09-03-2021 09:33 AM - edited 09-04-2021 03:37 PM
Hi guys,
I feel like it's a noob question but my understanding always was that there should be a separate TACACS+ authorization request which is not blended into an Authentication packet:
Please can you educate me, and point me to the correct KB?
Thanks,
myky
Solved! Go to Solution.
09-03-2021 10:14 AM
09-03-2021 10:14 AM
09-03-2021 10:35 AM - edited 09-05-2021 01:55 PM
Hello,
Thanks for your reply, and I think I got it now.
So basically, you will have to have shell access in the first place when authenticated, and for that to be allowed, you will have to have an explicit Authorization policy (which gets evaluated during the auth).
Then commands authorization, as you mention, (if configured) where another user group and authorization policy lookup happens and is logged by ISE as the separate Authorization lookup log.
Is my understanding correct?
Thanks,
myky
09-03-2021 11:33 AM
Hi @mykys ,
for better understand, please take a look at: Cisco ISE Device Administration Prescriptive Deployment Guide.
Hope this helps !!!
09-03-2021 05:27 PM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide