<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Authentication of cisco switch tacacs with ISE in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/authentication-of-cisco-switch-tacacs-with-ise/m-p/5262119#M595054</link>
    <description>&lt;P&gt;If I understand your question correctly. . .&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;&lt;SPAN&gt;you set ISE Profile as&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;Set Default Privilege to 1&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Maximum Privilege set to 15.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;you are landing at the user promt &amp;gt; then you have to type enable and you will be placed in # mode ( this is expected behavior )&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Now if you want your switch to ask for enable password, you have two options either configure your NAD/SWITCH to use local enable secret (configured on the same switch) or you can also confiure your NAD to verify enable password from ISE.&lt;BR /&gt;&lt;BR /&gt;-Which enable secret switch will accept depends upon the configuration you did on the switch&amp;nbsp;&lt;BR /&gt;- bydefault the switch will accept the locally configured enable secret&amp;nbsp;&lt;BR /&gt;- but you can configure switch to use enable password from the ISE with the following cammand&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;PRE&gt;aaa authentication enable default tacacs+ enable&lt;/PRE&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 18 Feb 2025 19:02:27 GMT</pubDate>
    <dc:creator>asaditian</dc:creator>
    <dc:date>2025-02-18T19:02:27Z</dc:date>
    <item>
      <title>Authentication of cisco switch tacacs with ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/authentication-of-cisco-switch-tacacs-with-ise/m-p/5260467#M594986</link>
      <description>&lt;P&gt;We're currently testing tacacs&lt;/P&gt;
&lt;P&gt;from ise to tacacs profile&lt;BR /&gt;Set Default Privilege to 1&lt;BR /&gt;Maximum Privilege set to 15.&lt;/P&gt;
&lt;P&gt;My personal opinion is&lt;BR /&gt;If you set it as above, the switch will successfully log in to the tacacs account and if enabled in the &amp;gt; state, you will receive Maximum Privilege and enter #.&lt;/P&gt;
&lt;P&gt;However, if you enable it in &amp;gt;, you can't enter # mode with the message %Error in authentication if you ask for password and enter password.&lt;/P&gt;
&lt;P&gt;Am I thinking wrong by any chance?&lt;/P&gt;</description>
      <pubDate>Fri, 14 Feb 2025 08:34:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authentication-of-cisco-switch-tacacs-with-ise/m-p/5260467#M594986</guid>
      <dc:creator>CCC3</dc:creator>
      <dc:date>2025-02-14T08:34:35Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication of cisco switch tacacs with ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/authentication-of-cisco-switch-tacacs-with-ise/m-p/5260544#M594993</link>
      <description>&lt;P&gt;Not sure what you are actually doing here, but why would you want users that auth as priv level 15 to log in to Disable-mode? If they are priv-users, just let them auth directly into Enable-mode?&lt;/P&gt;</description>
      <pubDate>Fri, 14 Feb 2025 11:14:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authentication-of-cisco-switch-tacacs-with-ise/m-p/5260544#M594993</guid>
      <dc:creator>trondaker</dc:creator>
      <dc:date>2025-02-14T11:14:08Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication of cisco switch tacacs with ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/authentication-of-cisco-switch-tacacs-with-ise/m-p/5260786#M595008</link>
      <description>&lt;P&gt;As I wrote in the post&lt;BR /&gt;We are testing it in various scenarios.&lt;/P&gt;
&lt;P&gt;1) Set Default Privilege to 1&lt;BR /&gt;Maximum Privilege set to 1.&lt;/P&gt;
&lt;P&gt;2) Set Default Privilege to 1&lt;BR /&gt;Maximum Privilege set to 15.&lt;/P&gt;
&lt;P&gt;3) Set Default Privilege to 15&lt;BR /&gt;Maximum Privilege set to 15.&lt;/P&gt;
&lt;P&gt;In case of number 1, it was impossible to enter the #mode with enable&lt;BR /&gt;For 3 times, as soon as I logged in, I entered #mode.&lt;/P&gt;
&lt;P&gt;This scenario is the same as I thought&lt;/P&gt;
&lt;P&gt;In case 2, I wrote a post because it was different from what I thought.&lt;/P&gt;</description>
      <pubDate>Sat, 15 Feb 2025 05:51:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authentication-of-cisco-switch-tacacs-with-ise/m-p/5260786#M595008</guid>
      <dc:creator>CCC3</dc:creator>
      <dc:date>2025-02-15T05:51:16Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication of cisco switch tacacs with ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/authentication-of-cisco-switch-tacacs-with-ise/m-p/5262119#M595054</link>
      <description>&lt;P&gt;If I understand your question correctly. . .&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;&lt;SPAN&gt;you set ISE Profile as&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;Set Default Privilege to 1&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Maximum Privilege set to 15.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;you are landing at the user promt &amp;gt; then you have to type enable and you will be placed in # mode ( this is expected behavior )&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Now if you want your switch to ask for enable password, you have two options either configure your NAD/SWITCH to use local enable secret (configured on the same switch) or you can also confiure your NAD to verify enable password from ISE.&lt;BR /&gt;&lt;BR /&gt;-Which enable secret switch will accept depends upon the configuration you did on the switch&amp;nbsp;&lt;BR /&gt;- bydefault the switch will accept the locally configured enable secret&amp;nbsp;&lt;BR /&gt;- but you can configure switch to use enable password from the ISE with the following cammand&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;PRE&gt;aaa authentication enable default tacacs+ enable&lt;/PRE&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Feb 2025 19:02:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authentication-of-cisco-switch-tacacs-with-ise/m-p/5262119#M595054</guid>
      <dc:creator>asaditian</dc:creator>
      <dc:date>2025-02-18T19:02:27Z</dc:date>
    </item>
  </channel>
</rss>

