<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: TACACS Role for ND and NDFC not working with one av-pair in Nexus Dashboard</title>
    <link>https://community.cisco.com/t5/nexus-dashboard/tacacs-role-for-nd-and-ndfc-not-working-with-one-av-pair/m-p/4953994#M355</link>
    <description>&lt;P&gt;Hi John,&lt;/P&gt;
&lt;P&gt;I just tested the av-pair you suggested in our TACACS server:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="BigDalton_0-1699240941436.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/201661i331DFCACD4E9A5EF/image-size/medium?v=v2&amp;amp;px=400" role="button" title="BigDalton_0-1699240941436.png" alt="BigDalton_0-1699240941436.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;This gives no access to either ND nor NDFC:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="BigDalton_1-1699241009895.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/201662iED9663EC7B4B2DB8/image-size/medium?v=v2&amp;amp;px=400" role="button" title="BigDalton_1-1699241009895.png" alt="BigDalton_1-1699241009895.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 06 Nov 2023 03:23:54 GMT</pubDate>
    <dc:creator>BigDalton</dc:creator>
    <dc:date>2023-11-06T03:23:54Z</dc:date>
    <item>
      <title>TACACS Role for ND and NDFC not working with one av-pair</title>
      <link>https://community.cisco.com/t5/nexus-dashboard/tacacs-role-for-nd-and-ndfc-not-working-with-one-av-pair/m-p/4940733#M338</link>
      <description>&lt;P&gt;According to configuration guide, the new version of NDFC and ND have RBAC configured all in ND admin console, and ND "admin" is treated as NDFC "network-admin" too. But in my ND 3.0.1 and NDFC 12.1.3 setup, one role does not give access to both ND and NDFC.&lt;/P&gt;
&lt;P&gt;If I return TACACS cisco-av-pair with shell:role="admin", I can access ND but not NDFC. If I change it to shell:role="network-admin", then I can access NDFC not ND admin console.&lt;/P&gt;
&lt;P&gt;I tried to manipulate attribute value but with no luck getting it working for both ND and NDFC access. Is the guide wrong, or I missed something?&lt;/P&gt;</description>
      <pubDate>Mon, 16 Oct 2023 03:20:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/nexus-dashboard/tacacs-role-for-nd-and-ndfc-not-working-with-one-av-pair/m-p/4940733#M338</guid>
      <dc:creator>BigDalton</dc:creator>
      <dc:date>2023-10-16T03:20:44Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS Role for ND and NDFC not working with one av-pair</title>
      <link>https://community.cisco.com/t5/nexus-dashboard/tacacs-role-for-nd-and-ndfc-not-working-with-one-av-pair/m-p/4951740#M349</link>
      <description>&lt;P&gt;Hello Mate&lt;/P&gt;
&lt;P&gt;I am building a NDFC multisite fabric and need to enable AAA. Seeing you have done that, would like to ask some queries around that, if it's okay with you:&lt;/P&gt;
&lt;P&gt;1. What documentation did you refer to enable AAA on the NDFC?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2. Did you enable AAA on the switches first and then on the NDFC? if so what user credentials NDFC uses when it pushes out configuration to the switches?&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Rohan&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 31 Oct 2023 23:08:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/nexus-dashboard/tacacs-role-for-nd-and-ndfc-not-working-with-one-av-pair/m-p/4951740#M349</guid>
      <dc:creator>rohandec1980</dc:creator>
      <dc:date>2023-10-31T23:08:45Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS Role for ND and NDFC not working with one av-pair</title>
      <link>https://community.cisco.com/t5/nexus-dashboard/tacacs-role-for-nd-and-ndfc-not-working-with-one-av-pair/m-p/4953988#M354</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Could you please have a try with&amp;nbsp;&lt;SPAN&gt;TACACS cisco-av-pair of "shell:domains=all/network-admin/"?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;This will grant ND admin permission, and "all" means entire NDFC security domain. &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;If you need specify particular security domain, you need change it accordingly.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please refer following guide for your deployment.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/dam/en/us/td/docs/dcn/ndfc/1213/articles/ndfc-security-domains/configuring-security-domains.pdf" target="_blank"&gt; https://www.cisco.com/c/dam/en/us/td/docs/dcn/ndfc/1213/articles/ndfc-security-domains/configuring-security-domains.pdf&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If you find my reply solved your question or issue, kindly click the 'Accept as Solution' button and vote it as helpful.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;You can also learn more about Cisco NDFC (previously known as DCNM) through our live Ask the Experts (ATXs) session. Check out this ATXs Resources [&lt;/SPAN&gt;&lt;A href="https://community.cisco.com/t5/data-center-and-cloud-knowledge/cisco-aci-ask-the-experts-resources/ta-p/4394491" target="_blank" rel="noopener"&gt;https://community.cisco.com/t5/data-center-and-cloud-knowledge/cisco-aci-ask-the-experts-resources/ta-p/4394491&lt;/A&gt;&lt;SPAN&gt;] to view the latest schedule for upcoming sessions, as well as the useful references, e.g. online guides, FAQs.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Nov 2023 03:09:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/nexus-dashboard/tacacs-role-for-nd-and-ndfc-not-working-with-one-av-pair/m-p/4953988#M354</guid>
      <dc:creator>John Cui</dc:creator>
      <dc:date>2023-11-06T03:09:02Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS Role for ND and NDFC not working with one av-pair</title>
      <link>https://community.cisco.com/t5/nexus-dashboard/tacacs-role-for-nd-and-ndfc-not-working-with-one-av-pair/m-p/4953994#M355</link>
      <description>&lt;P&gt;Hi John,&lt;/P&gt;
&lt;P&gt;I just tested the av-pair you suggested in our TACACS server:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="BigDalton_0-1699240941436.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/201661i331DFCACD4E9A5EF/image-size/medium?v=v2&amp;amp;px=400" role="button" title="BigDalton_0-1699240941436.png" alt="BigDalton_0-1699240941436.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;This gives no access to either ND nor NDFC:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="BigDalton_1-1699241009895.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/201662iED9663EC7B4B2DB8/image-size/medium?v=v2&amp;amp;px=400" role="button" title="BigDalton_1-1699241009895.png" alt="BigDalton_1-1699241009895.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Nov 2023 03:23:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/nexus-dashboard/tacacs-role-for-nd-and-ndfc-not-working-with-one-av-pair/m-p/4953994#M355</guid>
      <dc:creator>BigDalton</dc:creator>
      <dc:date>2023-11-06T03:23:54Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS Role for ND and NDFC not working with one av-pair</title>
      <link>https://community.cisco.com/t5/nexus-dashboard/tacacs-role-for-nd-and-ndfc-not-working-with-one-av-pair/m-p/4953996#M356</link>
      <description>&lt;P&gt;Hi Rohan,&lt;/P&gt;
&lt;P&gt;My question is about AAA for the ND/NDFC appliances, not AAA for the managed switches.&lt;/P&gt;
&lt;P&gt;I have not checked switch AAA in NDFC yet, but I think that would be pushed by NDFC to the switch using templates still. A local credential is still needed for inital switch discovery and config push.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Nov 2023 03:28:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/nexus-dashboard/tacacs-role-for-nd-and-ndfc-not-working-with-one-av-pair/m-p/4953996#M356</guid>
      <dc:creator>BigDalton</dc:creator>
      <dc:date>2023-11-06T03:28:09Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS Role for ND and NDFC not working with one av-pair</title>
      <link>https://community.cisco.com/t5/nexus-dashboard/tacacs-role-for-nd-and-ndfc-not-working-with-one-av-pair/m-p/4954038#M357</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Could you try to test some with following format?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ndfc.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/201671iBB766024580FFE72/image-size/large?v=v2&amp;amp;px=999" role="button" title="ndfc.png" alt="ndfc.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;If still not work, would be good to query with TAC engineer.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Nov 2023 06:42:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/nexus-dashboard/tacacs-role-for-nd-and-ndfc-not-working-with-one-av-pair/m-p/4954038#M357</guid>
      <dc:creator>John Cui</dc:creator>
      <dc:date>2023-11-06T06:42:59Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS Role for ND and NDFC not working with one av-pair</title>
      <link>https://community.cisco.com/t5/nexus-dashboard/tacacs-role-for-nd-and-ndfc-not-working-with-one-av-pair/m-p/4954599#M358</link>
      <description>&lt;P&gt;Hi John,&lt;/P&gt;
&lt;P&gt;When using shell:domains in the config, I can't even select NDFC from the ND dropdown list. But when using shell:roles at least I can choose either admin for ND or network-admin for NDFC. I'm not sure why shell:domains does not work despite the document says to use it. It looks like I will have to raise a TAC case to get the answer. Thanks for taking the time to look into this issue for me.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Nov 2023 23:22:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/nexus-dashboard/tacacs-role-for-nd-and-ndfc-not-working-with-one-av-pair/m-p/4954599#M358</guid>
      <dc:creator>BigDalton</dc:creator>
      <dc:date>2023-11-06T23:22:34Z</dc:date>
    </item>
  </channel>
</rss>

