<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE 2.1.0 TACACS command sets issue in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-2-1-0-tacacs-command-sets-issue/m-p/3212878#M551424</link>
    <description>Thank you for your response Arne. It would be interesting to get Cisco’s response to this. Logically the command set should block sh  version and allow show run but as we see, this is not the case. &lt;BR /&gt;&lt;BR /&gt;Thanks&lt;BR /&gt;Nick</description>
    <pubDate>Wed, 08 Nov 2017 07:45:55 GMT</pubDate>
    <dc:creator>n-russell-biggie</dc:creator>
    <dc:date>2017-11-08T07:45:55Z</dc:date>
    <item>
      <title>ISE 2.1.0 TACACS command sets issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-1-0-tacacs-command-sets-issue/m-p/3212453#M551414</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P style="padding: 0px; min-height: 8pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have created the below tacacs command set in ISE.&lt;/P&gt;
&lt;P style="padding: 0px; min-height: 8pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://communities.cisco.com/servlet/JiveServlet/showImage/2-273751-113031/pastedImage_0.png" target="_blank"&gt;&lt;IMG width="1082" height="538" class="image-1 jive-image" src="https://communities.cisco.com/servlet/JiveServlet/downloadImage/2-273751-113031/pastedImage_0.png" border="0" /&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P style="padding: 0px; min-height: 8pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When testing I am able to issue the commands conf t and exit but I can not run any show commands. I was intending to deny "show version" and then permit any other show commands but for some reason all "show" commands are being denied.&lt;/P&gt;
&lt;P style="padding: 0px; min-height: 8pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I moved the permit s*w .* above the deny show v* and all worked fine. I was under the impression that the way I have set this up in the screenshot then after issuing a "show run" it would skip past the deny show v* and be permitted by the permit s*w .*&lt;/P&gt;
&lt;P style="padding: 0px; min-height: 8pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can anyone see if I am making an obvious error?&lt;/P&gt;
&lt;P style="padding: 0px; min-height: 8pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Nick&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 18:38:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-1-0-tacacs-command-sets-issue/m-p/3212453#M551414</guid>
      <dc:creator>n-russell-biggie</dc:creator>
      <dc:date>2020-02-21T18:38:27Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.1.0 TACACS command sets issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-1-0-tacacs-command-sets-issue/m-p/3212529#M551417</link>
      <description>&lt;P&gt;I have now patched this to patch level six in the hope that it is possibly a bug. Still the same results.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Nov 2017 18:12:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-1-0-tacacs-command-sets-issue/m-p/3212529#M551417</guid>
      <dc:creator>n-russell-biggie</dc:creator>
      <dc:date>2017-11-07T18:12:57Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.1.0 TACACS command sets issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-1-0-tacacs-command-sets-issue/m-p/3212790#M551420</link>
      <description>&lt;P&gt;Hi Nick&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Very good question.&amp;nbsp; I hadn't noticed this before.&amp;nbsp; And I am keen to get a Cisco response on this.&amp;nbsp; I am still on ISE 2.2 patch 2 and upgrading to ISE 2.3 patch 1 tomorrow.&amp;nbsp; My experience with the TACACS functionality has been not so good - I have had issues were the PAN no longer sent the TACACS programming to the PSN nodes.&amp;nbsp; I configured the he&amp;amp;*% out of the Policy Sets and none of it landed on the PSNs!&amp;nbsp; Only after restarted the PAN, my PSN's got programmed again.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I tried the stuff below and no matter which way around I put the sh commands, I cannot execute the logic you want. I.e when I have it as shown below, then&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;show run&lt;/STRONG&gt; fails&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;show ver&lt;/STRONG&gt; fails&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ise-tacacs.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/3025i8729DF5E0CD5E614/image-size/large?v=v2&amp;amp;px=999" role="button" title="ise-tacacs.PNG" alt="ise-tacacs.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;When I have it as follows&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ise-tacacs2.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/3026iA0924931E34126FE/image-size/large?v=v2&amp;amp;px=999" role="button" title="ise-tacacs2.PNG" alt="ise-tacacs2.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;then&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;show run&lt;/STRONG&gt; passes&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;show ver&lt;/STRONG&gt; passes&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How bizarre.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Nov 2017 23:57:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-1-0-tacacs-command-sets-issue/m-p/3212790#M551420</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2017-11-07T23:57:05Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.1.0 TACACS command sets issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-1-0-tacacs-command-sets-issue/m-p/3212878#M551424</link>
      <description>Thank you for your response Arne. It would be interesting to get Cisco’s response to this. Logically the command set should block sh  version and allow show run but as we see, this is not the case. &lt;BR /&gt;&lt;BR /&gt;Thanks&lt;BR /&gt;Nick</description>
      <pubDate>Wed, 08 Nov 2017 07:45:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-1-0-tacacs-command-sets-issue/m-p/3212878#M551424</guid>
      <dc:creator>n-russell-biggie</dc:creator>
      <dc:date>2017-11-08T07:45:55Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.1.0 TACACS command sets issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-1-0-tacacs-command-sets-issue/m-p/3215095#M551426</link>
      <description>&lt;P&gt;Hey Nick/Arne,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Looks like ISE is not able to match "version" using the&amp;nbsp;regexp v* or ve* but it works with ver*. Same with run* instead of r* or ru*.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am not sure if this has already been documented as a defect (I will double check). In the meantime, if you edit your argument for ver* everything should work.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best regards,&lt;/P&gt;
&lt;P&gt;dacabrer&lt;/P&gt;</description>
      <pubDate>Sun, 12 Nov 2017 03:04:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-1-0-tacacs-command-sets-issue/m-p/3215095#M551426</guid>
      <dc:creator>dacabrer</dc:creator>
      <dc:date>2017-11-12T03:04:10Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.1.0 TACACS command sets issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-1-0-tacacs-command-sets-issue/m-p/3215964#M551429</link>
      <description>&lt;P&gt;This discussion was continued over at the Cisco Communities Forum for ISE, and I wrote some updates there&lt;/P&gt;
&lt;P&gt;&lt;A href="https://communities.cisco.com/message/273751#273751" target="_blank"&gt;https://communities.cisco.com/message/273751#273751&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Bottom line is, that the documentation is quite clear about the behaviour, but it is buried deep in the 1200 page manual.&amp;nbsp; I show some examples of how it works in the Communities post.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Nov 2017 00:25:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-1-0-tacacs-command-sets-issue/m-p/3215964#M551429</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2017-11-14T00:25:42Z</dc:date>
    </item>
  </channel>
</rss>

