Set up an Identity Service Engine (ISE) for TACACS+

Declare RADKit as a Network Device

A Network Device needs to be declared on ISE to authorize RADKit Service to place TACACS+ requests.

On ISE, navigate to Administration > System > Deployment. Select the ISE server and click Edit.

../../_images/external_sources_ISE_deployment_nodes.png

Enable Device Admin Service and click Save.

../../_images/external_sources_ISE_enable_admin_service.png

Now add RADKit as an ISE Network Device. Navigate to Administration > Network Resources > Network Device.

../../_images/external_sources_ISE_network_devices.png

Select + Add. In the new screen, configure the Name, IP address of RADKit, and TACACS+ Shared Secret. Select Save.

../../_images/external_sources_ISE_add_network_device_1.png ../../_images/external_sources_ISE_add_network_device_2.png

Create a RADKit administrator on ISE

An ISE identity must be configured to represent an administrator. Create as many as needed.

Navigate to Administration > Identity Management > Identities > Users.

../../_images/external_sources_ISE_identities.png

Select + Add. Configure the fields Username, Login, and Password, then select Save.

../../_images/external_sources_ISE_add_identity.png

Configure a TACACS+ policy

In this phase, ISE is configured to return TACACS+ ACCESS_ACCEPT.

Navigate to Work Centers > Device Administration. Select > against the Policy Set of your choice.

../../_images/external_sources_ISE_tacacs_policy.png

Scroll down to the Authorization Policies and add a new Authorization Policy by selecting the gear icon and choosing Insert new role above.

../../_images/external_sources_ISE_insert_new_role.png

Select + in the Condition of the new policy to edit the condition. Drag and drop Network_Access_Authentication_Passed from the left screen to the Editor. Select Use.

../../_images/external_sources_ISE_conditions_studio.png

Under Shell Profile select +.

../../_images/external_sources_ISE_shell_profile.png

Name the Shell Profile and click Save.

../../_images/external_sources_ISE_add_shell_profile.png

Save the Policy.

../../_images/external_sources_ISE_save_policy.png

Login to RADKit with an ISE-bound administrator

In order to login to RADKit, use the format <External TACACS+ Server>#<username>.

../../_images/external_sources_tacacs_admin_login.png

Check ISE Live Logs

Verify successful authentication on ISE.

Navigate to Operations > TACACS > Live Logs, and confirm that RADKit was able to successfully authenticate the administrator with ISE.

../../_images/external_sources_ISE_live_logs.png