cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1594
Views
0
Helpful
3
Replies

ISE command set not working as expected

mohanconnects
Level 1
Level 1

Hello,

 

I trying out ISE device administration, wanted to restrict for a user to send command 'username', so below is how I set TACACS+ profile and command sets.

 

TACACS+ profile

priv-lvl=4

 

command set

commandset.png

 

 

But when I tried to login, command username successfully get passed. Am I configuring it wrong, please guide.

Below username command actually sent without AAA error.

 

nexus88# config t
Enter configuration commands, one per line. End with CNTL/Z.


nexus88(config)# username ISE
warning: password for user:ISE not set. S/he may not be able to login
user steve does not have domain access to config Mo, class aaaUser


nexus88(config)# do sh ip int brief
Error: AAA authorization failed AAA_AUTHOR_STATUS_METHOD=16(0x10)


nexus88(config)#

 

Thanks,

Mohan

 

3 Replies 3

Cristian Matei
VIP Alumni
VIP Alumni

Hi,

 

    You gave not too much info to help out. Check that both Nexus and ISE are configured properly first. Look here, in the Nexus section:

 

https://community.cisco.com/t5/security-documents/cisco-ise-device-administration-prescriptive-deployment-guide/ta-p/3738365#toc-hId-1977002717

 

Regards,

Cristian Matei.

Thanks Cristian Matei

As Christian has mentioned you have not provided enough information on the issue you are facing. Check the TACACS live logs to see what policy and command set is being used.

--
Please remember to select a correct answer and rate helpful posts
Review Cisco Networking products for a $25 gift card