03-21-2021 01:34 AM
Hello Everyone,
I would I like to enable show running-configuration or Show configuration for read only users through ISE.
I am new to ISE, please help me on this.
we have two privilege in ISE, one is Full access and another is read only. Read only users unable to see running config. We need to enable this specific command. How can I do for Cisco switches.
by the way we are multi vendor network. Want to enable display current-configuration command for HP switches as well.
please help me on ISE config or any command want to configure in switches ??? Please help me. Thanks!!!
Regards,
Chandhuru
Solved! Go to Solution.
03-21-2021 08:12 AM
http://www.labminutes.com/sec0206_ise_20_tacacs_device_admin_command_authorization_1
https://community.cisco.com/t5/network-access-control/command-authorization-by-ise/td-p/3577202
03-21-2021 07:55 AM
show run is a bit tricky to achieve with read-only - it required higher privileges
i suggest to easy achieve is - user with 15 priv and lock the user to only show run command (or any other command you like (not config t)
https://bluenetsec.com/priv-level-15-with-cisco-ise/
03-21-2021 11:13 AM
Thanks Balaji!!!
It is working for Cisco devices.
For as HP switches, if we set privilege as 15 then it didnt checking command sets. Do you have any idea for that?
03-21-2021 12:18 PM
Chandhuru sekaran marimuthu, This thread is a dup of your other discussion Want to enable command running-config for read only users.
Please read the response from the other thread.
The example from Privilege Level 15 with Cisco ISE | Blue Network Security (bluenetsec.com) is using RADIUS and the command sets are for T+ only. Device administration is very specific to the network devices. Please consult with the admin guides or other info on the particular HP switches for available options and how to implement them.
03-21-2021 08:12 AM
http://www.labminutes.com/sec0206_ise_20_tacacs_device_admin_command_authorization_1
https://community.cisco.com/t5/network-access-control/command-authorization-by-ise/td-p/3577202
03-21-2021 12:02 PM
This appears a duplicate of Want to enable command running-config for read only users - Cisco Community
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide