Tacacs command set cisco ise
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-13-2022 12:36 PM
Dear genius.
i am trying to restrict shutdown command under fastethernet interfaces of switch but want to allow shutdown command under gig interfaces. How will i achieve this?
is this possible or not?
please tell me Grant, Command and arguments for my query.
- Labels:
-
Identity Services Engine (ISE)
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-13-2022 02:10 PM
I am new in AAA but I read before that TACACS can do control the commend available for each user.
please see link.
hope this help you
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-13-2022 10:47 PM
Dear MHM,
i am not asking how to control AD user access using ISE. The link which you shared i know thag thing. My question was how to provide a user deny and permit access for doing shutdown at same time under different interfaces of switch.
please read my question again.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-14-2022 02:22 AM
This is required more of testing tweaking of shell profile : @MHM Cisco World concept suggested was on ACS. but ISE side also work as same.
Watch this video get more idea, how you can do shell authorisation customisation.
https://www.youtube.com/watch?v=DlzALGHZ0o4
