<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Query on IPS Authentication with CISCO ISE in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/query-on-ips-authentication-with-cisco-ise/m-p/4443100#M568821</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;1.Is it possible to have RADIUS authentication enabled for the IPS device which comes within the subnet and which is already onboarded in ISE for TACACS authentication. Yes it's possible&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;2.If yes do I need to onboard the IPS devices separately? Again yes you should create a network device for these 2 ips as &lt;STRONG&gt;&lt;FONT color="#FF0000"&gt;/32&lt;/FONT&gt;&lt;/STRONG&gt; for radius with the preshared key.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="IIS.JPG" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/126862i4ED955FFA95D6B81/image-size/medium?v=v2&amp;amp;px=400" role="button" title="IIS.JPG" alt="IIS.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;3.If I onboard the IPS separately will ISE allow me to Onboard the devices? since it is already a part of the subnet and will it consider to be a duplicate one? &lt;STRONG&gt;In your case&lt;/STRONG&gt; ISE will not complain about the duplication creation as long as the NAD will be declared as /32.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that helps!&lt;/P&gt;</description>
    <pubDate>Mon, 02 Aug 2021 21:45:56 GMT</pubDate>
    <dc:creator>Amine ZAKARIA</dc:creator>
    <dc:date>2021-08-02T21:45:56Z</dc:date>
    <item>
      <title>Query on IPS Authentication with CISCO ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/query-on-ips-authentication-with-cisco-ise/m-p/4443060#M568818</link>
      <description>&lt;P&gt;Hello ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have an entire subnet onboarded for TACACS authentication and within that subnet we have IPS devices which requires a RADIUS authentication.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Version and patch : V 2.4.0.357 Patch 13&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Query :&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Is it possible to have RADIUS authentication enabled for the IPS device which comes within the subnet and which is already onboarded in ISE for TACACS authentication.&lt;/LI&gt;&lt;LI&gt;If yes do I need to onboard the IPS devices separately?&lt;/LI&gt;&lt;LI&gt;If I onboard the IPS separately will ISE allow me to Onboard the devices? since it is already a part of the subnet and will it consider to be a duplicate one?&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Example :&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Subnet onboarded for ISE TACACS is 10.2.2.0/24 , IPS IP's are&amp;nbsp;10.2.2.2 and&amp;nbsp;&lt;SPAN&gt;10.2.2.3.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Now I need to onboard the IPS devices10.2.2.2 and&amp;nbsp;10.2.2.3 (RADIUS Authentication) but&amp;nbsp;10.2.2.0/24 is already in ISE for TACACS authentication.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Kindly help me with this scenario.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Aug 2021 20:22:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/query-on-ips-authentication-with-cisco-ise/m-p/4443060#M568818</guid>
      <dc:creator>kirubashankarr</dc:creator>
      <dc:date>2021-08-02T20:22:26Z</dc:date>
    </item>
    <item>
      <title>Re: Query on IPS Authentication with CISCO ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/query-on-ips-authentication-with-cisco-ise/m-p/4443100#M568821</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;1.Is it possible to have RADIUS authentication enabled for the IPS device which comes within the subnet and which is already onboarded in ISE for TACACS authentication. Yes it's possible&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;2.If yes do I need to onboard the IPS devices separately? Again yes you should create a network device for these 2 ips as &lt;STRONG&gt;&lt;FONT color="#FF0000"&gt;/32&lt;/FONT&gt;&lt;/STRONG&gt; for radius with the preshared key.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="IIS.JPG" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/126862i4ED955FFA95D6B81/image-size/medium?v=v2&amp;amp;px=400" role="button" title="IIS.JPG" alt="IIS.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;3.If I onboard the IPS separately will ISE allow me to Onboard the devices? since it is already a part of the subnet and will it consider to be a duplicate one? &lt;STRONG&gt;In your case&lt;/STRONG&gt; ISE will not complain about the duplication creation as long as the NAD will be declared as /32.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that helps!&lt;/P&gt;</description>
      <pubDate>Mon, 02 Aug 2021 21:45:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/query-on-ips-authentication-with-cisco-ise/m-p/4443100#M568821</guid>
      <dc:creator>Amine ZAKARIA</dc:creator>
      <dc:date>2021-08-02T21:45:56Z</dc:date>
    </item>
    <item>
      <title>Re: Query on IPS Authentication with CISCO ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/query-on-ips-authentication-with-cisco-ise/m-p/4444399#M568855</link>
      <description>&lt;P&gt;RADIUS and TACACS are separate protocols supported by ISE.&lt;/P&gt;
&lt;P&gt;You may individually enable each protocol per device or device subnet under Administration &amp;gt; Network Resources &amp;gt; Network Devices:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/127071iAEAA5A2845654A72/image-size/medium?v=v2&amp;amp;px=400" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;To "onboard" the devices for RADIUS you would simply check the box in your device subnet configuration in ISE as shown above and provide the RADIUS shared secret similar to what you did with TACACS.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Aug 2021 18:27:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/query-on-ips-authentication-with-cisco-ise/m-p/4444399#M568855</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2021-08-04T18:27:11Z</dc:date>
    </item>
  </channel>
</rss>

