<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Tacacs : Telnet Vs SSH in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/tacacs-telnet-vs-ssh/m-p/3392558#M548572</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are in the process of migrating our device access from Telnet to SSH using Tacacs+&lt;/P&gt;
&lt;P&gt;In ISE (2.0 #6) we would like to create 2 different users, one user if access is done using Telnet, an other user if access is done via SSH.&lt;/P&gt;
&lt;P&gt;Is there an attribute in the Tacacs+ authentication process in ISE were we can differentiate if a user is using Telnet or SSH?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind regards,&lt;/P&gt;
&lt;P&gt;Lieven Stubbe&lt;/P&gt;
&lt;P&gt;Belgian Railways&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 18:57:16 GMT</pubDate>
    <dc:creator>lni1</dc:creator>
    <dc:date>2020-02-21T18:57:16Z</dc:date>
    <item>
      <title>Tacacs : Telnet Vs SSH</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-telnet-vs-ssh/m-p/3392558#M548572</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are in the process of migrating our device access from Telnet to SSH using Tacacs+&lt;/P&gt;
&lt;P&gt;In ISE (2.0 #6) we would like to create 2 different users, one user if access is done using Telnet, an other user if access is done via SSH.&lt;/P&gt;
&lt;P&gt;Is there an attribute in the Tacacs+ authentication process in ISE were we can differentiate if a user is using Telnet or SSH?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind regards,&lt;/P&gt;
&lt;P&gt;Lieven Stubbe&lt;/P&gt;
&lt;P&gt;Belgian Railways&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 18:57:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-telnet-vs-ssh/m-p/3392558#M548572</guid>
      <dc:creator>lni1</dc:creator>
      <dc:date>2020-02-21T18:57:16Z</dc:date>
    </item>
    <item>
      <title>Re: Tacacs : Telnet Vs SSH</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-telnet-vs-ssh/m-p/3392592#M548576</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I've had a quick look and don't think you can differentiate telnet/ssh protocols in a rule.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What you could do is create 2 separate AuthZ rules and use the condition "TACACS·User EQUALS xxxxxx" for telnet user and another rule for the ssh user, to differentiate between the users. xxxxx = equals the name of the user you create for telnet/ssh.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;HTH&lt;/P&gt;</description>
      <pubDate>Fri, 01 Jun 2018 14:06:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-telnet-vs-ssh/m-p/3392592#M548576</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2018-06-01T14:06:03Z</dc:date>
    </item>
    <item>
      <title>Re: Tacacs : Telnet Vs SSH</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-telnet-vs-ssh/m-p/3392605#M548577</link>
      <description>&lt;P&gt;Hello RJI,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you elaborate the AuthZ solution a little more? I don't quite get it...&lt;/P&gt;
&lt;P&gt;The one user should only be used for Telnet and the other for SSH&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Lieven&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Jun 2018 14:20:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-telnet-vs-ssh/m-p/3392605#M548577</guid>
      <dc:creator>lni1</dc:creator>
      <dc:date>2018-06-01T14:20:31Z</dc:date>
    </item>
    <item>
      <title>Re: Tacacs : Telnet Vs SSH</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-telnet-vs-ssh/m-p/3392628#M548579</link>
      <description>Ah ok, sorry I mis-understood/mis-read, I don't think you can distinguish between telnet/ssh. My suggestion was to merely differentiate the user authentications, which could then be used for different levels of AuthZ.</description>
      <pubDate>Fri, 01 Jun 2018 14:43:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-telnet-vs-ssh/m-p/3392628#M548579</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2018-06-01T14:43:46Z</dc:date>
    </item>
    <item>
      <title>Re: Tacacs : Telnet Vs SSH</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-telnet-vs-ssh/m-p/3393131#M548580</link>
      <description>&lt;P&gt;It seems possible with ASA. See&amp;nbsp;&lt;A href="https://communities.cisco.com/thread/92262" target="_blank"&gt;Device Policy Sets - tacacs ports 443 and 22&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;This depends on the T+ implementation on the network device platforms.&lt;/P&gt;</description>
      <pubDate>Sun, 03 Jun 2018 06:00:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-telnet-vs-ssh/m-p/3393131#M548580</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-06-03T06:00:49Z</dc:date>
    </item>
  </channel>
</rss>

