<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: TACACS in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/tacacs/m-p/4621982#M575124</link>
    <description>&lt;P&gt;i use ISE 3.1&lt;/P&gt;</description>
    <pubDate>Wed, 01 Jun 2022 04:53:27 GMT</pubDate>
    <dc:creator>naqibsafi</dc:creator>
    <dc:date>2022-06-01T04:53:27Z</dc:date>
    <item>
      <title>TACACS</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs/m-p/4621159#M575099</link>
      <description>&lt;P&gt;hi everyone&amp;nbsp;&lt;/P&gt;&lt;P&gt;i configure AAA all command deny and permit working will but the specific interface not be deny&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 31 May 2022 10:10:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs/m-p/4621159#M575099</guid>
      <dc:creator>naqibsafi</dc:creator>
      <dc:date>2022-05-31T10:10:03Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs/m-p/4621169#M575102</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; - On which platform(/model) are you trying this ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Tue, 31 May 2022 10:30:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs/m-p/4621169#M575102</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2022-05-31T10:30:06Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs/m-p/4621170#M575103</link>
      <description>&lt;P&gt;That should work, what ISE version, waht Device is this :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;check other example as below :&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;How do you create TACACS+ policies that can be applied to the Network device?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://ciscocustomer.lookbookhq.com/iseguidedjourney/ISE-device-admin-policy-sets" target="_blank"&gt;https://ciscocustomer.lookbookhq.com/iseguidedjourney/ISE-device-admin-policy-sets&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 31 May 2022 10:32:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs/m-p/4621170#M575103</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2022-05-31T10:32:40Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs/m-p/4621982#M575124</link>
      <description>&lt;P&gt;i use ISE 3.1&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jun 2022 04:53:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs/m-p/4621982#M575124</guid>
      <dc:creator>naqibsafi</dc:creator>
      <dc:date>2022-06-01T04:53:27Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs/m-p/4621983#M575125</link>
      <description>&lt;P&gt;i use ISE version 3.1&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jun 2022 04:53:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs/m-p/4621983#M575125</guid>
      <dc:creator>naqibsafi</dc:creator>
      <dc:date>2022-06-01T04:53:57Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs/m-p/4622945#M575151</link>
      <description>&lt;P&gt;The argument for the interface should replace / with a space character and G should be in capital, like this:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;GigabitEthernet 1 0 1&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jun 2022 03:13:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs/m-p/4622945#M575151</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2022-06-02T03:13:09Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs/m-p/4622991#M575155</link>
      <description>&lt;P&gt;I try that command also but not work&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jun 2022 05:58:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs/m-p/4622991#M575155</guid>
      <dc:creator>naqibsafi</dc:creator>
      <dc:date>2022-06-02T05:58:07Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs/m-p/4623438#M575170</link>
      <description>&lt;P&gt;Check the T+ livelog or reports and see how the command is coming in as. You may also try capturing the packets and then &lt;A href="https://support.f5.com/csp/article/K40341514" target="_self"&gt;AskF5: K40341514: How to decrypt the encrypted portion of TACACS+ traffic&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jun 2022 16:21:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs/m-p/4623438#M575170</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2022-06-02T16:21:26Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs/m-p/4624462#M575195</link>
      <description>&lt;P&gt;&lt;SPAN&gt;T+ live log&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 04 Jun 2022 07:06:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs/m-p/4624462#M575195</guid>
      <dc:creator>naqibsafi</dc:creator>
      <dc:date>2022-06-04T07:06:29Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs/m-p/4625321#M575216</link>
      <description>&lt;P&gt;&lt;SPAN class=""&gt;Try&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;PRE&gt;GigabitEthernet 1\/0\/1&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A id="link_22" class="lia-link-navigation lia-page-link lia-user-name-link" href="https://community.cisco.com/t5/user/viewprofilepage/user-id/291804" target="_self" aria-label="View Profile of marce1000"&gt;&lt;SPAN class=""&gt;marce1000&lt;/SPAN&gt;&lt;/A&gt;&amp;nbsp;asked you earlier&lt;/P&gt;
&lt;P&gt;&amp;gt;&amp;nbsp;On which platform(/model) are you trying this ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I tried it in one of our lab pods with a Cisco Catalyst 3650 on IOS-XE 3.6.10E and ISE able to reject a command as expected.&lt;/P&gt;
&lt;P&gt;I used two command sets when the user logged-in:&lt;/P&gt;
&lt;P&gt;1) helpDeskCmds&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2022-06-05 at 15.50.47.png" style="width: 361px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/152931i0FE00BB4447E8CE3/image-dimensions/361x179?v=v2" width="361" height="179" role="button" title="Screen Shot 2022-06-05 at 15.50.47.png" alt="Screen Shot 2022-06-05 at 15.50.47.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;2) iosSecCmds&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2022-06-05 at 15.52.22.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/152932i41659792E8E75370/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screen Shot 2022-06-05 at 15.52.22.png" alt="Screen Shot 2022-06-05 at 15.52.22.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;When the user issued a command like "interface g1/0/2" and the authZ failed.&lt;/P&gt;
&lt;PRE&gt;3k-access#conf t
Enter configuration commands, one per line.  End with CNTL/Z.
3k-access(config)#interface g1/0/2
Command authorization failed.
&lt;/PRE&gt;
&lt;P&gt;The switch I tested sent the command as "interface GigabitEthernet 1 0 2"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 05 Jun 2022 22:57:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs/m-p/4625321#M575216</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2022-06-05T22:57:16Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs/m-p/4627656#M575299</link>
      <description>&lt;P&gt;i try that command in switch 3850 and 3750&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jun 2022 07:43:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs/m-p/4627656#M575299</guid>
      <dc:creator>naqibsafi</dc:creator>
      <dc:date>2022-06-08T07:43:28Z</dc:date>
    </item>
  </channel>
</rss>

