<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: TACACS  vs RADIUS in AAA in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/tacacs-vs-radius-in-aaa/m-p/3453607#M536513</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Kevin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, you can use RADIUS for device admin but will have a lot of limitations when compared to TACACS+.&amp;nbsp; You will lack command authorization functionality if you use RADIUS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;-Tim&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 12 Jan 2017 18:16:45 GMT</pubDate>
    <dc:creator>Timothy Abbott</dc:creator>
    <dc:date>2017-01-12T18:16:45Z</dc:date>
    <item>
      <title>TACACS  vs RADIUS in AAA</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-vs-radius-in-aaa/m-p/3453606#M536511</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can RADIUS be used for Device Administration on ISE?&amp;nbsp; Or is TACACS+ the only way to do AAA on ISE? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a system with Cisco and Alcatel devices, and Alcatel devices seem to prefer RADIUS for AAA. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Jan 2017 18:02:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-vs-radius-in-aaa/m-p/3453606#M536511</guid>
      <dc:creator>kevin.mckee</dc:creator>
      <dc:date>2017-01-12T18:02:13Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS  vs RADIUS in AAA</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-vs-radius-in-aaa/m-p/3453607#M536513</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Kevin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, you can use RADIUS for device admin but will have a lot of limitations when compared to TACACS+.&amp;nbsp; You will lack command authorization functionality if you use RADIUS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;-Tim&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Jan 2017 18:16:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-vs-radius-in-aaa/m-p/3453607#M536513</guid>
      <dc:creator>Timothy Abbott</dc:creator>
      <dc:date>2017-01-12T18:16:45Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS  vs RADIUS in AAA</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-vs-radius-in-aaa/m-p/3453608#M536514</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've been able to get authentication working through RADIUS on ISE 2.1, but it seems to be handled through the network access side, and not the device administration side.&amp;nbsp; On Alcatel devices, the authorization is normally handled through RADIUS, which is why I was hoping to get it working on that side.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Jan 2017 18:34:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-vs-radius-in-aaa/m-p/3453608#M536514</guid>
      <dc:creator>kevin.mckee</dc:creator>
      <dc:date>2017-01-12T18:34:36Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS  vs RADIUS in AAA</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-vs-radius-in-aaa/m-p/3453609#M536516</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I was able to get AUTHORIZATION working through TACACS+ to the Alcatel/Nokia devices.&amp;nbsp; I'll will be waiting for the ISE 2.2 beta to see if any of this is addressed in the new features.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Jan 2017 22:39:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-vs-radius-in-aaa/m-p/3453609#M536516</guid>
      <dc:creator>kevin.mckee</dc:creator>
      <dc:date>2017-01-13T22:39:13Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS  vs RADIUS in AAA</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-vs-radius-in-aaa/m-p/3453610#M536518</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Be sure to communicate with Cisco account team so they can work with product management on any specific gaps.&amp;nbsp; You have not clarified what specifically you are looking to be addressed in newer release.&amp;nbsp; The lack of command authorization and command accounting is not a limitation of ISE RADIUS implementation, but a limitation of standard RADIUS protocol. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ISE certainly supports standard RADIUS authentication and authorization. Some NADs may support specific attributes to control device admin privileges.&amp;nbsp; If not already loaded, these can be imported into ISE and returned as part of the RADIUS authorization to the device itself.&amp;nbsp; We separated TACACS+ under its own section and titled it "Device Admin" since that is primary use case for TACACS+.&amp;nbsp; However, it is true that some use RADIUS for Device Admin function, but that would be configured under original policy for RADIUS auth.&amp;nbsp; Many customers choose to create a Policy Set specific to RADIUS Device Admin which matches on NDG, RADIUS service type, or other discriminating attribute which is specific to device admin.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;/Craig&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Jan 2017 23:49:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-vs-radius-in-aaa/m-p/3453610#M536518</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2017-01-17T23:49:54Z</dc:date>
    </item>
  </channel>
</rss>

