<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Difference between ise in c9800 in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/difference-between-ise-in-c9800/m-p/4823194#M255119</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- FYI :&amp;nbsp;&lt;A href="https://www.google.com/search?q=what+is+the+difference+between+radius+and+tacacs&amp;amp;rlz=1C1CHZL_enBE751BE751&amp;amp;oq=what+is++the+difference+between+radius+and+tacacs&amp;amp;aqs=chrome..69i57j0i512j0i22i30l5j69i64.6831j0j7&amp;amp;sourceid=chrome&amp;amp;ie=UTF-8" target="_blank"&gt;https://www.google.com/search?q=what+is+the+difference+between+radius+and+tacacs&amp;amp;rlz=1C1CHZL_enBE751BE751&amp;amp;oq=what+is++the+difference+between+radius+and+tacacs&amp;amp;aqs=chrome..69i57j0i512j0i22i30l5j69i64.6831j0j7&amp;amp;sourceid=chrome&amp;amp;ie=UTF-8&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
    <pubDate>Thu, 27 Apr 2023 16:27:38 GMT</pubDate>
    <dc:creator>Mark Elsen</dc:creator>
    <dc:date>2023-04-27T16:27:38Z</dc:date>
    <item>
      <title>Difference between ise in c9800</title>
      <link>https://community.cisco.com/t5/wireless/difference-between-ise-in-c9800/m-p/4823153#M255115</link>
      <description>&lt;P&gt;Hi, In C9800 wlc system, we can see radius configuration with ise, but in other cases, we can see they use tacacs instead of radius. In 9800 system, what is difference between radius and tacacs? Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Apr 2023 15:46:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/difference-between-ise-in-c9800/m-p/4823153#M255115</guid>
      <dc:creator>Leftz</dc:creator>
      <dc:date>2023-04-27T15:46:32Z</dc:date>
    </item>
    <item>
      <title>Re: Difference between ise in c9800</title>
      <link>https://community.cisco.com/t5/wireless/difference-between-ise-in-c9800/m-p/4823194#M255119</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- FYI :&amp;nbsp;&lt;A href="https://www.google.com/search?q=what+is+the+difference+between+radius+and+tacacs&amp;amp;rlz=1C1CHZL_enBE751BE751&amp;amp;oq=what+is++the+difference+between+radius+and+tacacs&amp;amp;aqs=chrome..69i57j0i512j0i22i30l5j69i64.6831j0j7&amp;amp;sourceid=chrome&amp;amp;ie=UTF-8" target="_blank"&gt;https://www.google.com/search?q=what+is+the+difference+between+radius+and+tacacs&amp;amp;rlz=1C1CHZL_enBE751BE751&amp;amp;oq=what+is++the+difference+between+radius+and+tacacs&amp;amp;aqs=chrome..69i57j0i512j0i22i30l5j69i64.6831j0j7&amp;amp;sourceid=chrome&amp;amp;ie=UTF-8&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Apr 2023 16:27:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/difference-between-ise-in-c9800/m-p/4823194#M255119</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2023-04-27T16:27:38Z</dc:date>
    </item>
    <item>
      <title>Re: Difference between ise in c9800</title>
      <link>https://community.cisco.com/t5/wireless/difference-between-ise-in-c9800/m-p/4823212#M255120</link>
      <description>&lt;P&gt;I think you need to understand why you might use TACACS for vs Radius, which is typically used these for user access. &amp;nbsp;Back in the day's radius was used for network device access until TACACS was born. &amp;nbsp;There are still networks out there that use radius for network device access, because they don't have a AAA server that supports TACACS. &amp;nbsp;Hope that somewhat clarifies your question.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Apr 2023 16:43:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/difference-between-ise-in-c9800/m-p/4823212#M255120</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2023-04-27T16:43:46Z</dc:date>
    </item>
    <item>
      <title>Re: Difference between ise in c9800</title>
      <link>https://community.cisco.com/t5/wireless/difference-between-ise-in-c9800/m-p/4824190#M255160</link>
      <description>&lt;P&gt;Cisco devices normally use TACACS to authenticate and authorise user access to the device itself - device management.&lt;BR /&gt;TACACS is a Cisco proprietary protocol (so mostly only used by Cisco devices) but Cisco did release the code for it so a few other vendors have released server and client support for it in a limited way.&lt;/P&gt;
&lt;P&gt;Radius is a standard used right across networking.&amp;nbsp; It can be used for management access (like TACACS) but on Cisco devices it is mostly used for user access authentication and management eg. WiFi users, remote access users etc.&lt;/P&gt;</description>
      <pubDate>Fri, 28 Apr 2023 13:52:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/difference-between-ise-in-c9800/m-p/4824190#M255160</guid>
      <dc:creator>Rich R</dc:creator>
      <dc:date>2023-04-28T13:52:36Z</dc:date>
    </item>
    <item>
      <title>Re: Difference between ise in c9800</title>
      <link>https://community.cisco.com/t5/wireless/difference-between-ise-in-c9800/m-p/4824315#M255175</link>
      <description>&lt;P&gt;Thanks for your reply!&lt;/P&gt;&lt;P&gt;Now the c9800 wlc is using Radius. If we change it to TACACS, what do we need to do? just setup TACACS and remove Radius?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Apr 2023 16:24:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/difference-between-ise-in-c9800/m-p/4824315#M255175</guid>
      <dc:creator>Leftz</dc:creator>
      <dc:date>2023-04-28T16:24:25Z</dc:date>
    </item>
    <item>
      <title>Re: Difference between ise in c9800</title>
      <link>https://community.cisco.com/t5/wireless/difference-between-ise-in-c9800/m-p/4824323#M255177</link>
      <description>&lt;P&gt;Not necessarily - it depends what it's using the radius for.&amp;nbsp; For example if you're using it to authenticate an 802.1x WLAN you can't remove it.&amp;nbsp; But if you're using it to authenticate management users then yes you could replace it with TACACS.&amp;nbsp; You'll also have to make sure the ISE server is correctly configured.&amp;nbsp; When you're sure TACACS is working then you could remove the radius.&lt;BR /&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/214490-configure-radius-and-tacacs-for-gui-and.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/214490-configure-radius-and-tacacs-for-gui-and.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Apr 2023 16:39:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/difference-between-ise-in-c9800/m-p/4824323#M255177</guid>
      <dc:creator>Rich R</dc:creator>
      <dc:date>2023-04-28T16:39:29Z</dc:date>
    </item>
    <item>
      <title>Re: Difference between ise in c9800</title>
      <link>https://community.cisco.com/t5/wireless/difference-between-ise-in-c9800/m-p/4824573#M255186</link>
      <description>&lt;P&gt;Please make sure you understand the configuration before you change anything. &amp;nbsp;You just need to review ISE and TACACS configuration documentation so you can follow how your setup is and what it is doing. &amp;nbsp;Then understand how ISE radius is used to authenticate clients. &amp;nbsp;Then and only then you will be able to understand the current policies defined.&lt;/P&gt;</description>
      <pubDate>Sat, 29 Apr 2023 12:51:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/difference-between-ise-in-c9800/m-p/4824573#M255186</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2023-04-29T12:51:16Z</dc:date>
    </item>
    <item>
      <title>Re: Difference between ise in c9800</title>
      <link>https://community.cisco.com/t5/wireless/difference-between-ise-in-c9800/m-p/4825794#M255240</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/244975"&gt;@Rich R&lt;/a&gt;&amp;nbsp;and&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/326193"&gt;@Scott Fella&lt;/a&gt;&amp;nbsp; Thanks for your comments. The below document is talking about radius/tacacs and wlc configuration. Based on the document, the two server radius and tacacs need to be configured at ISE. There are some same features that the two servers own. My question is when WLC need the same feature, which server(Radius or tacacs) would provide the function?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/214490-configure-radius-and-tacacs-for-gui-and.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/214490-configure-radius-and-tacacs-for-gui-and.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 01 May 2023 18:23:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/difference-between-ise-in-c9800/m-p/4825794#M255240</guid>
      <dc:creator>Leftz</dc:creator>
      <dc:date>2023-05-01T18:23:45Z</dc:date>
    </item>
    <item>
      <title>Re: Difference between ise in c9800</title>
      <link>https://community.cisco.com/t5/wireless/difference-between-ise-in-c9800/m-p/4825857#M255245</link>
      <description>&lt;P&gt;TACACS is generally the first choice for management user authentication on Cisco devices.&lt;BR /&gt;RADIUS is the standard for client access authentication across networks generally.&lt;BR /&gt;And when I say authentication I actually mean AAA - authentication, authorisation and accounting.&lt;/P&gt;</description>
      <pubDate>Mon, 01 May 2023 19:59:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/difference-between-ise-in-c9800/m-p/4825857#M255245</guid>
      <dc:creator>Rich R</dc:creator>
      <dc:date>2023-05-01T19:59:54Z</dc:date>
    </item>
    <item>
      <title>Re: Difference between ise in c9800</title>
      <link>https://community.cisco.com/t5/wireless/difference-between-ise-in-c9800/m-p/4825988#M255251</link>
      <description>&lt;P&gt;I am not asking the difference of the two server at this moment. Instead, I would like to know when both servers Radius/TACACS are installed and configured at same ISE/WLC, if a device request the same service feature that the two servers own, which server will respond to it? Is there a mechanism to handle the issue? Or only one of the two server can be selected?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 01 May 2023 21:29:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/difference-between-ise-in-c9800/m-p/4825988#M255251</guid>
      <dc:creator>Leftz</dc:creator>
      <dc:date>2023-05-01T21:29:50Z</dc:date>
    </item>
    <item>
      <title>Re: Difference between ise in c9800</title>
      <link>https://community.cisco.com/t5/wireless/difference-between-ise-in-c9800/m-p/4826038#M255252</link>
      <description>&lt;P&gt;Well you can configure primary and fallback options with aaa config so it might be possible but I really would &lt;U&gt;&lt;STRONG&gt;not&lt;/STRONG&gt;&lt;/U&gt; recommend ever doing that.&amp;nbsp; But if you did that then they'd be selected in the order you configure them to be used.&lt;/P&gt;</description>
      <pubDate>Mon, 01 May 2023 22:16:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/difference-between-ise-in-c9800/m-p/4826038#M255252</guid>
      <dc:creator>Rich R</dc:creator>
      <dc:date>2023-05-01T22:16:52Z</dc:date>
    </item>
    <item>
      <title>Re: Difference between ise in c9800</title>
      <link>https://community.cisco.com/t5/wireless/difference-between-ise-in-c9800/m-p/4826707#M255283</link>
      <description>&lt;P&gt;Thank you very much for your reply. It make sense.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;"Not necessarily - it depends what it's using the radius for.&amp;nbsp; For example if you're using it to authenticate an 802.1x WLAN you can't remove it.&amp;nbsp; But if you're using it to authenticate management users then yes you could replace it with TACACS ..."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Our system uses 802.1x radius for users, so we cannot remove radiius.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;"Well you can configure primary and fallback options with aaa config so it might be possible but I really would&amp;nbsp;&lt;/SPAN&gt;&lt;U&gt;&lt;STRONG&gt;not&lt;/STRONG&gt;&lt;/U&gt;&lt;SPAN&gt;&amp;nbsp;recommend ever doing that.&amp;nbsp; But if you did that then&amp;nbsp;&lt;STRONG&gt;they'd be selected in the order you configure them to be used.&amp;nbsp; "&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Regarding the order we selected, I think you mean AireOS, but looks like we do not have the function at catalyst 9800. so when both Radisu and tacacs co-exist in c9800, there should be a mechanism to control/decide which one(Radius or tacacs) to take care of users authentication and authorization&lt;/P&gt;</description>
      <pubDate>Tue, 09 May 2023 15:33:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/difference-between-ise-in-c9800/m-p/4826707#M255283</guid>
      <dc:creator>Leftz</dc:creator>
      <dc:date>2023-05-09T15:33:40Z</dc:date>
    </item>
    <item>
      <title>Re: Difference between ise in c9800</title>
      <link>https://community.cisco.com/t5/wireless/difference-between-ise-in-c9800/m-p/4826740#M255286</link>
      <description>&lt;P&gt;Please refer back to the answers already provided.&lt;/P&gt;</description>
      <pubDate>Tue, 02 May 2023 14:24:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/difference-between-ise-in-c9800/m-p/4826740#M255286</guid>
      <dc:creator>Rich R</dc:creator>
      <dc:date>2023-05-02T14:24:15Z</dc:date>
    </item>
    <item>
      <title>Re: Difference between ise in c9800</title>
      <link>https://community.cisco.com/t5/wireless/difference-between-ise-in-c9800/m-p/4832008#M255634</link>
      <description>&lt;P&gt;I changed the previous post after i reviewed the question&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;"Not necessarily - it depends what it's using the radius for.&amp;nbsp; For example if you're using it to authenticate an 802.1x WLAN you can't remove it.&amp;nbsp; But if you're using it to authenticate management users then yes you could replace it with TACACS ..."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Our system uses 802.1x radius for users, so we cannot remove radiius.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;"Well you can configure primary and fallback options with aaa config so it might be possible but I really would&amp;nbsp;&lt;/SPAN&gt;&lt;U&gt;&lt;STRONG&gt;not&lt;/STRONG&gt;&lt;/U&gt;&lt;SPAN&gt;&amp;nbsp;recommend ever doing that.&amp;nbsp; But if you did that then &lt;STRONG&gt;they'd be selected in the order you configure them to be used.&amp;nbsp; "&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Regarding the order we selected, I think you mean AireOS, but looks like we do not have the function at catalyst 9800. so when both Radisu and tacacs co-exist in c9800, there should be a mechanism to control/decide which one(Radius or tacacs) to take care of users authentication and authorization.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 May 2023 15:33:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/difference-between-ise-in-c9800/m-p/4832008#M255634</guid>
      <dc:creator>Leftz</dc:creator>
      <dc:date>2023-05-09T15:33:14Z</dc:date>
    </item>
    <item>
      <title>Re: Difference between ise in c9800</title>
      <link>https://community.cisco.com/t5/wireless/difference-between-ise-in-c9800/m-p/4832028#M255637</link>
      <description>&lt;P&gt;&amp;gt;&amp;nbsp;&lt;SPAN&gt;but looks like we do not have the function at catalyst 9800.&lt;BR /&gt;IOS aaa config allows to specify multiple groups so you should be able to use both in order of preference. eg:&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;aaa authentication login default group mytacacs group myradius local&lt;/FONT&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 09 May 2023 15:53:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/difference-between-ise-in-c9800/m-p/4832028#M255637</guid>
      <dc:creator>Rich R</dc:creator>
      <dc:date>2023-05-09T15:53:58Z</dc:date>
    </item>
  </channel>
</rss>

