<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Unable to see enforce command sets using cisco ISE device admin demo in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/unable-to-see-enforce-command-sets-using-cisco-ise-device-admin/m-p/4902001#M583356</link>
    <description>&lt;P&gt;I am doing evaluation for the cisco ISE device admin demo license, but users are able to authenticate properly and hit proper authorization policy but i can't enforce restrictions using command sets in the authorization policy&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;*************my switch config&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Security.png" style="width: 615px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/193798iF64E5E4D5198F4FB/image-size/large?v=v2&amp;amp;px=999" role="button" title="Security.png" alt="Security.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;BR /&gt;aaa group server tacacs+ eh_group&lt;BR /&gt;server name EH&lt;BR /&gt;ip tacacs source-interface Vlan1&lt;BR /&gt;aaa authentication login ehgroup group eh_group local&lt;BR /&gt;aaa authentication enable default group eh_group enable&lt;BR /&gt;aaa authorization config-commands&lt;BR /&gt;aaa authorization exec ehgroup group eh_group local if-authenticated&lt;BR /&gt;aaa authorization commands 0 ehgroup group eh_group local if-authenticated&lt;BR /&gt;aaa authorization commands 1 ehgroup group eh_group local if-authenticated&lt;BR /&gt;aaa authorization commands 7 ehgroup group eh_group local if-authenticated&lt;BR /&gt;aaa authorization commands 15 ehgroup group eh_group local if-authenticated&lt;BR /&gt;aaa accounting exec ehgroup start-stop group tacacs+ group eh_group&lt;BR /&gt;aaa accounting commands 0 ehgroup start-stop group eh_group&lt;BR /&gt;aaa accounting commands 1 ehgroup start-stop group eh_group&lt;BR /&gt;aaa accounting commands 15 ehgroup start-stop group eh_group&lt;/P&gt;&lt;P&gt;line vty 0 4&lt;BR /&gt;exec-timeout 300 0&lt;BR /&gt;authorization commands 0 ehgroup&lt;BR /&gt;authorization commands 1 ehgroup&lt;BR /&gt;authorization commands 15 ehgroup&lt;BR /&gt;authorization exec ehgroup&lt;BR /&gt;accounting commands 0 ehgroup&lt;BR /&gt;accounting commands 15 ehgroup&lt;BR /&gt;login authentication ehgroup&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 09 Aug 2023 04:25:27 GMT</pubDate>
    <dc:creator>henry chrizostom</dc:creator>
    <dc:date>2023-08-09T04:25:27Z</dc:date>
    <item>
      <title>Unable to see enforce command sets using cisco ISE device admin demo</title>
      <link>https://community.cisco.com/t5/network-access-control/unable-to-see-enforce-command-sets-using-cisco-ise-device-admin/m-p/4902001#M583356</link>
      <description>&lt;P&gt;I am doing evaluation for the cisco ISE device admin demo license, but users are able to authenticate properly and hit proper authorization policy but i can't enforce restrictions using command sets in the authorization policy&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;*************my switch config&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Security.png" style="width: 615px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/193798iF64E5E4D5198F4FB/image-size/large?v=v2&amp;amp;px=999" role="button" title="Security.png" alt="Security.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;BR /&gt;aaa group server tacacs+ eh_group&lt;BR /&gt;server name EH&lt;BR /&gt;ip tacacs source-interface Vlan1&lt;BR /&gt;aaa authentication login ehgroup group eh_group local&lt;BR /&gt;aaa authentication enable default group eh_group enable&lt;BR /&gt;aaa authorization config-commands&lt;BR /&gt;aaa authorization exec ehgroup group eh_group local if-authenticated&lt;BR /&gt;aaa authorization commands 0 ehgroup group eh_group local if-authenticated&lt;BR /&gt;aaa authorization commands 1 ehgroup group eh_group local if-authenticated&lt;BR /&gt;aaa authorization commands 7 ehgroup group eh_group local if-authenticated&lt;BR /&gt;aaa authorization commands 15 ehgroup group eh_group local if-authenticated&lt;BR /&gt;aaa accounting exec ehgroup start-stop group tacacs+ group eh_group&lt;BR /&gt;aaa accounting commands 0 ehgroup start-stop group eh_group&lt;BR /&gt;aaa accounting commands 1 ehgroup start-stop group eh_group&lt;BR /&gt;aaa accounting commands 15 ehgroup start-stop group eh_group&lt;/P&gt;&lt;P&gt;line vty 0 4&lt;BR /&gt;exec-timeout 300 0&lt;BR /&gt;authorization commands 0 ehgroup&lt;BR /&gt;authorization commands 1 ehgroup&lt;BR /&gt;authorization commands 15 ehgroup&lt;BR /&gt;authorization exec ehgroup&lt;BR /&gt;accounting commands 0 ehgroup&lt;BR /&gt;accounting commands 15 ehgroup&lt;BR /&gt;login authentication ehgroup&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Aug 2023 04:25:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/unable-to-see-enforce-command-sets-using-cisco-ise-device-admin/m-p/4902001#M583356</guid>
      <dc:creator>henry chrizostom</dc:creator>
      <dc:date>2023-08-09T04:25:27Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to see enforce command sets using cisco ISE device admin de</title>
      <link>https://community.cisco.com/t5/network-access-control/unable-to-see-enforce-command-sets-using-cisco-ise-device-admin/m-p/4902204#M583362</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1569284"&gt;@henry chrizostom&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Your configuration looks fine to me. However, report you are checking is about authentication. Please try and check TACACS Authorization report, where you would see which shell profile and command set were assigned to specific session. Based on that, it should be clear to you what is going on.&lt;/P&gt;
&lt;P&gt;Kind regards,&lt;/P&gt;
&lt;P&gt;Milos&lt;/P&gt;</description>
      <pubDate>Wed, 09 Aug 2023 11:36:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/unable-to-see-enforce-command-sets-using-cisco-ise-device-admin/m-p/4902204#M583362</guid>
      <dc:creator>Milos_Jovanovic</dc:creator>
      <dc:date>2023-08-09T11:36:41Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to see enforce command sets using cisco ISE device admin de</title>
      <link>https://community.cisco.com/t5/network-access-control/unable-to-see-enforce-command-sets-using-cisco-ise-device-admin/m-p/4902521#M583364</link>
      <description>&lt;P&gt;Thank you for your response. I am unable to locate any authorization logs in the Cisco ISE portal, which is unusual. I don't understand why I can't see authorization logs even though I've verified all the configurations are correct.&lt;/P&gt;&lt;P&gt;could it be the reason that I am using the Cisco ISE device admin demo license?&lt;/P&gt;</description>
      <pubDate>Wed, 09 Aug 2023 19:02:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/unable-to-see-enforce-command-sets-using-cisco-ise-device-admin/m-p/4902521#M583364</guid>
      <dc:creator>jovinco25</dc:creator>
      <dc:date>2023-08-09T19:02:44Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to see enforce command sets using cisco ISE device admin de</title>
      <link>https://community.cisco.com/t5/network-access-control/unable-to-see-enforce-command-sets-using-cisco-ise-device-admin/m-p/4902527#M583365</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/861005"&gt;@jovinco25&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;No, I don't think it has anythng to do with demo mode, as it is intended to provide every functionality, for a limited number of users and time.&lt;/P&gt;
&lt;P&gt;Are you sure you are logging under lines 0-4? Could it be all of those are taken, and you are testing under 5-15?&lt;/P&gt;
&lt;P&gt;Kind regards,&lt;/P&gt;
&lt;P&gt;Milos&lt;/P&gt;</description>
      <pubDate>Wed, 09 Aug 2023 19:48:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/unable-to-see-enforce-command-sets-using-cisco-ise-device-admin/m-p/4902527#M583365</guid>
      <dc:creator>Milos_Jovanovic</dc:creator>
      <dc:date>2023-08-09T19:48:17Z</dc:date>
    </item>
  </channel>
</rss>

