Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
I've set up TACACS+ on ISE and it's working fine, for both authentication and authorization, except that I can't get external group restriction to work.I've tried this with LDAP authentication, by setting up an LDAP-based External Identity Source, wi...
Ah! Now I see it. I thought user access to the shell should be controlled at the authentication step, but it is bound to (exec) authorization instead.The command "aaa authorization exec default group tacacs+ local" did the trick. Now the unauthorized...
Maybe I am misunderstanding the terms, but how can authorization prevent a user from getting to the CLI prompt, since this is controlled by authentication?I just wanna clarify that I have no problem regarding group restriction at the commands authori...
I do understand that I can restrict groups in the authorization policy, as I'm already doing so. The problem is: I don't wanna enable every user in my domain to log in to the routers/switches (even though they wouldn't be able to issue a single comma...
Cisco says the Bug is fixed (status:Fixed) but sadly it still happening with me.
We will have to migrate this solution to another manufacturer, like blue coat or checkpoint, we're still evaluating the options.