01-13-2020 05:40 AM
I am planning to upgrade our network security by deploying TACAC login on the switches.
We already setup an AD group and Cisco ISE server and are able to log into the switches with specific AD users.
There is an Cisco Prime server which will get his own AD User to log into these switches to manage them. (currently it uses the local login credentials to access the switches)
Now the question.
We want to secure the usage of the Cisco Prime AD account by only allowing it to be used from the Prime Server. We are very inexperience in the usage of Cisco ISE and don't know it's full potential yet.
Is this possible, if yes. How do you do this.
I would appreciate the help
Solved! Go to Solution.
01-13-2020 06:07 AM
01-13-2020 06:07 AM
01-16-2020 05:49 PM
Mike.Cifelli is correct.
You might also be interested in our resources page on device admin -- ISE Device Administration resources for TACACS+ and RADIUS; specifically, ISE Device Administration Prescriptive Deployment Guide has some examples on Prime Infrastructure.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide