<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE 2.6 and Cat9800 tacacs+ config for Lobby Admin in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-2-6-and-cat9800-tacacs-config-for-lobby-admin/m-p/4105772#M561294</link>
    <description>&lt;P&gt;Check if you are running into below issue:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvs87163" target="_blank"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvs87163&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If the lobby admin user is getting full access?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 18 Jun 2020 16:42:19 GMT</pubDate>
    <dc:creator>poongarg</dc:creator>
    <dc:date>2020-06-18T16:42:19Z</dc:date>
    <item>
      <title>ISE 2.6 and Cat9800 tacacs+ config for Lobby Admin</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-6-and-cat9800-tacacs-config-for-lobby-admin/m-p/4105578#M561289</link>
      <description>&lt;P&gt;Hello,&amp;nbsp; we are currently in the migration phase to a catalyst 9800 wlc. I am currently working on the tacacs configuration and I making no progress with setting up the lobby admins tacacs profile.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;With the old airos wlc you could simply select "Lobby Admin" in the tacacs profile, but with the new IOSXE-based&amp;nbsp; wlc the profile don't work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A profile for admin access is working fine at privilege level 15. Can anyone help me with that?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards Jan&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jun 2020 12:11:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-6-and-cat9800-tacacs-config-for-lobby-admin/m-p/4105578#M561289</guid>
      <dc:creator>Jan81</dc:creator>
      <dc:date>2020-06-18T12:11:22Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.6 and Cat9800 tacacs+ config for Lobby Admin</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-6-and-cat9800-tacacs-config-for-lobby-admin/m-p/4105772#M561294</link>
      <description>&lt;P&gt;Check if you are running into below issue:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvs87163" target="_blank"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvs87163&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If the lobby admin user is getting full access?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jun 2020 16:42:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-6-and-cat9800-tacacs-config-for-lobby-admin/m-p/4105772#M561294</guid>
      <dc:creator>poongarg</dc:creator>
      <dc:date>2020-06-18T16:42:19Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.6 and Cat9800 tacacs+ config for Lobby Admin</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-6-and-cat9800-tacacs-config-for-lobby-admin/m-p/4106129#M561303</link>
      <description>&lt;P&gt;Thanks, I have checked the aaa config and reconfigure the&amp;nbsp;&lt;SPAN&gt;authorization and authentication settings.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;But my problem is to configure the tacacs profile and command sets. For admin access it works fine with priv level 15. But for lobby admin access I don´t know what I must configure. For the old airos wlc it was easy to choose the right value, but his won´t work for catalyst 9800 wlc.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If I add a local lobby admin account on the wlc, I see that the user has the following settings.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;user-name lobby
 view LobbyAdminView
 type lobby-admin&lt;/PRE&gt;&lt;P&gt;&lt;SPAN&gt;But when I configure this as custom attributes in the tacacs profiles it won´t work.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jun 2020 05:44:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-6-and-cat9800-tacacs-config-for-lobby-admin/m-p/4106129#M561303</guid>
      <dc:creator>Jan81</dc:creator>
      <dc:date>2020-06-19T05:44:10Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.6 and Cat9800 tacacs+ config for Lobby Admin</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-6-and-cat9800-tacacs-config-for-lobby-admin/m-p/4106143#M561304</link>
      <description>&lt;P&gt;Set the TACACS to return the following:&lt;/P&gt;
&lt;P&gt;Default Privilege: priv-lvl=15&lt;/P&gt;
&lt;P&gt;Custom attributes: Type= &lt;STRONG&gt;Mandatory&lt;/STRONG&gt;, Name=&lt;STRONG&gt;user-type&lt;/STRONG&gt;, Value= &lt;STRONG&gt;lobby-admin&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On WLC, configure the username:&lt;/P&gt;
&lt;P&gt;aaa remote username &amp;lt;remote-lobby-admin-username&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jun 2020 06:15:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-6-and-cat9800-tacacs-config-for-lobby-admin/m-p/4106143#M561304</guid>
      <dc:creator>poongarg</dc:creator>
      <dc:date>2020-06-19T06:15:12Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.6 and Cat9800 tacacs+ config for Lobby Admin</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-6-and-cat9800-tacacs-config-for-lobby-admin/m-p/4106183#M561311</link>
      <description>&lt;P&gt;Thanks, that works, but I point the authorization policy in the ise config to an active directory group. Must I configure for each user in the group the "aaa remote username"?&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jun 2020 08:09:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-6-and-cat9800-tacacs-config-for-lobby-admin/m-p/4106183#M561311</guid>
      <dc:creator>Jan81</dc:creator>
      <dc:date>2020-06-19T08:09:21Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.6 and Cat9800 tacacs+ config for Lobby Admin</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-6-and-cat9800-tacacs-config-for-lobby-admin/m-p/4106196#M561313</link>
      <description>The username created on AD or ISE local DB for the Lobby Ambassador has to be defined as a remote username on the WLC. If the remote username is not defined in the WLC, the authentication will go through correctly, however, the user will be granted with full access to the WLC instead of only access to the Lobby Ambassador privileges.</description>
      <pubDate>Fri, 19 Jun 2020 08:36:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-6-and-cat9800-tacacs-config-for-lobby-admin/m-p/4106196#M561313</guid>
      <dc:creator>poongarg</dc:creator>
      <dc:date>2020-06-19T08:36:16Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.6 and Cat9800 tacacs+ config for Lobby Admin</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-6-and-cat9800-tacacs-config-for-lobby-admin/m-p/4106200#M561314</link>
      <description>&lt;P&gt;Okay, thanks for your help! Greetings Jan&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jun 2020 08:39:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-6-and-cat9800-tacacs-config-for-lobby-admin/m-p/4106200#M561314</guid>
      <dc:creator>Jan81</dc:creator>
      <dc:date>2020-06-19T08:39:30Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.6 and Cat9800 tacacs+ config for Lobby Admin</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-6-and-cat9800-tacacs-config-for-lobby-admin/m-p/5350434#M599107</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;This solution works well, thank you.&lt;/P&gt;
&lt;P&gt;However, I have observed that users are getting full CLI access to the WLC, whereas the GUI access functions as expected. Do you have any suggestions on how to restrict or manage CLI access with LobbyAdmin User?&lt;/P&gt;</description>
      <pubDate>Thu, 27 Nov 2025 11:08:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-6-and-cat9800-tacacs-config-for-lobby-admin/m-p/5350434#M599107</guid>
      <dc:creator>Nieo</dc:creator>
      <dc:date>2025-11-27T11:08:10Z</dc:date>
    </item>
  </channel>
</rss>

