Network Access Control

Cisco Access Control Server (ACS), Identity Services Engine (ISE), Zero Trust Workplace
cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
This community is for technical, feature, configuration and deployment questions.
For production deployment issues, please contact the TAC! We will not comment or assist with your TAC case in these forums.
Please see How to Ask the Community for Help for other best practices.

Labels

Forum Posts

I configured authentication for Enable to user Tacacs+. I need it to be authenticated the same time when users are logging in. That is, a user types his username and password, he is directly logged into Enable mode.However, it stops everytime at exec...

hanwu_dot by Level 1
  • 731 Views
  • 1 replies
  • 0 Helpful votes

We have following commands configured on the 2950aaa new-modelaaa authentication login default group radius localaaa authentication enable default enableaaa authorization exec default group radius if-authenticatedusername localuser  secret 5 *******W...

We have CAM/CAS 4.8.2, NAC agent 4.8.2.3 and compliance module 3.4.27.1. AVG 2012 cannot be recognized by NAC agent. From the link below, it should work:http://www.cisco.com/en/US/docs/security/nac/appliance/release_notes/49/WinAV-AS-vers90.pdfAnyone...

zhenningx by Level 4
  • 1082 Views
  • 1 replies
  • 0 Helpful votes

Hi,Is it possible to limit access for a specific tacacs username? For example, i need priviledge 15 for the username xyz from 10.1.1.1 to the client 192.168.1.1 but for the rest of the AAA clients all ip connection should be blocked.I tried DACLS and...

Srin_G by Level 3
  • 2591 Views
  • 6 replies
  • 0 Helpful votes

Hi All,My ACS5.2 joined Windows 2003 Active Directory successfully. I created Support group with user1 in the internal store, also created Support-AD group with userad1 in the AD store. Identity Store Sequency is set Internal first, then AD. I can ma...

we have configured  ipsec vpn cisco asa authentication by acs 5.1:Here the config in cisco vpn 5580:access-list acltest standard permit 10.10.30.0 255.255.255.0 aaa-server Gserver protocol radiusaaa-server Gserver (inside) host 10.1.8.10 key ciscoaaa...

ngo duyen by Level 1
  • 2364 Views
  • 5 replies
  • 0 Helpful votes

I am having an issue with authorization on the Nexus 5548. Note: The tacacs configuration has and still works correctly with all non-Nexus gear.Authentication succeeds, and initiatial authorization passes. However, all sh and config commands fail, th...

whinkle by Level 1
  • 1295 Views
  • 1 replies
  • 0 Helpful votes

Hi dearsI have a domain network with Windows Server 2003 and my clients have Windows XP or 7;I want the network authentication be through my NAC appliance (.1X).I add the NAC server to the NAC manager; enable active directory service on NAC manager a...

Aliz_ba by Level 1
  • 951 Views
  • 0 replies
  • 0 Helpful votes