09-20-2017 04:43 AM
Hi Team,
Please suggest attribute for Fortinet FW, Paloalto FW and Checkpoint FW for authenticate through TACACS+ of ISE.
I am not able to find right attribute.
Regards
Anjan
Solved! Go to Solution.
09-20-2017 02:19 PM
Not clear of the ask. Often the integration is to validate the authentication of a specific user via TACACS+ protocol. It is possible to perform authorization and ISE should be able to return whichever attribute expected by NAD as an authorization. Best to refer to individual vendor docs for the specific use case you need.
Craig
09-20-2017 02:19 PM
Not clear of the ask. Often the integration is to validate the authentication of a specific user via TACACS+ protocol. It is possible to perform authorization and ISE should be able to return whichever attribute expected by NAD as an authorization. Best to refer to individual vendor docs for the specific use case you need.
Craig
09-20-2017 02:31 PM
Craig is correct.
Fortinet FW does not appear to use its Vendor-specific attributes. Checkpoint seems useing privilege levels, per Best Practices - Configuring Cisco ACS 5 server for TACACS+ authentication with Gaia OS. Palto Alto Networks appears using admin roles, per How to configure Tacacs authentication with Palo Alto Networks firewall - Live Community.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide