08-03-2023 09:59 AM - edited 08-03-2023 10:06 AM
08-03-2023 11:43 AM
Hi @Nick O
Can you share the switch config?
08-03-2023 11:49 AM
yes I can
aaa authentication login VTY group ise-servers local
aaa authentication enable default group ise-servers enable
aaa authorization console
aaa authorization config-commands
aaa authorization exec VTY group ise-servers local
aaa accounting exec default start-stop group ise-servers
aaa accounting commands 0 default start-stop group tacacs+
aaa accounting commands 1 default stop-only group tacacs+
aaa accounting commands 7 default stop-only group tacacs+
aaa accounting commands 15 default stop-only group tacacs+
aaa accounting system default start-stop group ise-servers
08-03-2023 11:55 AM
Instead tacacs+ try to use the group name.
aaa accounting commands 0 default start-stop group ise-servers
aaa accounting commands 1 default stop-only group ise-servers
aaa accounting commands 7 default stop-only group ise-servers
aaa accounting commands 15 default stop-only group ise-servers
08-03-2023 12:58 PM
That solved the issue now the logs are reporting. But the TACACS live logs are not reporting at all. Any solve for that.
08-03-2023 01:06 PM
You mean on the ISE live logs you do not see any logs?
08-03-2023 01:16 PM
yes the live logs are not visible. Logs that are can be accessed through Device Admin>Reports>device admin reports
Usually they are accessible through the live logs. Before going through a deeper dive.
08-03-2023 03:05 PM
Well, ISE is not something I am well versed but you may take a look on this link
https://www.wiresandwi.fi/blog/cisco-ise-fresh-ise-31-queue-link-errors-empty-live-logs
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide