<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ISE doesn't show set commands in TACACS Command Accounting in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-doesn-t-show-set-commands-in-tacacs-command-accounting/m-p/5204526#M592246</link>
    <description>&lt;P&gt;The command is from FMC for firepower so you need to config fmc with ISE tacacs&lt;/P&gt;
&lt;P&gt;Also same for ASDM (not sure how we can config it).&lt;/P&gt;
&lt;P&gt;I. E. FW need to use cli for tacacs work correctly&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.calebsargeant.com/en/latest/networking/cisco/core-security/network-security-with-cisco-firepower/2.-configuring-aaa-on-an-ftd-appliance-for-use-with-cisco-ise.html" target="_blank"&gt;https://docs.calebsargeant.com/en/latest/networking/cisco/core-security/network-security-with-cisco-firepower/2.-configuring-aaa-on-an-ftd-appliance-for-use-with-cisco-ise.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
    <pubDate>Mon, 07 Oct 2024 13:18:12 GMT</pubDate>
    <dc:creator>MHM Cisco World</dc:creator>
    <dc:date>2024-10-07T13:18:12Z</dc:date>
    <item>
      <title>Cisco ISE doesn't show set commands in TACACS Command Accounting</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-doesn-t-show-set-commands-in-tacacs-command-accounting/m-p/5204420#M592231</link>
      <description>&lt;P&gt;I found interesting things in ISE 3.2. I configured policy set for some users after some time I wanted to get report "TACACS Command Accounting" and for users with policy set I could see only two commands&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;terminal no monitor
terminal pager 0&lt;/LI-CODE&gt;
&lt;P&gt;but if I open detail report on the&amp;nbsp;&lt;A class="" href="https://ise02-nsk.global.bcs/admin/#monitor/tacacs_logs/monitor_dashboard_tacacsauthandauthz_v2" data-item-id="monitor_dashboard_tacacsauthandauthz_v2" data-level="3" target="_blank"&gt;"Live Logs&lt;/A&gt;" I can see that there are commands which I permited&lt;/P&gt;
&lt;P&gt;for other users without comands policy sets (just priv 15) I can see all the command which were&amp;nbsp;&lt;SPAN class="EzKURWReUAB5oZgtQNkl" data-src-align="0:11"&gt;performed on the device&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="EzKURWReUAB5oZgtQNkl" data-src-align="0:11"&gt;problem only for FW&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Oct 2024 10:00:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-doesn-t-show-set-commands-in-tacacs-command-accounting/m-p/5204420#M592231</guid>
      <dc:creator>dijix1990</dc:creator>
      <dc:date>2024-10-07T10:00:02Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE doesn't show set commands in TACACS Command Accounting</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-doesn-t-show-set-commands-in-tacacs-command-accounting/m-p/5204495#M592236</link>
      <description>&lt;P&gt;What is "FW"?&amp;nbsp; Sounds like the NAD is not sending or is not properly configured for TACACS+ Accounting.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Oct 2024 12:27:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-doesn-t-show-set-commands-in-tacacs-command-accounting/m-p/5204495#M592236</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2024-10-07T12:27:20Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE doesn't show set commands in TACACS Command Accounting</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-doesn-t-show-set-commands-in-tacacs-command-accounting/m-p/5204512#M592239</link>
      <description>&lt;P&gt;Firewall, not properly? But why for users without tacacs command policy sets I can see every commands via report?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Oct 2024 12:49:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-doesn-t-show-set-commands-in-tacacs-command-accounting/m-p/5204512#M592239</guid>
      <dc:creator>dijix1990</dc:creator>
      <dc:date>2024-10-07T12:49:46Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE doesn't show set commands in TACACS Command Accounting</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-doesn-t-show-set-commands-in-tacacs-command-accounting/m-p/5204513#M592240</link>
      <description>&lt;P&gt;What is the firewall device?&amp;nbsp; Maybe that particular NAD doesn't send TACACS+ accounting when a command set is applied for TACACS+ Authorization?&amp;nbsp; Not sure.&amp;nbsp; Where as if no command set is assigned then the NAD does send TACACS+ accounting?&lt;/P&gt;</description>
      <pubDate>Mon, 07 Oct 2024 12:52:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-doesn-t-show-set-commands-in-tacacs-command-accounting/m-p/5204513#M592240</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2024-10-07T12:52:19Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE doesn't show set commands in TACACS Command Accounting</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-doesn-t-show-set-commands-in-tacacs-command-accounting/m-p/5204517#M592242</link>
      <description>&lt;P&gt;It's different, frp1010/2120/4125 with asa software. Don't know why, I just delete command set for particular users and after it I can see via report. And I can see every commands for users with command set via Tacacs Live page. Strange behaviour&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Oct 2024 12:58:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-doesn-t-show-set-commands-in-tacacs-command-accounting/m-p/5204517#M592242</guid>
      <dc:creator>dijix1990</dc:creator>
      <dc:date>2024-10-07T12:58:37Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE doesn't show set commands in TACACS Command Accounting</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-doesn-t-show-set-commands-in-tacacs-command-accounting/m-p/5204522#M592245</link>
      <description>That’s weird for sure, I would open a TAC case. Why ASA and not FTD though? Nothing to do with the question just curious &lt;BR /&gt;</description>
      <pubDate>Mon, 07 Oct 2024 13:06:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-doesn-t-show-set-commands-in-tacacs-command-accounting/m-p/5204522#M592245</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2024-10-07T13:06:10Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE doesn't show set commands in TACACS Command Accounting</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-doesn-t-show-set-commands-in-tacacs-command-accounting/m-p/5204526#M592246</link>
      <description>&lt;P&gt;The command is from FMC for firepower so you need to config fmc with ISE tacacs&lt;/P&gt;
&lt;P&gt;Also same for ASDM (not sure how we can config it).&lt;/P&gt;
&lt;P&gt;I. E. FW need to use cli for tacacs work correctly&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.calebsargeant.com/en/latest/networking/cisco/core-security/network-security-with-cisco-firepower/2.-configuring-aaa-on-an-ftd-appliance-for-use-with-cisco-ise.html" target="_blank"&gt;https://docs.calebsargeant.com/en/latest/networking/cisco/core-security/network-security-with-cisco-firepower/2.-configuring-aaa-on-an-ftd-appliance-for-use-with-cisco-ise.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Mon, 07 Oct 2024 13:18:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-doesn-t-show-set-commands-in-tacacs-command-accounting/m-p/5204526#M592246</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-10-07T13:18:12Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE doesn't show set commands in TACACS Command Accounting</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-doesn-t-show-set-commands-in-tacacs-command-accounting/m-p/5205068#M592280</link>
      <description>&lt;P&gt;We are going to move to FTD next year.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Oct 2024 08:50:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-doesn-t-show-set-commands-in-tacacs-command-accounting/m-p/5205068#M592280</guid>
      <dc:creator>dijix1990</dc:creator>
      <dc:date>2024-10-08T08:50:26Z</dc:date>
    </item>
  </channel>
</rss>

