02-27-2018 11:12 PM
Hi Expert
I am testing ISE 2.2 Device admin(TACACS+) with Nexus platform.
I want to apply command authorization based on sub command mode per account(identity).
below is example I want to do.
NX-OS(config)# interface ethernet 1/1
NX-OS(config-if)# shutdown ==> restrict
NX-OS(config-if)# exit
NX-OS(config)# router bgp 65001
NX-OS(config-router)# shutdown ==> permit
NX-OS(config-router)# neighbor 1.1.1.1
NX-OS(config-router-neighbor)# shutdown ==> permit
NX-OS(config)# interface ethernet 1/1
NX-OS(config-if)# shutdown ==> restrict
NX-OS(config-if)# exit
NX-OS(config)# router bgp 65001
NX-OS(config-router)# shutdown ==> restrict
NX-OS(config-router)# neighbor 1.1.1.1
NX-OS(config-router-neighbor)# shutdown ==> permit
Do you have any idea to do this ?
Regards,
Solved! Go to Solution.
03-01-2018 08:03 PM
I concurred with Danny's.
With T+ command authorization, the command sends to ISE will be "shutdown" without the context. If it applicable, you could simply restrict on command "interface".
NX-OS can also authorize users based on their user roles. In How To: ISE TACACS+ Configuration for Cisco NX-OS Network Devices, I gave one example.
role name demo-security
description A user-defined role example for demo purposes
rule 10 permit read-write feature interface
interface policy deny
permit interface Vethernet1
As I am no expert on NX-OS, I would suggest you to consult Nexus or NX-OS support teams for further guidance.
 
					
				
		
02-27-2018 11:20 PM
I *think* its only possible to accomplish by stating the exact port in your restrict commands.
Iet me check on this and update.
03-01-2018 05:01 PM
03-01-2018 08:03 PM
I concurred with Danny's.
With T+ command authorization, the command sends to ISE will be "shutdown" without the context. If it applicable, you could simply restrict on command "interface".
NX-OS can also authorize users based on their user roles. In How To: ISE TACACS+ Configuration for Cisco NX-OS Network Devices, I gave one example.
role name demo-security
description A user-defined role example for demo purposes
rule 10 permit read-write feature interface
interface policy deny
permit interface Vethernet1
As I am no expert on NX-OS, I would suggest you to consult Nexus or NX-OS support teams for further guidance.
 
					
				
				
			
		
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide