<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE Ver 2.7 authentication Error in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-ver-2-7-authentication-error/m-p/4116777#M561631</link>
    <description>&lt;P&gt;How does policy on ISE looks like?&lt;/P&gt;</description>
    <pubDate>Fri, 10 Jul 2020 18:43:34 GMT</pubDate>
    <dc:creator>marius.jakevicius</dc:creator>
    <dc:date>2020-07-10T18:43:34Z</dc:date>
    <item>
      <title>ISE Ver 2.7 authentication Error</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ver-2-7-authentication-error/m-p/4116751#M561630</link>
      <description>&lt;P&gt;I istalled an ISE server recently ,configured by Cisco Switch for tacacs authentication,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I constantly get failed login attempts while trying to login.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Attached herewith is the error log. Below is my switch Configuration:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;aaa group server tacacs+ ISE-DMO&lt;BR /&gt;server 16.128.15.75&lt;BR /&gt;server-private 16.128.15.75 key&amp;nbsp; man&amp;amp;woman&lt;BR /&gt;!&lt;BR /&gt;aaa authentication login default group tacacs+ local&lt;BR /&gt;aaa authentication enable default group tacacs+ enable&lt;BR /&gt;aaa authentication dot1x default group packetfence&lt;BR /&gt;aaa authorization exec default group tacacs+ local&lt;BR /&gt;aaa authorization network default group packetfence&lt;BR /&gt;aaa accounting commands 1 default start-stop group tacacs+&lt;BR /&gt;aaa accounting commands 7 default start-stop group tacacs+&lt;BR /&gt;aaa accounting commands 15 default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;tacacs-server host 16.128.15.75&lt;BR /&gt;tacacs-server directed-request&lt;BR /&gt;radius-server host 10.128.10.150 auth-port 1812 acct-port 1813 timeout 2 key&amp;nbsp;man&amp;amp;men&lt;BR /&gt;radius-server vsa send authentication&lt;BR /&gt;!&lt;BR /&gt;control-plane&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;line con 0&lt;BR /&gt;line vty 0 4&lt;BR /&gt;password done2020&lt;BR /&gt;line vty 5 15&lt;BR /&gt;password done2020&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jul 2020 17:50:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ver-2-7-authentication-error/m-p/4116751#M561630</guid>
      <dc:creator>okoroji80</dc:creator>
      <dc:date>2020-07-10T17:50:47Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Ver 2.7 authentication Error</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ver-2-7-authentication-error/m-p/4116777#M561631</link>
      <description>&lt;P&gt;How does policy on ISE looks like?&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jul 2020 18:43:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ver-2-7-authentication-error/m-p/4116777#M561631</guid>
      <dc:creator>marius.jakevicius</dc:creator>
      <dc:date>2020-07-10T18:43:34Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Ver 2.7 authentication Error</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ver-2-7-authentication-error/m-p/4116824#M561633</link>
      <description>&lt;P&gt;Hello Marius.,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Attached is my policy set on the ISE.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thank you&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jul 2020 21:02:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ver-2-7-authentication-error/m-p/4116824#M561633</guid>
      <dc:creator>okoroji80</dc:creator>
      <dc:date>2020-07-10T21:02:17Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Ver 2.7 authentication Error</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ver-2-7-authentication-error/m-p/4117043#M561641</link>
      <description>&lt;P&gt;Both of your two non-default authorization rules have conditions on user identity groups. ISE appears not finding the user in either groups so it applies the default; hence, Deny All Shell Profile.&lt;/P&gt;</description>
      <pubDate>Sat, 11 Jul 2020 18:29:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ver-2-7-authentication-error/m-p/4117043#M561641</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2020-07-11T18:29:30Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Ver 2.7 authentication Error</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ver-2-7-authentication-error/m-p/4117098#M561645</link>
      <description>&lt;P&gt;Kindly advice on the steps to have this resolved&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Sat, 11 Jul 2020 21:47:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ver-2-7-authentication-error/m-p/4117098#M561645</guid>
      <dc:creator>okoroji80</dc:creator>
      <dc:date>2020-07-11T21:47:33Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Ver 2.7 authentication Error</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ver-2-7-authentication-error/m-p/4117103#M561647</link>
      <description>&lt;P&gt;&lt;SPAN class=""&gt;&lt;A id="link_35" class="lia-link-navigation lia-page-link lia-user-name-link" href="https://community.cisco.com/t5/user/viewprofilepage/user-id/284822" target="_self"&gt;okoroji80,&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class=""&gt;Please verify whether the user in one of the user groups.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class=""&gt;Or, you may change the shell profile and the command set for the default rule and give some limited access.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 11 Jul 2020 23:01:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ver-2-7-authentication-error/m-p/4117103#M561647</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2020-07-11T23:01:38Z</dc:date>
    </item>
  </channel>
</rss>

