<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE Tacacs+ authentication CSCuy46322 (Restrict Authentiated but not Authorized users access to VTY) in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-tacacs-authentication-cscuy46322-restrict-authentiated-but/m-p/3548877#M536777</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Team, good day !&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regarding: &lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCuy46322/?referring_site=bugquickviewredir"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCuy46322/?referring_site=bugquickviewredir&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And situation when any user from AD can access VTY with default DenyAllCommands authorization policy &amp;amp; many such logins could potentially deny Administration access through VTY.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In bug notice, known fixed release is ISE &lt;SPAN lang="EN-US" style="font-size: 9.0pt; font-family: 'Arial','sans-serif'; color: #444444; background: white;"&gt;2.1(0.474).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-size: 9.0pt; font-family: 'Arial','sans-serif'; color: #444444; background: white;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-size: 10.0pt; font-family: 'Arial','sans-serif'; color: #444444; background: white;"&gt;We have all patches installed on ISE:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-size: 10.0pt; font-family: 'Helvetica','sans-serif'; color: black;"&gt;Cisco Identity Services Engine&lt;/SPAN&gt;&lt;BR /&gt; &lt;SPAN lang="EN-US" style="font-size: 10.0pt; font-family: 'Helvetica','sans-serif'; color: black;"&gt;---------------------------------------------&lt;/SPAN&gt;&lt;BR /&gt; &lt;SPAN lang="EN-US" style="font-size: 10.0pt; font-family: 'Helvetica','sans-serif'; color: black;"&gt;Version : 2.1.0.474&lt;/SPAN&gt;&lt;BR /&gt; &lt;SPAN lang="EN-US" style="font-size: 10.0pt; font-family: 'Helvetica','sans-serif'; color: black;"&gt;Build Date&amp;nbsp;&amp;nbsp; : Wed May 25 07:34:43 &lt;/SPAN&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;SPAN lang="EN-US" style="font-size: 10.0pt; font-family: 'Helvetica','sans-serif'; color: blue;"&gt;2016&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt; &lt;SPAN lang="EN-US" style="font-size: 10.0pt; font-family: 'Helvetica','sans-serif'; color: black;"&gt;Install Date : Mon Sep 19 21:08:02 &lt;/SPAN&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;SPAN lang="EN-US" style="font-size: 10.0pt; font-family: 'Helvetica','sans-serif'; color: blue;"&gt;2016&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt; &lt;BR /&gt; &lt;SPAN lang="EN-US" style="font-size: 10.0pt; font-family: 'Helvetica','sans-serif'; color: black;"&gt;Cisco Identity Services Engine Patch &lt;/SPAN&gt;&lt;BR /&gt; &lt;SPAN lang="EN-US" style="font-size: 10.0pt; font-family: 'Helvetica','sans-serif'; color: black;"&gt;---------------------------------------------&lt;/SPAN&gt;&lt;BR /&gt; &lt;SPAN lang="EN-US" style="font-size: 10.0pt; font-family: 'Helvetica','sans-serif'; color: black;"&gt;Version : 1&lt;/SPAN&gt;&lt;BR /&gt; &lt;SPAN lang="EN-US" style="font-size: 10.0pt; font-family: 'Helvetica','sans-serif'; color: black;"&gt;Install Date : Mon Sep 19 23:50:15 &lt;/SPAN&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;SPAN lang="EN-US" style="font-size: 10.0pt; font-family: 'Helvetica','sans-serif'; color: blue;"&gt;2016&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt; &lt;BR /&gt; &lt;SPAN lang="EN-US" style="font-size: 10.0pt; font-family: 'Helvetica','sans-serif'; color: black;"&gt;Cisco Identity Services Engine Patch &lt;/SPAN&gt;&lt;BR /&gt; &lt;SPAN lang="EN-US" style="font-size: 10.0pt; font-family: 'Helvetica','sans-serif'; color: black;"&gt;---------------------------------------------&lt;/SPAN&gt;&lt;BR /&gt; &lt;SPAN lang="EN-US" style="font-size: 10.0pt; font-family: 'Helvetica','sans-serif'; color: black;"&gt;Version : 2&lt;/SPAN&gt;&lt;BR /&gt; &lt;SPAN lang="EN-US" style="font-size: 10.0pt; font-family: 'Helvetica','sans-serif'; color: black;"&gt;Install Date : Mon Nov 28 11:52:19 &lt;/SPAN&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;SPAN lang="EN-US" style="font-size: 10.0pt; font-family: 'Helvetica','sans-serif'; color: blue;"&gt;2016&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;And provided few tests regarding Authentication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;OL style="list-style-type: decimal;"&gt;&lt;LI&gt;1) DenyAllCommands can not be deleted (to test DefaultDeny access to VTY)&lt;/LI&gt;&lt;LI&gt;2) Authenticated, but not authorized user still can access to VTY &lt;/LI&gt;&lt;LI&gt;3) Tried execute Autocommand ‘exit’ on such users – command doesn’t works&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Team, any workarounds/solutions not to allow Authenticated, but not Authorized users not to allow access to VTY ? Or restrict Authentication to specific AD groups/OU’s ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you !&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 06 Dec 2016 10:57:47 GMT</pubDate>
    <dc:creator>epetyaks</dc:creator>
    <dc:date>2016-12-06T10:57:47Z</dc:date>
    <item>
      <title>ISE Tacacs+ authentication CSCuy46322 (Restrict Authentiated but not Authorized users access to VTY)</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-tacacs-authentication-cscuy46322-restrict-authentiated-but/m-p/3548877#M536777</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Team, good day !&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regarding: &lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCuy46322/?referring_site=bugquickviewredir"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCuy46322/?referring_site=bugquickviewredir&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And situation when any user from AD can access VTY with default DenyAllCommands authorization policy &amp;amp; many such logins could potentially deny Administration access through VTY.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In bug notice, known fixed release is ISE &lt;SPAN lang="EN-US" style="font-size: 9.0pt; font-family: 'Arial','sans-serif'; color: #444444; background: white;"&gt;2.1(0.474).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-size: 9.0pt; font-family: 'Arial','sans-serif'; color: #444444; background: white;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-size: 10.0pt; font-family: 'Arial','sans-serif'; color: #444444; background: white;"&gt;We have all patches installed on ISE:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-size: 10.0pt; font-family: 'Helvetica','sans-serif'; color: black;"&gt;Cisco Identity Services Engine&lt;/SPAN&gt;&lt;BR /&gt; &lt;SPAN lang="EN-US" style="font-size: 10.0pt; font-family: 'Helvetica','sans-serif'; color: black;"&gt;---------------------------------------------&lt;/SPAN&gt;&lt;BR /&gt; &lt;SPAN lang="EN-US" style="font-size: 10.0pt; font-family: 'Helvetica','sans-serif'; color: black;"&gt;Version : 2.1.0.474&lt;/SPAN&gt;&lt;BR /&gt; &lt;SPAN lang="EN-US" style="font-size: 10.0pt; font-family: 'Helvetica','sans-serif'; color: black;"&gt;Build Date&amp;nbsp;&amp;nbsp; : Wed May 25 07:34:43 &lt;/SPAN&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;SPAN lang="EN-US" style="font-size: 10.0pt; font-family: 'Helvetica','sans-serif'; color: blue;"&gt;2016&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt; &lt;SPAN lang="EN-US" style="font-size: 10.0pt; font-family: 'Helvetica','sans-serif'; color: black;"&gt;Install Date : Mon Sep 19 21:08:02 &lt;/SPAN&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;SPAN lang="EN-US" style="font-size: 10.0pt; font-family: 'Helvetica','sans-serif'; color: blue;"&gt;2016&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt; &lt;BR /&gt; &lt;SPAN lang="EN-US" style="font-size: 10.0pt; font-family: 'Helvetica','sans-serif'; color: black;"&gt;Cisco Identity Services Engine Patch &lt;/SPAN&gt;&lt;BR /&gt; &lt;SPAN lang="EN-US" style="font-size: 10.0pt; font-family: 'Helvetica','sans-serif'; color: black;"&gt;---------------------------------------------&lt;/SPAN&gt;&lt;BR /&gt; &lt;SPAN lang="EN-US" style="font-size: 10.0pt; font-family: 'Helvetica','sans-serif'; color: black;"&gt;Version : 1&lt;/SPAN&gt;&lt;BR /&gt; &lt;SPAN lang="EN-US" style="font-size: 10.0pt; font-family: 'Helvetica','sans-serif'; color: black;"&gt;Install Date : Mon Sep 19 23:50:15 &lt;/SPAN&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;SPAN lang="EN-US" style="font-size: 10.0pt; font-family: 'Helvetica','sans-serif'; color: blue;"&gt;2016&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt; &lt;BR /&gt; &lt;SPAN lang="EN-US" style="font-size: 10.0pt; font-family: 'Helvetica','sans-serif'; color: black;"&gt;Cisco Identity Services Engine Patch &lt;/SPAN&gt;&lt;BR /&gt; &lt;SPAN lang="EN-US" style="font-size: 10.0pt; font-family: 'Helvetica','sans-serif'; color: black;"&gt;---------------------------------------------&lt;/SPAN&gt;&lt;BR /&gt; &lt;SPAN lang="EN-US" style="font-size: 10.0pt; font-family: 'Helvetica','sans-serif'; color: black;"&gt;Version : 2&lt;/SPAN&gt;&lt;BR /&gt; &lt;SPAN lang="EN-US" style="font-size: 10.0pt; font-family: 'Helvetica','sans-serif'; color: black;"&gt;Install Date : Mon Nov 28 11:52:19 &lt;/SPAN&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;SPAN lang="EN-US" style="font-size: 10.0pt; font-family: 'Helvetica','sans-serif'; color: blue;"&gt;2016&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;And provided few tests regarding Authentication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;OL style="list-style-type: decimal;"&gt;&lt;LI&gt;1) DenyAllCommands can not be deleted (to test DefaultDeny access to VTY)&lt;/LI&gt;&lt;LI&gt;2) Authenticated, but not authorized user still can access to VTY &lt;/LI&gt;&lt;LI&gt;3) Tried execute Autocommand ‘exit’ on such users – command doesn’t works&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Team, any workarounds/solutions not to allow Authenticated, but not Authorized users not to allow access to VTY ? Or restrict Authentication to specific AD groups/OU’s ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you !&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Dec 2016 10:57:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-tacacs-authentication-cscuy46322-restrict-authentiated-but/m-p/3548877#M536777</guid>
      <dc:creator>epetyaks</dc:creator>
      <dc:date>2016-12-06T10:57:47Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Tacacs+ authentication CSCuy46322 (Restrict Authentiated but not Authorized users access to VTY)</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-tacacs-authentication-cscuy46322-restrict-authentiated-but/m-p/3548878#M536780</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If seen only with NX-OS, it's likely due to known issues with NX-OS devices. I documented the workaround in the lab guide for T+ in Sales Connect.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Otherwise, you are likely hitting a newer bug -- CSCvc15000.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Dec 2016 17:32:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-tacacs-authentication-cscuy46322-restrict-authentiated-but/m-p/3548878#M536780</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2016-12-06T17:32:54Z</dc:date>
    </item>
  </channel>
</rss>

