cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1493
Views
5
Helpful
3
Replies

Usings TACACS to authenticate ISE system administrators

Scott Gillies
Level 1
Level 1

Hi

I am getting a bit confused with the term "ISE Device Administration via TACACS" and what it actually means.

 

Is it possible to use TACACS to authenticate ISE system administrators?

 

I.E. If more that one person has the authority to perform ISE system administration tasks is it possible to have them use their network TACACS account to log onto the ISE, to perform admin tasks, rather than use a local admin account?

 

I am amazed I actually have to ask this but I cannot find a straight forward answer.

1 Accepted Solution

Accepted Solutions

Cristian Matei
VIP Alumni
VIP Alumni

Hi,

 

   That refers to using ISE as TACACS server, for your network devices administration (when you connect to your network devices via SSH let's say, the NAD authenticates you, authorises you and accounts for you agains the TACACS service running on ISE) . It does not refer to ISE admin users being authenticated via an ISE integration with another TACACS server.

 

Regards,

Cristian Matei.

View solution in original post

3 Replies 3

omz
VIP Alumni
VIP Alumni

Hi

 

ISE requires a Device Administration license to use TACACS+.

There are two types of administrators for device administration:

  • Device Administrator

  • ISE Administrator

The device administrator is the user who logs into the network devices such as switches, wireless access points, routers, and gateways, (normally through SSH), in order to perform the configuration and maintenance of the administered devices. The ISE administrator logs into ISE to configure and coordinate the devices that a device administrator logs in to.

https://www.cisco.com/c/en/us/td/docs/security/ise/2-1/admin_guide/b_ise_admin_guide_21/b_ise_admin_guide_20_chapter_0100010.html

"ISE Device Administration via TACACS" is for device administration.

 

Is it possible to use TACACS to authenticate ISE system administrators? 

Yes, depending on the version of ISE - Administration > Identity Management > External Identity Sources > Active Directory.

 

hope this helps

 

Hi thanks

So just to confirm (for my sanity),

it is NOT possible to authenticate ISE admin users using seperate individual user accounts hosted on an external TACACS server?

Cristian Matei
VIP Alumni
VIP Alumni

Hi,

 

   That refers to using ISE as TACACS server, for your network devices administration (when you connect to your network devices via SSH let's say, the NAD authenticates you, authorises you and accounts for you agains the TACACS service running on ISE) . It does not refer to ISE admin users being authenticated via an ISE integration with another TACACS server.

 

Regards,

Cristian Matei.

Review Cisco Networking for a $25 gift card