<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic TACACS - 9300 switch GUI in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/tacacs-9300-switch-gui/m-p/4819304#M581339</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I've added a 9300 switch on to ISE and and using the Gui which is working.&lt;/P&gt;&lt;P&gt;My question is I can see a lot of entries being logged on tacacs for authtication, seem to keep login while on the switch, is this normal?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;aaa group server tacacs+ ISE_Group&lt;BR /&gt;server name&lt;BR /&gt;server name&lt;BR /&gt;server name&lt;BR /&gt;!&lt;BR /&gt;aaa authentication fail-message ^CCCCCCC_______Failed login in via ISE. Try again.^C&lt;BR /&gt;aaa authentication login default group ISE_Group local&lt;BR /&gt;aaa authentication enable default group ISE_Group enable&lt;BR /&gt;aaa authentication login GUILogin group ISE_Group local&lt;BR /&gt;aaa authorization console&lt;BR /&gt;aaa authorization config-commands&lt;BR /&gt;aaa authorization exec default group ISE_Group local&lt;BR /&gt;aaa authorization commands 0 default group ISE_Group local&lt;BR /&gt;aaa authorization commands 1 default group ISE_Group local&lt;BR /&gt;aaa authorization commands 15 default group ISE_Group local&lt;BR /&gt;aaa accounting exec default start-stop group ISE_Group&lt;BR /&gt;aaa accounting commands 0 default start-stop group ISE_Group&lt;BR /&gt;aaa accounting commands 1 default start-stop group ISE_Group&lt;BR /&gt;aaa accounting commands 15 default start-stop group ISE_Group&lt;BR /&gt;aaa accounting connection default start-stop group ISE_Group&lt;BR /&gt;!&lt;BR /&gt;aaa session-id common&lt;/P&gt;</description>
    <pubDate>Fri, 21 Apr 2023 14:23:44 GMT</pubDate>
    <dc:creator>craiglebutt</dc:creator>
    <dc:date>2023-04-21T14:23:44Z</dc:date>
    <item>
      <title>TACACS - 9300 switch GUI</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-9300-switch-gui/m-p/4819304#M581339</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I've added a 9300 switch on to ISE and and using the Gui which is working.&lt;/P&gt;&lt;P&gt;My question is I can see a lot of entries being logged on tacacs for authtication, seem to keep login while on the switch, is this normal?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;aaa group server tacacs+ ISE_Group&lt;BR /&gt;server name&lt;BR /&gt;server name&lt;BR /&gt;server name&lt;BR /&gt;!&lt;BR /&gt;aaa authentication fail-message ^CCCCCCC_______Failed login in via ISE. Try again.^C&lt;BR /&gt;aaa authentication login default group ISE_Group local&lt;BR /&gt;aaa authentication enable default group ISE_Group enable&lt;BR /&gt;aaa authentication login GUILogin group ISE_Group local&lt;BR /&gt;aaa authorization console&lt;BR /&gt;aaa authorization config-commands&lt;BR /&gt;aaa authorization exec default group ISE_Group local&lt;BR /&gt;aaa authorization commands 0 default group ISE_Group local&lt;BR /&gt;aaa authorization commands 1 default group ISE_Group local&lt;BR /&gt;aaa authorization commands 15 default group ISE_Group local&lt;BR /&gt;aaa accounting exec default start-stop group ISE_Group&lt;BR /&gt;aaa accounting commands 0 default start-stop group ISE_Group&lt;BR /&gt;aaa accounting commands 1 default start-stop group ISE_Group&lt;BR /&gt;aaa accounting commands 15 default start-stop group ISE_Group&lt;BR /&gt;aaa accounting connection default start-stop group ISE_Group&lt;BR /&gt;!&lt;BR /&gt;aaa session-id common&lt;/P&gt;</description>
      <pubDate>Fri, 21 Apr 2023 14:23:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-9300-switch-gui/m-p/4819304#M581339</guid>
      <dc:creator>craiglebutt</dc:creator>
      <dc:date>2023-04-21T14:23:44Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS - 9300 switch GUI</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-9300-switch-gui/m-p/4819312#M581340</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/347992"&gt;@craiglebutt&lt;/a&gt; authentication or authorisation? You should see an authorisation entry in the TACACS live logs for each command being run on the switch, which is authorised on ISE.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Apr 2023 14:29:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-9300-switch-gui/m-p/4819312#M581340</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2023-04-21T14:29:10Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS - 9300 switch GUI</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-9300-switch-gui/m-p/4819327#M581342</link>
      <description>&lt;P&gt;you run HTTP in SW, this is why ? you must disable the HTTP&lt;/P&gt;</description>
      <pubDate>Fri, 21 Apr 2023 14:52:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-9300-switch-gui/m-p/4819327#M581342</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-04-21T14:52:35Z</dc:date>
    </item>
  </channel>
</rss>

