cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
6962
Views
5
Helpful
4
Replies

Using CHAP with TACACS

hradhanp
Cisco Employee
Cisco Employee

 Can we use CHAP instead of PAP for device administration. If yes, how we can configure ACS/lSE to achieve this?

1 Accepted Solution

Accepted Solutions

Surendra
Cisco Employee
Cisco Employee
It is primarily a configuration on the Network Device. On the ISE, you can navigate to Policy > Policy Elements > Results > Authentication > Allowed Protocols, to allow CHAP or any other protocol. On the ACS, it would be Access Policies > [ Click on Access Service Name] > Allowed Protocols

View solution in original post

4 Replies 4

Surendra
Cisco Employee
Cisco Employee
It is primarily a configuration on the Network Device. On the ISE, you can navigate to Policy > Policy Elements > Results > Authentication > Allowed Protocols, to allow CHAP or any other protocol. On the ACS, it would be Access Policies > [ Click on Access Service Name] > Allowed Protocols

Any configuration required on the Network Device? We have already configured the policy in ACS/ISE.

Configuration depends on the Network Device make and model. Would suggest you check documentation of those devices for the same.

I have this problem too and was solved it by:

ACS > Access Policies > Access Service Name > Allowed Protocols