04-01-2020 04:55 AM
Hi
I am getting a bit confused with the term "ISE Device Administration via TACACS" and what it actually means.
Is it possible to use TACACS to authenticate ISE system administrators?
I.E. If more that one person has the authority to perform ISE system administration tasks is it possible to have them use their network TACACS account to log onto the ISE, to perform admin tasks, rather than use a local admin account?
I am amazed I actually have to ask this but I cannot find a straight forward answer.
Solved! Go to Solution.
04-01-2020 08:18 AM
Hi,
That refers to using ISE as TACACS server, for your network devices administration (when you connect to your network devices via SSH let's say, the NAD authenticates you, authorises you and accounts for you agains the TACACS service running on ISE) . It does not refer to ISE admin users being authenticated via an ISE integration with another TACACS server.
Regards,
Cristian Matei.
04-01-2020 05:05 AM - edited 04-01-2020 05:06 AM
Hi
ISE requires a Device Administration license to use TACACS+.
There are two types of administrators for device administration:
Device Administrator
ISE Administrator
The device administrator is the user who logs into the network devices such as switches, wireless access points, routers, and gateways, (normally through SSH), in order to perform the configuration and maintenance of the administered devices. The ISE administrator logs into ISE to configure and coordinate the devices that a device administrator logs in to.
"ISE Device Administration via TACACS" is for device administration.
Is it possible to use TACACS to authenticate ISE system administrators?
Yes, depending on the version of ISE - Administration > Identity Management > External Identity Sources > Active Directory.
hope this helps
04-01-2020 09:02 AM
Hi thanks
So just to confirm (for my sanity),
it is NOT possible to authenticate ISE admin users using seperate individual user accounts hosted on an external TACACS server?
04-01-2020 08:18 AM
Hi,
That refers to using ISE as TACACS server, for your network devices administration (when you connect to your network devices via SSH let's say, the NAD authenticates you, authorises you and accounts for you agains the TACACS service running on ISE) . It does not refer to ISE admin users being authenticated via an ISE integration with another TACACS server.
Regards,
Cristian Matei.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide