04-17-2017 09:30 PM
Hello,
I understand in ISE, repeated RADIUS requests can be suppressed under Administration>System>Settings>Protocols>RADIUS. Screenshot attached.
Are there plans to extend this suppression capability to TACACS?
The scenario is customer runs a monthly vulnerability scan on their infrastructure devices (switches, WLCs, firewalls). Vulnerability scan software makes repeated login attempts on the infrastructure devices, which is flooding ISE and causing adverse performance issues. Can suppression be configured for TACACS requests as well? If not, what is the recommended workaround?
Thanks in advance.
Solved! Go to Solution.
04-18-2017 02:09 PM
No, log suppression is for RADIUS only but not for T+. No known workaround.
04-18-2017 02:09 PM
No, log suppression is for RADIUS only but not for T+. No known workaround.
04-18-2017 02:13 PM
Recommended workaround is to throttle their tool's usage to a more acceptable level of performance impact.
04-18-2017 02:18 PM
Hi Hsing and Thomas,
Thanks for the replies. I have already provided the customer recommendations, including limiting access to infrastructure devices to management endpoints, control plane policing for management protocols on infrastructure devices, etc. However, as ISE is positioned as the replacement for ACS, and since there is RADIUS suppression available, I would think TACACS suppression should be a natural extension of that.
Thanks again for the insights.
04-18-2017 02:24 PM
I'll forward your request to the Product Manager!
10-22-2018 11:02 AM
Hello, I have a customer asking this same question and I'm wondering if there's any discussions with the BU that came of this feature request. The customer would like to suppress the service account logs that they see in their TACACS Live Logs. Currently I recommended a filter but they'd like to know if there's a way to do it without a filter.
Thanks!
10-22-2018 01:22 PM
The fix CSCvb45390 is likely coming in next patch releases of shipping ISE 2.x.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide