<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IDS with tacacs in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ids-with-tacacs/m-p/794557#M86308</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;you may be aware of this already, but you can limit access at the network level and enable password lockouts.  Still using local credentials of course;-(&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 28 Jun 2007 16:34:37 GMT</pubDate>
    <dc:creator>mhellman</dc:creator>
    <dc:date>2007-06-28T16:34:37Z</dc:date>
    <item>
      <title>IDS with tacacs</title>
      <link>https://community.cisco.com/t5/network-security/ids-with-tacacs/m-p/794552#M86300</link>
      <description>&lt;P&gt;Are IDS 4215 sensors compatable with tacacs? I did not see anything in the csm, the user guides or ids itself that would lead me to believe it was, but just wanted to make sure with the group.&lt;/P&gt;&lt;P&gt;Thank you. &lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 10:40:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ids-with-tacacs/m-p/794552#M86300</guid>
      <dc:creator>daven.delidle</dc:creator>
      <dc:date>2019-03-10T10:40:42Z</dc:date>
    </item>
    <item>
      <title>Re: IDS with tacacs</title>
      <link>https://community.cisco.com/t5/network-security/ids-with-tacacs/m-p/794553#M86302</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As of now IDS/IPS devices dont support external authentication using AAA servers. Hence the only way users can be authenticated is using the local database on the IDS/IPS device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Vibhor.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Jun 2007 16:27:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ids-with-tacacs/m-p/794553#M86302</guid>
      <dc:creator>vitripat</dc:creator>
      <dc:date>2007-06-27T16:27:16Z</dc:date>
    </item>
    <item>
      <title>Re: IDS with tacacs</title>
      <link>https://community.cisco.com/t5/network-security/ids-with-tacacs/m-p/794554#M86305</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just some additional comments that may or may not help in your planning.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Most of the time it is multi-user environments that require tacacs+ support.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Often these same environments are where CSM is being used for management, and MARS is being used for monitoring.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Both CSM and MARS are built for multi-user environments, and I believe that CSM supports tacacs+ for loggin into the CSM client.  And I am fairly sure MARS also supports tacacs+.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When CSM and/or MARS accesses the sensor they will do so through a single account for all tranmission of data regardless of which user requested the change; rather than trying to connect to the sensor using the same account through which the changes were made in CSM and/or MARS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So at least for day to day monitoring and configuration activities you use tacacs when using CSM and MARS for those activities.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then it is only the periodic troubleshooting requiring direct sensor access that wont fit into your tacacs+ model and local accounts would need to be used on the sensor.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Jun 2007 18:38:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ids-with-tacacs/m-p/794554#M86305</guid>
      <dc:creator>marcabal</dc:creator>
      <dc:date>2007-06-27T18:38:35Z</dc:date>
    </item>
    <item>
      <title>Re: IDS with tacacs</title>
      <link>https://community.cisco.com/t5/network-security/ids-with-tacacs/m-p/794555#M86306</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I  believe tacacs+ is on the roadmap for MARS, but it is currently not supported.  Only local authentication is. You don't really use MARS for day to day management either though.  All MARS really does today is collect the events.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Jun 2007 13:49:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ids-with-tacacs/m-p/794555#M86306</guid>
      <dc:creator>mhellman</dc:creator>
      <dc:date>2007-06-28T13:49:20Z</dc:date>
    </item>
    <item>
      <title>Re: IDS with tacacs</title>
      <link>https://community.cisco.com/t5/network-security/ids-with-tacacs/m-p/794556#M86307</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The lack of tacacs+ or RADIUS support on the IPS sensors have caused me to fail many a security audit and have made me explain WHY my security devices are less secure than the hosts they protect.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Jun 2007 16:11:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ids-with-tacacs/m-p/794556#M86307</guid>
      <dc:creator>rhermes</dc:creator>
      <dc:date>2007-06-28T16:11:07Z</dc:date>
    </item>
    <item>
      <title>Re: IDS with tacacs</title>
      <link>https://community.cisco.com/t5/network-security/ids-with-tacacs/m-p/794557#M86308</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;you may be aware of this already, but you can limit access at the network level and enable password lockouts.  Still using local credentials of course;-(&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Jun 2007 16:34:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ids-with-tacacs/m-p/794557#M86308</guid>
      <dc:creator>mhellman</dc:creator>
      <dc:date>2007-06-28T16:34:37Z</dc:date>
    </item>
  </channel>
</rss>

