<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CIsco ISE vs Prime Infrastructure 3.0 in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-vs-prime-infrastructure-3-0/m-p/3177753#M554980</link>
    <description>&lt;P&gt;Your original question was about TACACS and ISE, in your screenshots you are configuring RADIUS authentication. For TACACS you need to go to Work Centers -&amp;gt; Device Administration -&amp;gt; Device Administration policy sets and also Policy elements. In TACACS&amp;nbsp;Policy elements&amp;nbsp;create a new TACACS profile, set type to Generic and add the attributes. I added all attributes from Prime. I have attached the list of what I have.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In TACACS profiles you can click Raw View and copy/paste all these attributes, without having to add them one by one.. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 30 Aug 2017 10:20:21 GMT</pubDate>
    <dc:creator>agrissimanis</dc:creator>
    <dc:date>2017-08-30T10:20:21Z</dc:date>
    <item>
      <title>CIsco ISE vs Prime Infrastructure 3.0</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-vs-prime-infrastructure-3-0/m-p/3177686#M554976</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;can i use ISE as a TACACS+ server for login to Cisco Prime Infra 3.0?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 18:33:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-vs-prime-infrastructure-3-0/m-p/3177686#M554976</guid>
      <dc:creator>exmode</dc:creator>
      <dc:date>2020-02-21T18:33:08Z</dc:date>
    </item>
    <item>
      <title>Re: CIsco ISE vs Prime Infrastructure 3.0</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-vs-prime-infrastructure-3-0/m-p/3177697#M554977</link>
      <description>&lt;P&gt;Absolutely, you can.&lt;/P&gt;&lt;P&gt;Have a look at the Prime admin guide -&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/td/docs/net_mgmt/prime/infrastructure/3-1/administrator/guide/PIAdminBook/maint_user_access.html#95932" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/net_mgmt/prime/infrastructure/3-1/administrator/guide/PIAdminBook/maint_user_access.html#95932&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Let me know if you get stuck with the config&lt;/P&gt;&lt;P&gt;The only bit I found tricky was to get the TACACS profile for Prime correct.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Aug 2017 07:57:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-vs-prime-infrastructure-3-0/m-p/3177697#M554977</guid>
      <dc:creator>agrissimanis</dc:creator>
      <dc:date>2017-08-30T07:57:18Z</dc:date>
    </item>
    <item>
      <title>Re: CIsco ISE vs Prime Infrastructure 3.0</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-vs-prime-infrastructure-3-0/m-p/3177721#M554978</link>
      <description>&lt;P&gt;In this paragraph &lt;STRONG&gt;Creating a New Authorization Profile in ISE &lt;/STRONG&gt;it is written :&lt;/P&gt;&lt;P class="pSN_StepNext"&gt;&lt;EM&gt;&lt;STRONG&gt;Step 5&lt;/STRONG&gt; In the Advanced Attribute Settings area, add Prime Infrastructure user group RADIUS custom attributes one after another along with the virtual domain attributes at the end.&lt;/EM&gt;&lt;/P&gt;&lt;P class="pSN_StepNext"&gt;&lt;EM&gt;User group RADIUS custom attributes are located in Prime Infrastructure at&amp;nbsp;&lt;STRONG&gt;Administration &amp;gt; Users &amp;gt; Users, Roles &amp;amp; AAA &amp;gt; User Groups&lt;/STRONG&gt;&amp;nbsp;. Click&amp;nbsp;&lt;STRONG&gt;Task List&lt;/STRONG&gt;&amp;nbsp;for the group with appropriate permissions.&lt;/EM&gt;&lt;/P&gt;&lt;P class="pSB_StepBody"&gt;&lt;EM&gt;&amp;nbsp; a. Select&amp;nbsp;&lt;STRONG&gt;cisco - av - pair&lt;/STRONG&gt;&amp;nbsp;and paste Prime Infrastructure user group RADIUS custom attribute next to it. Keep adding one after another.&lt;/EM&gt;&lt;/P&gt;&lt;P class="pSB_StepBody"&gt;&lt;EM&gt;&amp;nbsp; b. Add the Virtual Domain attribute at the end of the last RADIUS custom attribute for each group (for RADIUS custom attributes, see “Exporting Virtual Domain RADIUS and TACACS+ Attributes”).&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If i see on Prime&amp;nbsp;&lt;EM&gt;&lt;STRONG&gt;Task List&lt;/STRONG&gt;&amp;nbsp; for&amp;nbsp;&lt;STRONG&gt;User Groups &amp;gt; SuperUser&lt;/STRONG&gt;&lt;/EM&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;STRONG&gt;(see atttach file - &lt;/STRONG&gt;Prime User Groups.png&lt;STRONG&gt;) &lt;/STRONG&gt;its many attributes.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Should I add them all in this way (&lt;STRONG&gt;see atttach file -&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;ISE New Authorization Profile for Prime .png)?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Aug 2017 08:48:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-vs-prime-infrastructure-3-0/m-p/3177721#M554978</guid>
      <dc:creator>exmode</dc:creator>
      <dc:date>2017-08-30T08:48:49Z</dc:date>
    </item>
    <item>
      <title>Re: CIsco ISE vs Prime Infrastructure 3.0</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-vs-prime-infrastructure-3-0/m-p/3177745#M554979</link>
      <description>&lt;P&gt;If I understand correctly, when create Authorization Profile then you need only to specify attributes: role and virtual-domain&lt;/P&gt;&lt;P&gt;Access Type = ACCESS_ACCEPT&lt;/P&gt;&lt;P&gt;cisco-av-pair = NCS:role0=Super Users&lt;/P&gt;&lt;P&gt;cisco-av-pair = NCS:virtual-domain0=ROOT-DOMAIN&lt;/P&gt;</description>
      <pubDate>Wed, 30 Aug 2017 09:37:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-vs-prime-infrastructure-3-0/m-p/3177745#M554979</guid>
      <dc:creator>exmode</dc:creator>
      <dc:date>2017-08-30T09:37:08Z</dc:date>
    </item>
    <item>
      <title>Re: CIsco ISE vs Prime Infrastructure 3.0</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-vs-prime-infrastructure-3-0/m-p/3177753#M554980</link>
      <description>&lt;P&gt;Your original question was about TACACS and ISE, in your screenshots you are configuring RADIUS authentication. For TACACS you need to go to Work Centers -&amp;gt; Device Administration -&amp;gt; Device Administration policy sets and also Policy elements. In TACACS&amp;nbsp;Policy elements&amp;nbsp;create a new TACACS profile, set type to Generic and add the attributes. I added all attributes from Prime. I have attached the list of what I have.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In TACACS profiles you can click Raw View and copy/paste all these attributes, without having to add them one by one.. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Aug 2017 10:20:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-vs-prime-infrastructure-3-0/m-p/3177753#M554980</guid>
      <dc:creator>agrissimanis</dc:creator>
      <dc:date>2017-08-30T10:20:21Z</dc:date>
    </item>
    <item>
      <title>Re: CIsco ISE vs Prime Infrastructure 3.0</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-vs-prime-infrastructure-3-0/m-p/3177814#M554981</link>
      <description>&lt;P&gt;Yes, the first question was about TACACS+, but after you gave me the link I saw&lt;EM&gt;&lt;STRONG&gt; Authenticating AAA Users Through RADIUS Using ISE: Workflow&lt;/STRONG&gt;&lt;/EM&gt; and tried to make settings for the RADIUS, for &lt;SPAN&gt;TACACS+&amp;nbsp;&lt;/SPAN&gt;also did the work.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;In your list, the attribute virtual-domain0=ROOT-DOMAIN is added to the beginning, when configure &lt;EM&gt;Authorization Profiles&lt;/EM&gt; for RADIUS, attribute Virtual Domain add at the end list.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Aug 2017 12:01:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-vs-prime-infrastructure-3-0/m-p/3177814#M554981</guid>
      <dc:creator>exmode</dc:creator>
      <dc:date>2017-08-30T12:01:38Z</dc:date>
    </item>
  </channel>
</rss>

