<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE - AD &amp;amp; Internal User Access for the same device in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-ad-amp-internal-user-access-for-the-same-device/m-p/4442535#M568806</link>
    <description>&lt;P&gt;Hello,&lt;BR /&gt;&lt;BR /&gt;From my understanding you want on the same policy to authenticate and differentiate the authorization between AD Users and ISE Internal Users.(The AD User should not be the same as the ISE internal User).&lt;BR /&gt;&lt;BR /&gt;First you need to create an Identity Source Sequence &lt;STRONG&gt;(Administration Identity -&amp;gt; Identity Management -&amp;gt; Identity Source Sequences)&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="IIS.JPG" style="width: 525px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/126802iB3796531F23F8965/image-dimensions/525x529?v=v2" width="525" height="529" role="button" title="IIS.JPG" alt="IIS.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Under the &lt;STRONG&gt;Authentication&lt;/STRONG&gt; Policy choose the Identity sequence you have created :&lt;BR /&gt; &lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="IIS.JPG" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/126803i99FA8F4B499B6614/image-size/medium?v=v2&amp;amp;px=400" role="button" title="IIS.JPG" alt="IIS.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;And under &lt;STRONG&gt;Authorization&lt;/STRONG&gt; policy should be like this :&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="IIS.JPG" style="width: 965px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/126804i49CAFE5DC106E7BA/image-dimensions/965x114?v=v2" width="965" height="114" role="button" title="IIS.JPG" alt="IIS.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 01 Aug 2021 16:18:33 GMT</pubDate>
    <dc:creator>Amine ZAKARIA</dc:creator>
    <dc:date>2021-08-01T16:18:33Z</dc:date>
    <item>
      <title>ISE - AD &amp; Internal User Access for the same device</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ad-amp-internal-user-access-for-the-same-device/m-p/4442395#M568800</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;I'm having some issue that I'm&amp;nbsp; almost sure that I've succeeded with it in the past.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have a device type "x", and we want the following thing :&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. Admins user [an AD group] - will have privilege 15&lt;/P&gt;&lt;P&gt;2. Internal User "user" - will be able to run only specific command [we've created the command set "command"]&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can't find/think on a way, that in the same "Device Admin Policy Set"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What Am I doing wrong ? and how can I solve it please&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Sun, 01 Aug 2021 06:18:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ad-amp-internal-user-access-for-the-same-device/m-p/4442395#M568800</guid>
      <dc:creator>robad</dc:creator>
      <dc:date>2021-08-01T06:18:30Z</dc:date>
    </item>
    <item>
      <title>Re: ISE - AD &amp; Internal User Access for the same device</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ad-amp-internal-user-access-for-the-same-device/m-p/4442433#M568802</link>
      <description>&lt;P&gt;You need to look command set :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Work Centers &amp;gt; Device Administration &amp;gt; Policy Results &amp;gt; TACACS Command Sets&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;below document help you : (Let us know if this is not the case or am I miss understood your requirement ?)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://ciscocustomer.lookbookhq.com/iseguidedjourney/ISE-device-admin" target="_blank"&gt;https://ciscocustomer.lookbookhq.com/iseguidedjourney/ISE-device-admin&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 01 Aug 2021 10:33:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ad-amp-internal-user-access-for-the-same-device/m-p/4442433#M568802</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2021-08-01T10:33:46Z</dc:date>
    </item>
    <item>
      <title>Re: ISE - AD &amp; Internal User Access for the same device</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ad-amp-internal-user-access-for-the-same-device/m-p/4442457#M568804</link>
      <description>&lt;P&gt;Hi, and thanks for your reply.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But, It's not what I've asked for.&lt;/P&gt;&lt;P&gt;We already have a command set for the internal user.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We need that for the same device, there will be an option the users from External ID Source [AD] and Internal ISE Users will be able to login.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 01 Aug 2021 11:36:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ad-amp-internal-user-access-for-the-same-device/m-p/4442457#M568804</guid>
      <dc:creator>robad</dc:creator>
      <dc:date>2021-08-01T11:36:43Z</dc:date>
    </item>
    <item>
      <title>Re: ISE - AD &amp; Internal User Access for the same device</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ad-amp-internal-user-access-for-the-same-device/m-p/4442467#M568805</link>
      <description>&lt;P&gt;Personally, I do not believe that Device can do both, there is only Option First one, and if that fails to the second one.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Identity Source Sequence&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;that will contain&amp;nbsp; AD groups and if needed any local accounts on ISE (in the event that AD can’t be&amp;nbsp; reachable or failed, you have a local ISE account to log into your equipment).&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 01 Aug 2021 12:25:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ad-amp-internal-user-access-for-the-same-device/m-p/4442467#M568805</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2021-08-01T12:25:53Z</dc:date>
    </item>
    <item>
      <title>Re: ISE - AD &amp; Internal User Access for the same device</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ad-amp-internal-user-access-for-the-same-device/m-p/4442535#M568806</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;&lt;BR /&gt;From my understanding you want on the same policy to authenticate and differentiate the authorization between AD Users and ISE Internal Users.(The AD User should not be the same as the ISE internal User).&lt;BR /&gt;&lt;BR /&gt;First you need to create an Identity Source Sequence &lt;STRONG&gt;(Administration Identity -&amp;gt; Identity Management -&amp;gt; Identity Source Sequences)&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="IIS.JPG" style="width: 525px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/126802iB3796531F23F8965/image-dimensions/525x529?v=v2" width="525" height="529" role="button" title="IIS.JPG" alt="IIS.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Under the &lt;STRONG&gt;Authentication&lt;/STRONG&gt; Policy choose the Identity sequence you have created :&lt;BR /&gt; &lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="IIS.JPG" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/126803i99FA8F4B499B6614/image-size/medium?v=v2&amp;amp;px=400" role="button" title="IIS.JPG" alt="IIS.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;And under &lt;STRONG&gt;Authorization&lt;/STRONG&gt; policy should be like this :&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="IIS.JPG" style="width: 965px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/126804i49CAFE5DC106E7BA/image-dimensions/965x114?v=v2" width="965" height="114" role="button" title="IIS.JPG" alt="IIS.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 01 Aug 2021 16:18:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ad-amp-internal-user-access-for-the-same-device/m-p/4442535#M568806</guid>
      <dc:creator>Amine ZAKARIA</dc:creator>
      <dc:date>2021-08-01T16:18:33Z</dc:date>
    </item>
    <item>
      <title>Re: ISE - AD &amp; Internal User Access for the same device</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ad-amp-internal-user-access-for-the-same-device/m-p/4442675#M568808</link>
      <description>&lt;P&gt;Hi Amine&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks ! It's getting closer for solution.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Now I'm able to login with both AD user &amp;amp; Internal User&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But, for some reason, the Command Sets are not taking any effect. i.e, the users can login but they have priv 15, and not only the "clear line" command set...&lt;/P&gt;&lt;P&gt;Do you have any Idea why ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;BTW -&amp;nbsp;&lt;/P&gt;&lt;P&gt;In other Policy Sets it's working. the "users" can login and get only "clear line" command set, and admins getting all command.&lt;/P&gt;&lt;P&gt;The only change is that in the other Policy Sets, the "users" are from the same Identity Source as the admins&amp;nbsp; [AD].&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Attached the Policy Set + The TACACS Log&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="policy set.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/126824i0D7819E063B3FE90/image-size/large?v=v2&amp;amp;px=999" role="button" title="policy set.PNG" alt="policy set.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="tacacas log.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/126823iDFDBF507888128A8/image-size/large?v=v2&amp;amp;px=999" role="button" title="tacacas log.PNG" alt="tacacas log.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Aug 2021 07:03:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ad-amp-internal-user-access-for-the-same-device/m-p/4442675#M568808</guid>
      <dc:creator>robad</dc:creator>
      <dc:date>2021-08-02T07:03:12Z</dc:date>
    </item>
    <item>
      <title>Re: ISE - AD &amp; Internal User Access for the same device</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ad-amp-internal-user-access-for-the-same-device/m-p/4442694#M568809</link>
      <description>&lt;P&gt;*********&lt;/P&gt;&lt;P&gt;Update&lt;/P&gt;&lt;P&gt;*********&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;IT IS WORKING !&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've noticed that something is wrong only with a specific Terminal Server.&lt;/P&gt;&lt;P&gt;There was one command that was missing :&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;aaa authorization commands 15 default local group tacacs+&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and that's it now it's working !&lt;/P&gt;&lt;P&gt;thanks&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Aug 2021 07:37:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ad-amp-internal-user-access-for-the-same-device/m-p/4442694#M568809</guid>
      <dc:creator>robad</dc:creator>
      <dc:date>2021-08-02T07:37:59Z</dc:date>
    </item>
    <item>
      <title>Re: ISE - AD &amp; Internal User Access for the same device</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ad-amp-internal-user-access-for-the-same-device/m-p/4442773#M568812</link>
      <description>&lt;PRE&gt;aaa authorization commands 15 default local group tacacs+&lt;/PRE&gt;
&lt;P&gt;Sure this make sense - this&amp;nbsp; will do first Local and TACACS&amp;nbsp; later.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Aug 2021 09:43:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ad-amp-internal-user-access-for-the-same-device/m-p/4442773#M568812</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2021-08-02T09:43:16Z</dc:date>
    </item>
  </channel>
</rss>

