cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2148
Views
10
Helpful
3
Replies

Smart Card Authentication PKI - NX-OS Device TACACS+ On ISE 2.7

Roger3
Level 1
Level 1

Is there a definitive guide for configuring smart card authentication on NX-OS devices that use TACACS+ on ISE?

 

I found this white paper for IOS-XE but NX-OS is significantly different.

 

cisco-2-factor (pragmasys.com)

1 Accepted Solution

Accepted Solutions

The tacacs+ config for NXOS is pretty straightforward and easily done. The harder part was the ssh/crypto stuff. Once NXOS has extracted the username from the cert, the “aaa authentication…” and “aaa authorisation…” commands are needed to perform the aaa tasks to the tacacs+ servers.

 

The Prescriptive Guide is very good  -there is a section specific to Nexus.

 

(https://community.cisco.com/t5/security-documents/cisco-ise-device-administration-prescriptive-deployment-guide/ta-p/3738365)

 

 

View solution in original post

3 Replies 3

Arne Bier
VIP
VIP

Hello

 

It's a great question.

 

Have you tried this method?

 

 

Hello Arne,

 

I found that before I posted this.  I don't want to have to configure local users on every switch.  Is there a way to configure this with TACACS+?

 

Roger

The tacacs+ config for NXOS is pretty straightforward and easily done. The harder part was the ssh/crypto stuff. Once NXOS has extracted the username from the cert, the “aaa authentication…” and “aaa authorisation…” commands are needed to perform the aaa tasks to the tacacs+ servers.

 

The Prescriptive Guide is very good  -there is a section specific to Nexus.

 

(https://community.cisco.com/t5/security-documents/cisco-ise-device-administration-prescriptive-deployment-guide/ta-p/3738365)