cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
218
Views
0
Helpful
1
Replies

Cisco ISE Radius limit telnet access on switches to certain AD/LDAP us

mimosa09
Level 1
Level 1

I configured the 9400 switch for Radius access (Telnet) and created a basic policy set via Cisco ISE. I tested succesfully using my AD credentials.

This ISE policy set is configured to allow access to the switch when a user Telnets to it using the AD/LDAP credentials.

How can i limit the AD/LDAP to certain users? The Authurization Policy technically can let anyone log in with their AD credentials, but of course thats not the brightest idea

I though of creating local accounts in Cisco ISE, but i will prefer using AD credentials.

What will be the best approach to cover all ends?

Cisco ISE 3.1.0.518

1 Reply 1

Hi

 You can use Authorization policy. Search for "Configure TACACS Profile" on the link below and dont use Telnet in your network, always prefer SSH.

https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/200208-Configure-ISE-2-0-IOS-TACACS-Authentic.html#anc17 

Review Cisco Networking for a $25 gift card