<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE tacacs+ command set for all interface-specific subcommands in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-tacacs-command-set-for-all-interface-specific-subcommands/m-p/4145402#M562660</link>
    <description>&lt;P&gt;Thank you, it appears that you were correct - all commands within a command group that you want some control over need to be individually defined.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 02 Sep 2020 21:45:39 GMT</pubDate>
    <dc:creator>Azlord_Cisco</dc:creator>
    <dc:date>2020-09-02T21:45:39Z</dc:date>
    <item>
      <title>ISE tacacs+ command set for all interface-specific subcommands</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-tacacs-command-set-for-all-interface-specific-subcommands/m-p/4141685#M562522</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I'd really like to know what the ISE tacacs+ command set is for all interface-specific subcommands.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;" Permit interface* " gets me into the interface configuration mode, but nothing within that mode. Is there a one-line command set that will include all subcommands within the interface mode? (wildcard "*" in the argument box didn't work).&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 26 Aug 2020 13:57:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-tacacs-command-set-for-all-interface-specific-subcommands/m-p/4141685#M562522</guid>
      <dc:creator>Azlord_Cisco</dc:creator>
      <dc:date>2020-08-26T13:57:24Z</dc:date>
    </item>
    <item>
      <title>Re: ISE tacacs+ command set for all interface-specific subcommands</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-tacacs-command-set-for-all-interface-specific-subcommands/m-p/4141692#M562523</link>
      <description>You should be able to use ISE to validate your command expressions.  Under TACACS Command Sets I think what you are looking for is:&lt;BR /&gt;Grant = PERMIT; Command = Interface; Arguments = all;&lt;BR /&gt;Try that and test accordingly.  Lastly, see section 'TACACS+ Command Sets' here: &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/admin_guide/b_ISE_admin_guide_24/m_ise_tacacs_device_admin.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/admin_guide/b_ISE_admin_guide_24/m_ise_tacacs_device_admin.html&lt;/A&gt;</description>
      <pubDate>Wed, 26 Aug 2020 14:05:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-tacacs-command-set-for-all-interface-specific-subcommands/m-p/4141692#M562523</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2020-08-26T14:05:59Z</dc:date>
    </item>
    <item>
      <title>Re: ISE tacacs+ command set for all interface-specific subcommands</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-tacacs-command-set-for-all-interface-specific-subcommands/m-p/4141693#M562524</link>
      <description>&lt;P&gt;what kind of user rights ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Aug 2020 14:06:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-tacacs-command-set-for-all-interface-specific-subcommands/m-p/4141693#M562524</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2020-08-26T14:06:00Z</dc:date>
    </item>
    <item>
      <title>Re: ISE tacacs+ command set for all interface-specific subcommands</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-tacacs-command-set-for-all-interface-specific-subcommands/m-p/4141695#M562525</link>
      <description>&lt;P&gt;Every command is treated on its own merits regardless of where you are in the configuration.&amp;nbsp; ISE has no awarness of the fact that you are at the interface section.&amp;nbsp; If you allow the user to go to the interface section then you need to allow the user to issue commands:&lt;/P&gt;
&lt;P&gt;shutdown&lt;/P&gt;
&lt;P&gt;switchport access vlan&lt;/P&gt;
&lt;P&gt;no shutdown&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;etc.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Aug 2020 14:09:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-tacacs-command-set-for-all-interface-specific-subcommands/m-p/4141695#M562525</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2020-08-26T14:09:51Z</dc:date>
    </item>
    <item>
      <title>Re: ISE tacacs+ command set for all interface-specific subcommands</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-tacacs-command-set-for-all-interface-specific-subcommands/m-p/4145402#M562660</link>
      <description>&lt;P&gt;Thank you, it appears that you were correct - all commands within a command group that you want some control over need to be individually defined.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Sep 2020 21:45:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-tacacs-command-set-for-all-interface-specific-subcommands/m-p/4145402#M562660</guid>
      <dc:creator>Azlord_Cisco</dc:creator>
      <dc:date>2020-09-02T21:45:39Z</dc:date>
    </item>
  </channel>
</rss>

