<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ACS to ISE 2.7 migration.  TACAC+ enable login issue in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-to-ise-2-7-migration-tacac-enable-login-issue/m-p/4261192#M564389</link>
    <description>&lt;P&gt;Wow!&amp;nbsp; It didn't take my questions.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Basically in ISE the user successfully login the 1st part but when the switch ask for enable password it fails.&amp;nbsp; Authc failure.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;FYI when pointing the switch to the ACS it works without issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Sat, 19 Dec 2020 15:08:18 GMT</pubDate>
    <dc:creator>KelvinT</dc:creator>
    <dc:date>2020-12-19T15:08:18Z</dc:date>
    <item>
      <title>ACS to ISE 2.7 migration.  TACAC+ enable login issue</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-to-ise-2-7-migration-tacac-enable-login-issue/m-p/4260941#M564384</link>
      <description />
      <pubDate>Fri, 18 Dec 2020 18:39:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-to-ise-2-7-migration-tacac-enable-login-issue/m-p/4260941#M564384</guid>
      <dc:creator>KelvinT</dc:creator>
      <dc:date>2020-12-18T18:39:21Z</dc:date>
    </item>
    <item>
      <title>Re: ACS to ISE 2.7 migration.  TACAC+ enable login issue</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-to-ise-2-7-migration-tacac-enable-login-issue/m-p/4261108#M564386</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;- What is the issue ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Sat, 19 Dec 2020 08:27:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-to-ise-2-7-migration-tacac-enable-login-issue/m-p/4261108#M564386</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2020-12-19T08:27:29Z</dc:date>
    </item>
    <item>
      <title>Re: ACS to ISE 2.7 migration.  TACAC+ enable login issue</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-to-ise-2-7-migration-tacac-enable-login-issue/m-p/4261192#M564389</link>
      <description>&lt;P&gt;Wow!&amp;nbsp; It didn't take my questions.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Basically in ISE the user successfully login the 1st part but when the switch ask for enable password it fails.&amp;nbsp; Authc failure.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;FYI when pointing the switch to the ACS it works without issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Sat, 19 Dec 2020 15:08:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-to-ise-2-7-migration-tacac-enable-login-issue/m-p/4261192#M564389</guid>
      <dc:creator>KelvinT</dc:creator>
      <dc:date>2020-12-19T15:08:18Z</dc:date>
    </item>
    <item>
      <title>Re: ACS to ISE 2.7 migration.  TACAC+ enable login issue</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-to-ise-2-7-migration-tacac-enable-login-issue/m-p/4261226#M564390</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; - What's in the ISE &lt;STRONG&gt;logs&lt;/STRONG&gt; when this happens ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Sat, 19 Dec 2020 17:20:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-to-ise-2-7-migration-tacac-enable-login-issue/m-p/4261226#M564390</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2020-12-19T17:20:19Z</dc:date>
    </item>
    <item>
      <title>Re: ACS to ISE 2.7 migration.  TACAC+ enable login issue</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-to-ise-2-7-migration-tacac-enable-login-issue/m-p/4261269#M564391</link>
      <description>&lt;P&gt;The initial log on shows authz successful.&amp;nbsp; the enable login attempt shows authc failure.&amp;nbsp; bad credential.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 19 Dec 2020 21:03:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-to-ise-2-7-migration-tacac-enable-login-issue/m-p/4261269#M564391</guid>
      <dc:creator>KelvinT</dc:creator>
      <dc:date>2020-12-19T21:03:04Z</dc:date>
    </item>
    <item>
      <title>Re: ACS to ISE 2.7 migration.  TACAC+ enable login issue</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-to-ise-2-7-migration-tacac-enable-login-issue/m-p/4261382#M564392</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- Verify your &lt;EM&gt;ISE policies&lt;/EM&gt; and &lt;STRONG&gt;setup&lt;/STRONG&gt; according to this document :&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/200208-Configure-ISE-2-0-IOS-TACACS-Authentic.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/200208-Configure-ISE-2-0-IOS-TACACS-Authentic.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Sun, 20 Dec 2020 08:19:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-to-ise-2-7-migration-tacac-enable-login-issue/m-p/4261382#M564392</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2020-12-20T08:19:28Z</dc:date>
    </item>
    <item>
      <title>Re: ACS to ISE 2.7 migration.  TACAC+ enable login issue</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-to-ise-2-7-migration-tacac-enable-login-issue/m-p/4261435#M564393</link>
      <description>&lt;P&gt;Yes it is with some exceptions.&lt;/P&gt;&lt;P&gt;We check the box for maximum privilege 15.&amp;nbsp; Is there a reason it isn't selected?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 20 Dec 2020 13:29:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-to-ise-2-7-migration-tacac-enable-login-issue/m-p/4261435#M564393</guid>
      <dc:creator>KelvinT</dc:creator>
      <dc:date>2020-12-20T13:29:03Z</dc:date>
    </item>
    <item>
      <title>Re: ACS to ISE 2.7 migration.  TACAC+ enable login issue</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-to-ise-2-7-migration-tacac-enable-login-issue/m-p/4261437#M564394</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; - You mean you can't check the box ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Sun, 20 Dec 2020 13:39:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-to-ise-2-7-migration-tacac-enable-login-issue/m-p/4261437#M564394</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2020-12-20T13:39:25Z</dc:date>
    </item>
    <item>
      <title>Re: ACS to ISE 2.7 migration.  TACAC+ enable login issue</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-to-ise-2-7-migration-tacac-enable-login-issue/m-p/4261439#M564395</link>
      <description>&lt;P&gt;No.&amp;nbsp; Its checked.&amp;nbsp; We are running ISE 2.7 patch2. I thought that was required for enabled mode.&lt;/P&gt;</description>
      <pubDate>Sun, 20 Dec 2020 13:43:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-to-ise-2-7-migration-tacac-enable-login-issue/m-p/4261439#M564395</guid>
      <dc:creator>KelvinT</dc:creator>
      <dc:date>2020-12-20T13:43:31Z</dc:date>
    </item>
    <item>
      <title>Re: ACS to ISE 2.7 migration.  TACAC+ enable login issue</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-to-ise-2-7-migration-tacac-enable-login-issue/m-p/4261451#M564396</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- The original document I referred to also &lt;STRONG&gt;contains&lt;/STRONG&gt; :&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;STRONG&gt;Note&lt;/STRONG&gt;&lt;SPAN&gt;: For TACACS you need to have separate license installed&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;EM&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Check this thread for further&amp;nbsp;info's on that :&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;A href="https://community.cisco.com/t5/network-access-control/tacacs-licenses-in-ise/m-p/3504911" target="_blank"&gt;https://community.cisco.com/t5/network-access-control/tacacs-licenses-in-ise/m-p/3504911&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Sun, 20 Dec 2020 14:28:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-to-ise-2-7-migration-tacac-enable-login-issue/m-p/4261451#M564396</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2020-12-20T14:28:56Z</dc:date>
    </item>
    <item>
      <title>Re: ACS to ISE 2.7 migration.  TACAC+ enable login issue</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-to-ise-2-7-migration-tacac-enable-login-issue/m-p/4261452#M564397</link>
      <description>&lt;P&gt;Yes.&amp;nbsp; Licenses are there and consumed.&lt;/P&gt;</description>
      <pubDate>Sun, 20 Dec 2020 14:32:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-to-ise-2-7-migration-tacac-enable-login-issue/m-p/4261452#M564397</guid>
      <dc:creator>KelvinT</dc:creator>
      <dc:date>2020-12-20T14:32:49Z</dc:date>
    </item>
    <item>
      <title>Re: ACS to ISE 2.7 migration.  TACAC+ enable login issue</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-to-ise-2-7-migration-tacac-enable-login-issue/m-p/4261467#M564398</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;-&amp;nbsp;&amp;nbsp;&lt;A href="https://community.cisco.com/t5/security-documents/cisco-ise-device-administration-prescriptive-deployment-guide/ta-p/3738365#toc-hId--919282975" target="_blank"&gt;https://community.cisco.com/t5/security-documents/cisco-ise-device-administration-prescriptive-deployment-guide/ta-p/3738365#toc-hId--919282975&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Follow the referenced example, to create&amp;nbsp; a user or user(s) with enable(d) privilege(s) directly. If problems persist on the logging for the failed authentication click on &lt;STRONG&gt;detail&lt;/STRONG&gt;. Check which policy rules were matched &lt;EM&gt;and or check correctness of the policy (sets)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Sun, 20 Dec 2020 15:08:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-to-ise-2-7-migration-tacac-enable-login-issue/m-p/4261467#M564398</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2020-12-20T15:08:43Z</dc:date>
    </item>
    <item>
      <title>Re: ACS to ISE 2.7 migration.  TACAC+ enable login issue</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-to-ise-2-7-migration-tacac-enable-login-issue/m-p/4262056#M564418</link>
      <description>&lt;P&gt;I found the issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;An ISE configuration that migrated over from 2 previous upgrades using the 1st old ACS to new ACS IOS then from new ACS to ISE.&amp;nbsp; The configuration was a shell:roles"network-admin" that was on the profile.&amp;nbsp; The debug showed it failing with ACS but ACS just ignored it and authc the user.&amp;nbsp; ISE doesn't ignore it.&amp;nbsp; It gives an authc failure.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After removing the av-pair from the shell profile the user authc successfully.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your help.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Dec 2020 21:44:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-to-ise-2-7-migration-tacac-enable-login-issue/m-p/4262056#M564418</guid>
      <dc:creator>KelvinT</dc:creator>
      <dc:date>2020-12-21T21:44:08Z</dc:date>
    </item>
  </channel>
</rss>

