QuestionQ38

Policy Enforcement

An administrator must provide users with the same level of access to network devices when they log in using TACACS+. However, the administrator must limit certain commands according to one of three user roles, each requiring different commands.

How can this be achieved without creating too many objects in Cisco ISE?

Explanation

A TACACS+ shell profile controls the initial login session and privilege level, while command sets enforce which commands a device administrator may execute. A single shared shell profile can provide the common access level, and separate command sets can implement the distinct command permissions required by the three roles. Cisco ISE authorization policies support one shell profile with multiple command sets.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!