ā01-26-2021 04:05 AM
Hello
I have searched information , but i did not found anything. I need to identify the vendor of my routers on my ISE deployment to apply diferents tacacs commands sets and policys. I have Cisco and Huawei.
Anyboyd knows a guide or info to do this?
Solved! Go to Solution.
ā01-26-2021 09:49 AM
ISE cannot detect the vendor for purposes of device admin (TACACS+).
The methods you mention are used in device profiling for use with Network Access Control (802.1x and MAB) policy sets.
ā01-26-2021 05:01 AM
here is for cisco profiling (hope this is what you looking, if not please suggest)
ISE do support other vendors you need to Look matrix
ā01-26-2021 07:33 AM
Hello Balaji
Tahnks but This is not that i am looking for. I am looking to apply diferent tacacs command set, if the device is huawei or cisco.
I have read this
But i dont know how to start ...
ā01-26-2021 08:10 AM
When you create your NADs, assign each to a device group. Then create your TACACs policy sets with device group as the top level condition / selector. Then, within a given policy set, include your custom command sets etc. for that type of device.
Don't worry about the "profile" when creating the NAD if you are just using it for Device Admin. That profile is more to describe device capabilities for Authorization results for network access policy sets - not for device admin.
ā01-26-2021 08:46 AM
@Marvin Rhoads Thanks!! Yes i have already created as you described, But i dont need separate device per IP address. Because i only have one loopbak IP range with cisco and huawei mixed ... This is the problem.
So I need that ISE detect the vendor with (mac address CDP lldp or some way , i dont know) and use this condition to apply the correspondent auth policy for commands sets.
ā01-26-2021 09:49 AM
ISE cannot detect the vendor for purposes of device admin (TACACS+).
The methods you mention are used in device profiling for use with Network Access Control (802.1x and MAB) policy sets.
ā01-27-2021 09:11 AM
True, i have solved my problem "tricking" with the auth policies. Creating one profile for both vendors Cisco and Huawei, including both tacacs+ commands sets. thanks por support!
ā01-26-2021 07:34 AM
ISE does provide a inventory of what switches / routers it receives radius/tacacs requests from, but this is not vendor profiling!
Vendor profiling is meant to analyze what clients devices want to authenticate, not the network devices / routers in use.
maybe this guide will help ISE Profiling Design Guide
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide