<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: TACACS Profile Questions for Third-Party Equipment Using ISE in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/tacacs-profile-questions-for-third-party-equipment-using-ise/m-p/4995267#M586295</link>
    <description>&lt;P&gt;I'm not sure I'm following your question but you should use network device groups to differentiate within the Device Admin Policy.&amp;nbsp; By matching on those NAD groups, you can ensure that Juniper attributes are only sent to Juniper NADs and Cisco attributes are only sent to Cisco devices.&lt;/P&gt;</description>
    <pubDate>Fri, 12 Jan 2024 14:48:25 GMT</pubDate>
    <dc:creator>ahollifield</dc:creator>
    <dc:date>2024-01-12T14:48:25Z</dc:date>
    <item>
      <title>TACACS Profile Questions for Third-Party Equipment Using ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-profile-questions-for-third-party-equipment-using-ise/m-p/4994704#M586280</link>
      <description>&lt;P&gt;Using ISE, we want to set up TACACS not only for CISCO equipment but also for third-party equipment.&lt;/P&gt;
&lt;P&gt;I'm trying to create a TACACS profile&lt;BR /&gt;I understand that each vendor has an attribute value to set up TACACS on the ISE.&lt;/P&gt;
&lt;P&gt;If I put various attribute values in one profile, can I set up TACACS of third-party equipment with just one profile?&lt;/P&gt;
&lt;P&gt;When I put in the juniper attribute value, I thought TACACS would be set for both the juniper and cisco equipment because the cisco equipment did not have a separate attribute value.&lt;/P&gt;
&lt;P&gt;The juniper equipment was applied, but the cisco equipment only showed the authentication success log in the live log, and the actual cli was not accessible.&lt;/P&gt;
&lt;P&gt;Please give me some advice regarding this.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jan 2024 23:48:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-profile-questions-for-third-party-equipment-using-ise/m-p/4994704#M586280</guid>
      <dc:creator>CCC3</dc:creator>
      <dc:date>2024-01-11T23:48:16Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS Profile Questions for Third-Party Equipment Using ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-profile-questions-for-third-party-equipment-using-ise/m-p/4995267#M586295</link>
      <description>&lt;P&gt;I'm not sure I'm following your question but you should use network device groups to differentiate within the Device Admin Policy.&amp;nbsp; By matching on those NAD groups, you can ensure that Juniper attributes are only sent to Juniper NADs and Cisco attributes are only sent to Cisco devices.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jan 2024 14:48:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-profile-questions-for-third-party-equipment-using-ise/m-p/4995267#M586295</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2024-01-12T14:48:25Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS Profile Questions for Third-Party Equipment Using ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-profile-questions-for-third-party-equipment-using-ise/m-p/4995270#M586296</link>
      <description>&lt;P&gt;So you want to use ISE for both juniper and cisco admin authc and authz ?&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jan 2024 14:51:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-profile-questions-for-third-party-equipment-using-ise/m-p/4995270#M586296</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-01-12T14:51:41Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS Profile Questions for Third-Party Equipment Using ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-profile-questions-for-third-party-equipment-using-ise/m-p/4996190#M586330</link>
      <description>&lt;P&gt;&amp;gt;&amp;nbsp;If I put various attribute values in one profile, can I set up TACACS of third-party equipment with just one profile?&lt;/P&gt;
&lt;P&gt;No. As different vendors expect different sets of attributes, we need separate profiles for them.&amp;nbsp;&lt;A href="https://community.cisco.com/t5/security-knowledge-base/cisco-ise-device-administration-prescriptive-deployment-guide/ta-p/3738365" target="_self"&gt;Cisco ISE Device Administration Prescriptive Deployment Guide&lt;/A&gt;&amp;nbsp;would be a good start point in understanding how TACACS+ works.&lt;/P&gt;</description>
      <pubDate>Sat, 13 Jan 2024 19:02:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-profile-questions-for-third-party-equipment-using-ise/m-p/4996190#M586330</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2024-01-13T19:02:08Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS Profile Questions for Third-Party Equipment Using ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-profile-questions-for-third-party-equipment-using-ise/m-p/4996481#M586334</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for your answer.&lt;/P&gt;
&lt;P&gt;If you set it up like the attached picture&lt;/P&gt;
&lt;P&gt;The juniper equipment has tacacs set and the cisco equipment has no attribute value, so I think the cisco equipment will be set as well&lt;/P&gt;
&lt;P&gt;Does that mean it isn't?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="20240115_083528.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/207308iA3E8722541559CEF/image-size/large?v=v2&amp;amp;px=999" role="button" title="20240115_083528.png" alt="20240115_083528.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 14 Jan 2024 23:37:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-profile-questions-for-third-party-equipment-using-ise/m-p/4996481#M586334</guid>
      <dc:creator>CCC3</dc:creator>
      <dc:date>2024-01-14T23:37:09Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS Profile Questions for Third-Party Equipment Using ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-profile-questions-for-third-party-equipment-using-ise/m-p/4997684#M586369</link>
      <description>&lt;P&gt;Where is the policy in which is this result is called?&amp;nbsp; Do both Juniper and Cisco devices hit this rule?&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jan 2024 14:49:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-profile-questions-for-third-party-equipment-using-ise/m-p/4997684#M586369</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2024-01-16T14:49:10Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS Profile Questions for Third-Party Equipment Using ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-profile-questions-for-third-party-equipment-using-ise/m-p/4997692#M586370</link>
      <description>&lt;P&gt;I think this issue of attribute'&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The cisco use specific attributes for login and this is different for other vendor.&lt;/P&gt;
&lt;P&gt;I am out home now' you can check this point and when I retrun back and make more seach and update you.&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jan 2024 15:05:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-profile-questions-for-third-party-equipment-using-ise/m-p/4997692#M586370</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-01-16T15:05:15Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS Profile Questions for Third-Party Equipment Using ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-profile-questions-for-third-party-equipment-using-ise/m-p/4997701#M586373</link>
      <description>&lt;P&gt;What I'm just curious about is whether it is possible to set tacacs on third-party equipment with that profile if you put attribute values for multiple third-party equipment (Juniper, Altheon, F5,etc) in one tacacs profile.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jan 2024 15:12:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-profile-questions-for-third-party-equipment-using-ise/m-p/4997701#M586373</guid>
      <dc:creator>CCC3</dc:creator>
      <dc:date>2024-01-16T15:12:32Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS Profile Questions for Third-Party Equipment Using ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-profile-questions-for-third-party-equipment-using-ise/m-p/4997731#M586376</link>
      <description>&lt;P&gt;No, you one per vendor. Use network device groups (or whatever mechanism you like) to ensure only Cisco attributes are sent to Cisco devices, only Juniper to Juniper devices, etc.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/security-knowledge-base/cisco-ise-device-administration-prescriptive-deployment-guide/ta-p/3738365" target="_blank"&gt;https://community.cisco.com/t5/security-knowledge-base/cisco-ise-device-administration-prescriptive-deployment-guide/ta-p/3738365&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jan 2024 15:45:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-profile-questions-for-third-party-equipment-using-ise/m-p/4997731#M586376</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2024-01-16T15:45:13Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS Profile Questions for Third-Party Equipment Using ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-profile-questions-for-third-party-equipment-using-ise/m-p/4997737#M586378</link>
      <description>&lt;P&gt;important attribute is service-type which I think Juniper use standard&amp;nbsp;&lt;BR /&gt;and other VSA check below&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://supportportal.juniper.net/s/article/Configuration-Example-How-to-assign-a-login-class-to-users-that-are-authenticated-using-a-FreeRADIUS-server?language=en_US" target="_blank"&gt;https://supportportal.juniper.net/s/article/Configuration-Example-How-to-assign-a-login-class-to-users-that-are-authenticated-using-a-FreeRADIUS-server?language=en_US&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jan 2024 15:55:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-profile-questions-for-third-party-equipment-using-ise/m-p/4997737#M586378</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-01-16T15:55:16Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS Profile Questions for Third-Party Equipment Using ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-profile-questions-for-third-party-equipment-using-ise/m-p/4998035#M586394</link>
      <description>&lt;P&gt;This means that you have to use one tacacs profile for each vendor.&lt;/P&gt;
&lt;P&gt;Do you know what will happen if you put multiple third-party equipment attribute values in one profile like my question?&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2024 02:25:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-profile-questions-for-third-party-equipment-using-ise/m-p/4998035#M586394</guid>
      <dc:creator>CCC3</dc:creator>
      <dc:date>2024-01-17T02:25:36Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS Profile Questions for Third-Party Equipment Using ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-profile-questions-for-third-party-equipment-using-ise/m-p/4998055#M586397</link>
      <description>It depends on the network device. Some devices just ignore them and work fine if they are given at least one correct attribute. Others will fail to authenticate the admin user completely.&lt;BR /&gt;</description>
      <pubDate>Wed, 17 Jan 2024 03:02:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-profile-questions-for-third-party-equipment-using-ise/m-p/4998055#M586397</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2024-01-17T03:02:43Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS Profile Questions for Third-Party Equipment Using ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-profile-questions-for-third-party-equipment-using-ise/m-p/4998060#M586398</link>
      <description>&lt;P&gt;Do you have any information about some of the equipment you mentioned?&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2024 03:27:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-profile-questions-for-third-party-equipment-using-ise/m-p/4998060#M586398</guid>
      <dc:creator>CCC3</dc:creator>
      <dc:date>2024-01-17T03:27:33Z</dc:date>
    </item>
  </channel>
</rss>

