp;nbsp; Example: &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-3/admin_guide/b_ise_admin_guide_23/b_ise_admin_guide_23_chapter_01000.html" title="https://www.cisco.com/c/en/us/td/docs/security/ise/2-3/admin_guide/b_ise_admin_guide_23/b_ise_admin_guide_23_chapter_01000.html"&gt;Cisco Identity Services Engine Administrator Guide, Release 2.3 - Control Device Administration Using TACACS+ [Cisco I…&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ISE does log and provide reports based on TACACS+ or RADIUS events for device admin access, but ISE does not &lt;EM&gt;alarm &lt;/EM&gt;on these events.&amp;nbsp; This is more of the realm of the network device management system.&amp;nbsp;&amp;nbsp; It is possible to generate SNMP traps from switches when config is changed:&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.petri.com/notified-cisco-router-configuration-change" title="https://www.petri.com/notified-cisco-router-configuration-change"&gt;https://www.petri.com/notified-cisco-router-configuration-change&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://supportforums.cisco.com/t5/network-management/config-management-snmp-trap/td-p/1955634" title="https://supportforums.cisco.com/t5/network-management/config-management-snmp-trap/td-p/1955634"&gt;Config Management SNMP Trap - Cisco Support Community&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your SNMP Management system can then generate the desired alert.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Craig&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 20 Sep 2017 21:01:33 GMT</pubDate>
    <dc:creator>Craig Hyps</dc:creator>
    <dc:date>2017-09-20T21:01:33Z</dc:date>
    <item>
      <title>Monitoring NAC?</title>
      <link>https://community.cisco.com/t5/network-access-control/monitoring-nac/m-p/3479387#M526577</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What is the best practice/process to make sure someone does not inadvertently remove the NAC configuration from a user port? Is there a method to monitor the ports set up for NAC and alert if they are changed? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Sep 2017 07:55:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/monitoring-nac/m-p/3479387#M526577</guid>
      <dc:creator>ashvaras</dc:creator>
      <dc:date>2017-09-19T07:55:42Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring NAC?</title>
      <link>https://community.cisco.com/t5/network-access-control/monitoring-nac/m-p/3479388#M526579</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;TACACS with command authorization and accounting will 1) validate user authorized to make change, 2) Log changes by command by admin.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Craig&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Sep 2017 17:21:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/monitoring-nac/m-p/3479388#M526579</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2017-09-19T17:21:48Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring NAC?</title>
      <link>https://community.cisco.com/t5/network-access-control/monitoring-nac/m-p/3479389#M526581</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hmmmm-So is there documentation or any more detail on how to do this? And also if I understand correctly you are saying there is no ability to alert on a configuration change?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Sep 2017 20:11:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/monitoring-nac/m-p/3479389#M526581</guid>
      <dc:creator>ashvaras</dc:creator>
      <dc:date>2017-09-20T20:11:12Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring NAC?</title>
      <link>https://community.cisco.com/t5/network-access-control/monitoring-nac/m-p/3479390#M526582</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am making the assumption that "user ports" is referring to switch port configuration, or the ports on the network access device.&amp;nbsp; TACACS configuration on switch should be covered in the switch docs.&amp;nbsp; For example, to configure TACACS+ on a Catalyst 3850, you can quickly get links from Cisco.com search, or Google, example: &lt;A href="http://lmgtfy.com/?q=catalyst+3850+TACACS" title="http://lmgtfy.com/?q=catalyst+3850+TACACS"&gt;LMGTFY&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For ISE configuration of T+, this is covered in ISE documentation.&amp;nbsp; Example: &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-3/admin_guide/b_ise_admin_guide_23/b_ise_admin_guide_23_chapter_01000.html" title="https://www.cisco.com/c/en/us/td/docs/security/ise/2-3/admin_guide/b_ise_admin_guide_23/b_ise_admin_guide_23_chapter_01000.html"&gt;Cisco Identity Services Engine Administrator Guide, Release 2.3 - Control Device Administration Using TACACS+ [Cisco I…&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ISE does log and provide reports based on TACACS+ or RADIUS events for device admin access, but ISE does not &lt;EM&gt;alarm &lt;/EM&gt;on these events.&amp;nbsp; This is more of the realm of the network device management system.&amp;nbsp;&amp;nbsp; It is possible to generate SNMP traps from switches when config is changed:&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.petri.com/notified-cisco-router-configuration-change" title="https://www.petri.com/notified-cisco-router-configuration-change"&gt;https://www.petri.com/notified-cisco-router-configuration-change&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://supportforums.cisco.com/t5/network-management/config-management-snmp-trap/td-p/1955634" title="https://supportforums.cisco.com/t5/network-management/config-management-snmp-trap/td-p/1955634"&gt;Config Management SNMP Trap - Cisco Support Community&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your SNMP Management system can then generate the desired alert.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Craig&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Sep 2017 21:01:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/monitoring-nac/m-p/3479390#M526582</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2017-09-20T21:01:33Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring NAC?</title>
      <link>https://community.cisco.com/t5/network-access-control/monitoring-nac/m-p/3479391#M526585</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ISE does not manage configurations of network devices. Please look for others, such as Cisco Prime Infrastructure -- &lt;A href="https://www.cisco.com/c/en/us/td/docs/net_mgmt/prime/infrastructure/3-1-5/user/guide/pi_ug/chgdevconfig.html#91391"&gt;Comparing Current and Previous Device Configurations&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Sep 2017 21:03:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/monitoring-nac/m-p/3479391#M526585</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2017-09-20T21:03:13Z</dc:date>
    </item>
  </channel>
</rss>

