<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ise and switch authentication and privilege level in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-and-switch-authentication-and-privilege-level/m-p/4444798#M568875</link>
    <description>&lt;P&gt;Hello, thank you for your response. What if you need to provide privilege level 7 with full running configuration view -&amp;gt; like this&lt;BR /&gt;privilege exec level 7 show running-config view full&lt;BR /&gt;Is there any option how could I set the atributes in ISE to do this?&lt;/P&gt;</description>
    <pubDate>Thu, 05 Aug 2021 12:47:33 GMT</pubDate>
    <dc:creator>mexx03</dc:creator>
    <dc:date>2021-08-05T12:47:33Z</dc:date>
    <item>
      <title>ise and switch authentication and privilege level</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-and-switch-authentication-and-privilege-level/m-p/1818727#M203962</link>
      <description>&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;I'm working on an eval on vmware. I have got everything working for wlan authentication and I’m working on shell authentication for switches. On the ACS you have the possibility to give the user privilege level on the switch. You can do this with shell profiles in ACS. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;Is there a way to get this done in ISE? I was thinking to make a result policy elements but I can't find a shell profile or privilege attributes like in ACS. &lt;/P&gt;&lt;P&gt;For the record, switch authentication is working with Active Directory. I only need to know how to give the right return attribute.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;I appreciate any help!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;Sander&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 01:48:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-and-switch-authentication-and-privilege-level/m-p/1818727#M203962</guid>
      <dc:creator>S M85</dc:creator>
      <dc:date>2019-03-11T01:48:10Z</dc:date>
    </item>
    <item>
      <title>ise and switch authentication and privilege level</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-and-switch-authentication-and-privilege-level/m-p/1818728#M203963</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ISE (as of now) doesnt support TACACS+ ; hence you will not be able to do shell profiles/priv. commands. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Sep 2012 03:25:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-and-switch-authentication-and-privilege-level/m-p/1818728#M203963</guid>
      <dc:creator>tsmarcyes</dc:creator>
      <dc:date>2012-09-28T03:25:13Z</dc:date>
    </item>
    <item>
      <title>Re: ise and switch authentication and privilege level</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-and-switch-authentication-and-privilege-level/m-p/1818729#M203964</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;@Sander, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You were in the right area.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Policy-&amp;gt;Results-&amp;gt;Authorization-&amp;gt;Authorization Profiles.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Create AuthZ profile for Access-Accept and Under the Advanced Attributes Settings you can use:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;Cisco:cisco-av-pair = shell:priv-lvl=15&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;or whatever privilege level you want to assign.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On your AuthZ rule, match the conditions and apply the created profile.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Oct 2012 19:40:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-and-switch-authentication-and-privilege-level/m-p/1818729#M203964</guid>
      <dc:creator>john.steiner</dc:creator>
      <dc:date>2012-10-12T19:40:56Z</dc:date>
    </item>
    <item>
      <title>I've tested this recently</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-and-switch-authentication-and-privilege-level/m-p/1818730#M203965</link>
      <description>&lt;P&gt;I've tested this recently:&lt;/P&gt;&lt;H2&gt;&lt;A href="http://ltlnetworker.wordpress.com/2014/08/31/using-cisco-ise-as-a-generic-radius-server/" rel="bookmark"&gt;Using Cisco ISE as a generic RADIUS&amp;nbsp;server&lt;/A&gt;&lt;/H2&gt;</description>
      <pubDate>Sun, 31 Aug 2014 11:48:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-and-switch-authentication-and-privilege-level/m-p/1818730#M203965</guid>
      <dc:creator>Peter Koltl</dc:creator>
      <dc:date>2014-08-31T11:48:41Z</dc:date>
    </item>
    <item>
      <title>Re: ise and switch authentication and privilege level</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-and-switch-authentication-and-privilege-level/m-p/4444798#M568875</link>
      <description>&lt;P&gt;Hello, thank you for your response. What if you need to provide privilege level 7 with full running configuration view -&amp;gt; like this&lt;BR /&gt;privilege exec level 7 show running-config view full&lt;BR /&gt;Is there any option how could I set the atributes in ISE to do this?&lt;/P&gt;</description>
      <pubDate>Thu, 05 Aug 2021 12:47:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-and-switch-authentication-and-privilege-level/m-p/4444798#M568875</guid>
      <dc:creator>mexx03</dc:creator>
      <dc:date>2021-08-05T12:47:33Z</dc:date>
    </item>
    <item>
      <title>Re: ise and switch authentication and privilege level</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-and-switch-authentication-and-privilege-level/m-p/4444800#M568876</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hello, thank you for your response. What if you need to provide privilege level 7 with full running configuration view -&amp;gt; like this&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;privilege exec level 7 show running-config view full&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Is there any option how could I set the atributes in ISE to do this?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Aug 2021 12:48:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-and-switch-authentication-and-privilege-level/m-p/4444800#M568876</guid>
      <dc:creator>mexx03</dc:creator>
      <dc:date>2021-08-05T12:48:12Z</dc:date>
    </item>
    <item>
      <title>Re: ise and switch authentication and privilege level</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-and-switch-authentication-and-privilege-level/m-p/4444843#M568878</link>
      <description>&lt;P&gt;You really should use TACACS+ for this...&lt;/P&gt;</description>
      <pubDate>Thu, 05 Aug 2021 13:38:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-and-switch-authentication-and-privilege-level/m-p/4444843#M568878</guid>
      <dc:creator>rschlayer</dc:creator>
      <dc:date>2021-08-05T13:38:48Z</dc:date>
    </item>
    <item>
      <title>Re: ise and switch authentication and privilege level</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-and-switch-authentication-and-privilege-level/m-p/4445274#M568884</link>
      <description>&lt;P&gt;If you're defining privilege level 7 and providing the necessary commands on the switch, you can then provide the admin with privilege level 7 by returning a Shell Profile with the Default privilege level 7.&lt;/P&gt;
&lt;P&gt;See the &lt;A href="https://community.cisco.com/t5/security-documents/cisco-ise-device-administration-prescriptive-deployment-guide/ta-p/3738365#toc-hId--919282975" target="_blank" rel="noopener"&gt;Cisco ISE Device Administration Prescriptive Deployment Guide&lt;/A&gt;&amp;nbsp; for more details.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Aug 2021 22:42:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-and-switch-authentication-and-privilege-level/m-p/4445274#M568884</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2021-08-05T22:42:04Z</dc:date>
    </item>
  </channel>
</rss>

