cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2602
Views
5
Helpful
17
Replies

Use ISE to limit access to specific VRFs

Nerd_Herd
Level 1
Level 1

One of my clients would like to limit access of user to their specific VRFs. Since the VRFs span multiple devices its not possible to restrict by network access device, We're using TACACS so I tried to limit commands pertaining to other VRFs but all commands were blocked regardless of the argument given. Ex command = sh argument= ^vrf vrfname$ I used the ^$ symbols to get the start and stop of the string but it hit on every vrf. Any examples doing something would be appreciated.  

17 Replies 17

If that So it will work' keep in mind dont select permit any command not list option.

Goodluck 

MHM

That's one of the things we discovered is that regex does not seem to work.