cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1532
Views
2
Helpful
2
Replies

ISE Admin Login

chunhwon
Cisco Employee
Cisco Employee

Hi All,

have checked that external identity source didn't include TACACS+ (AD, LDAP, ODBC, Radius token, RSA SecureID and SAML supported), just wonder if ISE admin login authentication can support TACACS+?

Many thanks,
CH

1 Accepted Solution

Accepted Solutions

hslai
Cisco Employee
Cisco Employee

Neither ISE admin web UI or CLI is currently supporting TACACS+. If you have customers interested on such, please contact our PM team.

The aaa configuration command appears accidentally exposed in some particular ISE version/patch combination but never supported officially.

View solution in original post

2 Replies 2

Charlie Moreton
Cisco Employee
Cisco Employee

Currently, for the Web GUI, you can choose from the External Identity Sources that can be found at Administration > Identity Management > External Identity Sources (excluding Social Login in v2.3).  TACACS+ is not listed and cannot be leveraged for login at the Admin Portal.

The Identity Sources used for the Admin Portal do not include servers added to Work Centers > Device Administration > Network Resources > TACACS External Servers and therefore, cannot be leveraged.

From CLI, You can configure the command aaa authentication tacacs+ server <IP or hostname> key <TACACS Shared Secret>, but this will only be for CLI login.

hslai
Cisco Employee
Cisco Employee

Neither ISE admin web UI or CLI is currently supporting TACACS+. If you have customers interested on such, please contact our PM team.

The aaa configuration command appears accidentally exposed in some particular ISE version/patch combination but never supported officially.