<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE 2.6 CLI Access through External Identity Store in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-2-6-cli-access-through-external-identity-store/m-p/4097066#M560870</link>
    <description>I am trying to understand how ISE decide the user is a CLI admin with full administrative role privilege or CLI user with read-only role privileges. where is the ISE uses these uidNumber and gidNumber values?</description>
    <pubDate>Wed, 03 Jun 2020 18:17:51 GMT</pubDate>
    <dc:creator>Sp@wn</dc:creator>
    <dc:date>2020-06-03T18:17:51Z</dc:date>
    <item>
      <title>ISE 2.6 CLI Access through External Identity Store</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-6-cli-access-through-external-identity-store/m-p/3994866#M455130</link>
      <description>&lt;P&gt;Hi community,&lt;/P&gt;
&lt;P&gt;I want to configure my AD as an external identity source for ISE CLI access. The only documentation I've found so far is this:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-6/admin_guide/b_ise_admin_guide_26/b_ise_admin_guide_26_chapter_0101.html#id_99029" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/2-6/admin_guide/b_ise_admin_guide_26/b_ise_admin_guide_26_chapter_0101.html#id_99029&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Maybe it's just me but in my opinion it doesn't cut it. Can anyone point me to a more comprehensive documentation? If it does not exist, I think we should create it!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Jonathan&lt;/P&gt;</description>
      <pubDate>Fri, 06 Dec 2019 15:15:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-6-cli-access-through-external-identity-store/m-p/3994866#M455130</guid>
      <dc:creator>JP_Berlin</dc:creator>
      <dc:date>2019-12-06T15:15:28Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.6 CLI Access through External Identity Store</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-6-cli-access-through-external-identity-store/m-p/3994909#M455131</link>
      <description>&lt;P&gt;Within Active Directory, you can edit attributes for a particular user account.&amp;nbsp; The documentation is saying to modify the "gidNumber" and "uidNumber" attributes in Active Directory for the account you want to use as the CLI Admin User.&amp;nbsp; ISE will read those attributes to ensure the user is authorized to be a CLI Admin.&amp;nbsp; These attributes are not used by Active Directory and are not set by default.&amp;nbsp; So you can find your user within AD and go to Properties.&amp;nbsp; Then select "Attribute Editor" to see/edit attributes.&amp;nbsp; If you don't see the "Attribute Editor" tab, then you need to go to View and select the option for "Advanced".&amp;nbsp; Then open Properties again and it will be there.&amp;nbsp; Following are screenshots showing you the default settings for a user in AD for "gidNumber" and "uidNumber":&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="gidnumber.jpg" style="width: 799px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/62945i17A611AAEB68022B/image-size/large?v=v2&amp;amp;px=999" role="button" title="gidnumber.jpg" alt="gidnumber.jpg" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="uidnumber.jpg" style="width: 800px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/62944iDC7DAF2A58AF3EC8/image-size/large?v=v2&amp;amp;px=999" role="button" title="uidnumber.jpg" alt="uidnumber.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Dec 2019 15:58:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-6-cli-access-through-external-identity-store/m-p/3994909#M455131</guid>
      <dc:creator>Colby LeMaire</dc:creator>
      <dc:date>2019-12-06T15:58:21Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.6 CLI Access through External Identity Store</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-6-cli-access-through-external-identity-store/m-p/3995497#M455132</link>
      <description>&lt;P&gt;&lt;A href="https://community.cisco.com/t5/user/viewprofilepage/user-id/624773" target="_blank" rel="noopener"&gt;Colby.LeMaire&lt;/A&gt;&amp;nbsp;is correct.&lt;/P&gt;
&lt;P&gt;Attached is the section of our ISE 2.6 Update lab guide on this feature.&lt;/P&gt;
&lt;P&gt;I also opened a doc bug to ask the admin and cli guides updated.&amp;nbsp;CSCvs37998&lt;/P&gt;</description>
      <pubDate>Sun, 08 Dec 2019 18:22:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-6-cli-access-through-external-identity-store/m-p/3995497#M455132</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2019-12-08T18:22:11Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.6 CLI Access through External Identity Store</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-6-cli-access-through-external-identity-store/m-p/3995707#M455133</link>
      <description>&lt;P&gt;Super helpful, thanks a lot for this description! I have it now running in my lab...&lt;/P&gt;</description>
      <pubDate>Mon, 09 Dec 2019 10:54:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-6-cli-access-through-external-identity-store/m-p/3995707#M455133</guid>
      <dc:creator>JP_Berlin</dc:creator>
      <dc:date>2019-12-09T10:54:06Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.6 CLI Access through External Identity Store</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-6-cli-access-through-external-identity-store/m-p/3995715#M455134</link>
      <description>&lt;P&gt;Thanks a lot for opening the defect. I really appreciate the effort by Product Management on this forum&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":thumbs_up:"&gt;👍🏻&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Some feedback on the feature: I like it and I could make it run in a couple of minutes with this descriptive guide. I just hope we can avoid to rejoin the ISE node from the GUI in the future..&lt;/P&gt;</description>
      <pubDate>Mon, 09 Dec 2019 11:04:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-6-cli-access-through-external-identity-store/m-p/3995715#M455134</guid>
      <dc:creator>JP_Berlin</dc:creator>
      <dc:date>2019-12-09T11:04:10Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.6 CLI Access through External Identity Store</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-6-cli-access-through-external-identity-store/m-p/4096040#M560832</link>
      <description>&lt;P&gt;Hello &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/113005"&gt;@hslai&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is it not necessary to create any tacacs + rules on the ISE using the "gidNumber" and "uidNumber" parameters configured on the Active Directory side, except for active directory integration from the command line?&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jun 2020 09:54:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-6-cli-access-through-external-identity-store/m-p/4096040#M560832</guid>
      <dc:creator>Sp@wn</dc:creator>
      <dc:date>2020-06-02T09:54:50Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.6 CLI Access through External Identity Store</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-6-cli-access-through-external-identity-store/m-p/4096209#M560838</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/39046"&gt;Sp@wn&lt;/a&gt;&amp;nbsp;ISE CLI Admin access is &lt;STRONG&gt;NOT&lt;/STRONG&gt; using ISE T+ so no relationships to ISE T+ rules. I am guessing you are thinking about the admin CLI of Cisco PI, which allows T+.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jun 2020 16:24:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-6-cli-access-through-external-identity-store/m-p/4096209#M560838</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2020-06-03T16:24:42Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.6 CLI Access through External Identity Store</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-6-cli-access-through-external-identity-store/m-p/4097066#M560870</link>
      <description>I am trying to understand how ISE decide the user is a CLI admin with full administrative role privilege or CLI user with read-only role privileges. where is the ISE uses these uidNumber and gidNumber values?</description>
      <pubDate>Wed, 03 Jun 2020 18:17:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-6-cli-access-through-external-identity-store/m-p/4097066#M560870</guid>
      <dc:creator>Sp@wn</dc:creator>
      <dc:date>2020-06-03T18:17:51Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.6 CLI Access through External Identity Store</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-6-cli-access-through-external-identity-store/m-p/4124696#M561904</link>
      <description>&lt;P&gt;From&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-6/admin_guide/b_ise_admin_guide_26/b_ise_admin_guide_26_chapter_0101.html#id_99029" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/2-6/admin_guide/b_ise_admin_guide_26/b_ise_admin_guide_26_chapter_0101.html#id_99029&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P class="p"&gt;Assign&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;gidNumber&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;as 110 or 111.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P class="p"&gt;GidNumber 110 denotes an admin user whereas 111 denotes a read-only user.&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jul 2020 01:05:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-6-cli-access-through-external-identity-store/m-p/4124696#M561904</guid>
      <dc:creator>matthew.shelley</dc:creator>
      <dc:date>2020-07-24T01:05:22Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.6 CLI Access through External Identity Store</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-6-cli-access-through-external-identity-store/m-p/4124826#M561910</link>
      <description>&lt;P&gt;I am trying to understand the configuration made on ISE side for the CLI Access through External Identity Store.&amp;nbsp;I read the document you shared.&amp;nbsp;I did not see a configuration example related with GidNumber on the ISE side, but I encountered the following contradictory statement.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p"&gt;Administrators who belong to a Super Admin group, and are configured to authenticate and authorize using an external identity store, can also authenticate with the external identity store for CLI access.&lt;/P&gt;&lt;DIV class="tableContainer"&gt;&lt;TABLE border="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;IMG src="https://www.cisco.com/content/dam/en/us/td/i/templates/note.gif" border="0" /&gt;&lt;STRONG&gt;Note&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD&gt;&lt;HR /&gt;&lt;P class="p N1_Note1-E8D24015"&gt;You can configure this method of providing external administrator authentication only via the Admin portal. The Cisco ISE Command Line Interface (CLI) does not feature these functions.&lt;/P&gt;&lt;HR /&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;</description>
      <pubDate>Fri, 24 Jul 2020 08:18:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-6-cli-access-through-external-identity-store/m-p/4124826#M561910</guid>
      <dc:creator>Sp@wn</dc:creator>
      <dc:date>2020-07-24T08:18:58Z</dc:date>
    </item>
  </channel>
</rss>

