AAA Configuration on ISE

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-23-2017 03:38 AM
Dears in Community
I have configured AAA in ISE 2.2. but I am receiving error of 13036 error message (selected shell profile is deny access) when it is authenticated in live logs.
Regards
- Labels:
-
Identity Services Engine (ISE)

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-23-2017 05:19 AM
You would need to post a screen shot of your policy set and the details of the authentication hitting the Deny Access. It sounds like your rules aren't configured correctly and you aren't hitting the rule you expect.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-23-2017 08:48 PM
Hi,
Along with the policy, I think you need to share your debug radius authen from NAD to match the sent attributes against the policy set.

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-23-2017 11:16 PM
Hello , go to Device administration -> policy elements >results >Tacacs command sets > create new command set like
permit all commands
Command Set
Commands
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-28-2017 03:00 PM
Adding to the other comments, please check out the guides @ Device Administration (TACACS+)
