<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic TACACS Proxy with Service-Argument Attribute not working Issue in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/tacacs-proxy-with-service-argument-attribute-not-working-issue/m-p/4103303#M561223</link>
    <description>&lt;P&gt;Hello, we are trying to utilize TACACS Proxy for the following scenario,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;WLC &amp;lt; ----- &amp;gt; ISE2.6-Patch5 &amp;lt; ----- proxying ----- &amp;gt; Central ISE&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We are using the 'Service-Argument' attribute in the proxied request as below screenshot and we see this on both ISE and in packet captures. When we create a rule however it is not matched using this attribute.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="thumbnail_image005.jpg" style="width: 685px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/76715i00874381DB0C264E/image-size/large?v=v2&amp;amp;px=999" role="button" title="thumbnail_image005.jpg" alt="thumbnail_image005.jpg" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="thumbnail_image019.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/76714i0A229875249E6CFB/image-size/large?v=v2&amp;amp;px=999" role="button" title="thumbnail_image019.png" alt="thumbnail_image019.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The Central ISE does not match this in any of the following cases “EQUALS, CONTAINS, IN, STARTSWITH or MATCHES”. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 15 Jun 2020 12:45:18 GMT</pubDate>
    <dc:creator>joshhunter</dc:creator>
    <dc:date>2020-06-15T12:45:18Z</dc:date>
    <item>
      <title>TACACS Proxy with Service-Argument Attribute not working Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-proxy-with-service-argument-attribute-not-working-issue/m-p/4103303#M561223</link>
      <description>&lt;P&gt;Hello, we are trying to utilize TACACS Proxy for the following scenario,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;WLC &amp;lt; ----- &amp;gt; ISE2.6-Patch5 &amp;lt; ----- proxying ----- &amp;gt; Central ISE&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We are using the 'Service-Argument' attribute in the proxied request as below screenshot and we see this on both ISE and in packet captures. When we create a rule however it is not matched using this attribute.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="thumbnail_image005.jpg" style="width: 685px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/76715i00874381DB0C264E/image-size/large?v=v2&amp;amp;px=999" role="button" title="thumbnail_image005.jpg" alt="thumbnail_image005.jpg" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="thumbnail_image019.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/76714i0A229875249E6CFB/image-size/large?v=v2&amp;amp;px=999" role="button" title="thumbnail_image019.png" alt="thumbnail_image019.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The Central ISE does not match this in any of the following cases “EQUALS, CONTAINS, IN, STARTSWITH or MATCHES”. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jun 2020 12:45:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-proxy-with-service-argument-attribute-not-working-issue/m-p/4103303#M561223</guid>
      <dc:creator>joshhunter</dc:creator>
      <dc:date>2020-06-15T12:45:18Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS Proxy with Service-Argument Attribute not working Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-proxy-with-service-argument-attribute-not-working-issue/m-p/4103313#M561226</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/183914"&gt;@joshhunter&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To absolutely confirm that is indeed this attribute which is not letting the Central ISE match that AuthZ rule, can you please remove the condition where you are looking for this.&lt;/P&gt;
&lt;P&gt;So, if this attribute is really the problem, you should match that particular AuthZ rule with the other two conditions in place.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jun 2020 13:09:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-proxy-with-service-argument-attribute-not-working-issue/m-p/4103313#M561226</guid>
      <dc:creator>Anurag Sharma</dc:creator>
      <dc:date>2020-06-15T13:09:11Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS Proxy with Service-Argument Attribute not working Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-proxy-with-service-argument-attribute-not-working-issue/m-p/4103338#M561228</link>
      <description>Sorry I forgot to mention, yes it matches rules further down, so it is definitely this attribute.&lt;BR /&gt;It needs this attribute to match on we cannot use location, device group, or IP.&lt;BR /&gt;Thanks</description>
      <pubDate>Mon, 15 Jun 2020 13:47:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-proxy-with-service-argument-attribute-not-working-issue/m-p/4103338#M561228</guid>
      <dc:creator>joshhunter</dc:creator>
      <dc:date>2020-06-15T13:47:16Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS Proxy with Service-Argument Attribute not working Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-proxy-with-service-argument-attribute-not-working-issue/m-p/4103566#M561238</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/183914"&gt;@joshhunter&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;How are you "proxying" the requests from one ISE to another?&lt;/LI&gt;
&lt;LI&gt;Which version is the 'Central ISE'?&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;I'd suggest you enable DEBUG for the component called '&lt;SPAN&gt;runtime-AAA' on the central ISE and check there.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The log to check would be prrt-server.log.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Check out this article for debugs and logs:&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/212594-debugs-to-troubleshoot-on-ise.html#anc28" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/212594-debugs-to-troubleshoot-on-ise.html#anc28&lt;/A&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jun 2020 17:20:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-proxy-with-service-argument-attribute-not-working-issue/m-p/4103566#M561238</guid>
      <dc:creator>Anurag Sharma</dc:creator>
      <dc:date>2020-06-15T17:20:39Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS Proxy with Service-Argument Attribute not working Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-proxy-with-service-argument-attribute-not-working-issue/m-p/4103629#M561243</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Central ISE is running 2.7 Patch1 but tried various versions in lab environment.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;TACACS PROXY using the external TACACS server pointing ISE to Central ISE.&lt;BR /&gt;&lt;BR /&gt;I will give the debug ago&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jun 2020 18:24:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-proxy-with-service-argument-attribute-not-working-issue/m-p/4103629#M561243</guid>
      <dc:creator>joshhunter</dc:creator>
      <dc:date>2020-06-15T18:24:51Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS Proxy with Service-Argument Attribute not working Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-proxy-with-service-argument-attribute-not-working-issue/m-p/4103988#M561253</link>
      <description>&lt;P&gt;Hello, I've since tried without TACACS 'Proxy' (Using External TACACS server). It still fails to match.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I tried to match using the service argument of “ciscowlc”.&amp;nbsp; This didn’t match the required rule – again I tried the different options. &amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jun 2020 08:47:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-proxy-with-service-argument-attribute-not-working-issue/m-p/4103988#M561253</guid>
      <dc:creator>joshhunter</dc:creator>
      <dc:date>2020-06-16T08:47:26Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS Proxy with Service-Argument Attribute not working Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-proxy-with-service-argument-attribute-not-working-issue/m-p/4104229#M561258</link>
      <description>&lt;P&gt;The debugging didn't tell me much.&lt;/P&gt;&lt;P&gt;I suspect it is a BUG and will log.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jun 2020 15:59:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-proxy-with-service-argument-attribute-not-working-issue/m-p/4104229#M561258</guid>
      <dc:creator>joshhunter</dc:creator>
      <dc:date>2020-06-16T15:59:23Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS Proxy with Service-Argument Attribute not working Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-proxy-with-service-argument-attribute-not-working-issue/m-p/4104264#M561263</link>
      <description>&lt;P&gt;Alright. Please let us know the findings.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jun 2020 16:51:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-proxy-with-service-argument-attribute-not-working-issue/m-p/4104264#M561263</guid>
      <dc:creator>Anurag Sharma</dc:creator>
      <dc:date>2020-06-16T16:51:20Z</dc:date>
    </item>
  </channel>
</rss>

