AAA with TACACS+ and Cisco ISE: Securing Network Device Access on IOS-XE
New on ignaonline.com: AAA with TACACS+ and Cisco ISE
If you're still using a shared enable password across your Cisco switches, this one's for you.
Today's post is a full walkthrough of configuring TACACS+ AAA with Cisco ISE 3.3 on IOS-XE — covering everything from enabling aaa new-model safely to per-command authorization, full accounting, and ISE Device Admin policy sets with real CLI output throughout.
What's covered:
- TACACS+ vs RADIUS: why TACACS+ wins for device administration
- Securing local fallback before you enable AAA (so you don't lock yourself out)
- ISE command sets and shell profiles for admin vs NOC read-only access
- Verifying authentication with
test aaa groupanddebug tacacs - Troubleshooting the three most common issues (authorization rejected, fallback failing, missing accounting records)
- SSH hardening: removing CBC ciphers and weak MACs that trigger vulnerability scans
— Sarah Chen
Don't miss what's next. Subscribe to IGNA Online: