This community is for technical, feature, configuration and deployment questions.
For production deployment issues, please contact the TAC!
We will not comment or assist with your TAC case in these forums.
Please see How to Ask the Community for Help for other best practices.
Hi guys,
One of my clients is asking if it’s possible for a tacacs user account in ISE to bypass all logging and audit type features ?
Such an account will only authenticate and the password should never be decipherable.
Any sort of auth logs including accounting and commands run should never be recorded at all.
Could you let me know if that’s even possible ? To me it sounds this goes against the AAA method.
Thank you
Sam
Collection filters for TACACS was just added in patch 6. You can now filter out all logs for given usernames just like you are able to do for RADIUS. Basically the same collection filters now apply to both.