<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How can we enable write access on allowed change window in TACACS (ACS)via change record? in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/how-can-we-enable-write-access-on-allowed-change-window-in/m-p/3956099#M557127</link>
    <description>Thank you for solution on ACS. I need to work more to create demo and then move it to prod.</description>
    <pubDate>Sat, 09 Nov 2019 13:11:21 GMT</pubDate>
    <dc:creator>ranjanvishwakarma4</dc:creator>
    <dc:date>2019-11-09T13:11:21Z</dc:date>
    <item>
      <title>How can we enable write access on allowed change window in TACACS (ACS)via change record?</title>
      <link>https://community.cisco.com/t5/network-access-control/how-can-we-enable-write-access-on-allowed-change-window-in/m-p/3951875#M557115</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Current Scenario&lt;/STRONG&gt;-&lt;/P&gt;&lt;P&gt;Network engineer have TACACS (r/w) access so there is possibility authorized engineer can do not schedule or without record change , which can cause outage .&lt;/P&gt;&lt;P&gt;Since engineer have authorized to do make change they do changes and unfortunately brings outages.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Need help on -&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;What if Engineer’s TACACS write access enabled only in &amp;nbsp;change window ?&lt;/P&gt;&lt;P&gt;Is it possible ? we are using snow ticketing solution&amp;nbsp; and there is stages of change record like New-&amp;gt;schedule-&amp;gt;implement.&lt;/P&gt;&lt;P&gt;As per change window timing TACACS will &amp;nbsp;be in &lt;STRONG&gt;write&lt;/STRONG&gt; mode else always in read mode.&lt;/P&gt;&lt;P&gt;So any change owner whose change comes in Implement stage &amp;nbsp;can do the change because at that time only write access would enable.&lt;/P&gt;&lt;P&gt;Can anyone please suggest if it is possible in traditional way of ACS configuration ?&lt;/P&gt;&lt;P&gt;we are not using ISE Solution as of now.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 19:11:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-can-we-enable-write-access-on-allowed-change-window-in/m-p/3951875#M557115</guid>
      <dc:creator>ranjanvishwakarma4</dc:creator>
      <dc:date>2020-02-21T19:11:19Z</dc:date>
    </item>
    <item>
      <title>Re: How can we enable write access on allowed change window in TACACS (ACS)via change record?</title>
      <link>https://community.cisco.com/t5/network-access-control/how-can-we-enable-write-access-on-allowed-change-window-in/m-p/3952203#M557118</link>
      <description>Hi&lt;BR /&gt;&lt;BR /&gt;On ise you can create rules based on a time and date condition. However, i don't recall any API available to modify it dynamically.&lt;BR /&gt;You'll need to do it manually and i believe it's going to be a nightmare.&lt;BR /&gt;&lt;BR /&gt;What you can do is using api to modify the tacacs profile. This means you need to find a way to get the date and information saved from your tool and dynamically create a cron job that will modify the tacacs profile at that date and time using ise API.&lt;BR /&gt;&lt;BR /&gt;Right now, i don't think any other solution but if something comes up in my mind i let you know.</description>
      <pubDate>Sun, 03 Nov 2019 04:01:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-can-we-enable-write-access-on-allowed-change-window-in/m-p/3952203#M557118</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2019-11-03T04:01:20Z</dc:date>
    </item>
    <item>
      <title>Re: How can we enable write access on allowed change window in TACACS (ACS)via change record?</title>
      <link>https://community.cisco.com/t5/network-access-control/how-can-we-enable-write-access-on-allowed-change-window-in/m-p/3952221#M557121</link>
      <description>Thank you so much for replying.&lt;BR /&gt;This though was for my automation Idea and seems Like i have to dig more on solution however your suggestion is very helpful and greatly appreciated.&lt;BR /&gt;</description>
      <pubDate>Sun, 03 Nov 2019 07:04:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-can-we-enable-write-access-on-allowed-change-window-in/m-p/3952221#M557121</guid>
      <dc:creator>ranjanvishwakarma4</dc:creator>
      <dc:date>2019-11-03T07:04:39Z</dc:date>
    </item>
    <item>
      <title>Re: How can we enable write access on allowed change window in TACACS (ACS)via change record?</title>
      <link>https://community.cisco.com/t5/network-access-control/how-can-we-enable-write-access-on-allowed-change-window-in/m-p/3953117#M557124</link>
      <description>You're welcome.</description>
      <pubDate>Tue, 05 Nov 2019 04:06:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-can-we-enable-write-access-on-allowed-change-window-in/m-p/3953117#M557124</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2019-11-05T04:06:44Z</dc:date>
    </item>
    <item>
      <title>Re: How can we enable write access on allowed change window in TACACS (ACS)via change record?</title>
      <link>https://community.cisco.com/t5/network-access-control/how-can-we-enable-write-access-on-allowed-change-window-in/m-p/3954491#M557126</link>
      <description>&lt;P&gt;Similar to ISE, ACS 5.8 appears also have&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/td/docs/net_mgmt/cisco_secure_access_control_system/5-8/user/guide/acsuserguide/pol_elem.html#pgfId-1194868" target="_blank"&gt;Date and Time Conditions&lt;/A&gt;. In case the maintenance windows are always on specific days and hours (e.g. Sunday 12:01 midnight to 06:00 AM), it's not so bad to use date/time conditions. And, you may combine it by user group memberships, which might possibly be updated via API.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Nov 2019 04:58:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-can-we-enable-write-access-on-allowed-change-window-in/m-p/3954491#M557126</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2019-11-07T04:58:30Z</dc:date>
    </item>
    <item>
      <title>Re: How can we enable write access on allowed change window in TACACS (ACS)via change record?</title>
      <link>https://community.cisco.com/t5/network-access-control/how-can-we-enable-write-access-on-allowed-change-window-in/m-p/3956099#M557127</link>
      <description>Thank you for solution on ACS. I need to work more to create demo and then move it to prod.</description>
      <pubDate>Sat, 09 Nov 2019 13:11:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-can-we-enable-write-access-on-allowed-change-window-in/m-p/3956099#M557127</guid>
      <dc:creator>ranjanvishwakarma4</dc:creator>
      <dc:date>2019-11-09T13:11:21Z</dc:date>
    </item>
  </channel>
</rss>

