<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic The bug was originally in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-admin-access-authentication-to-radius-token-server/m-p/2213392#M126612</link>
    <description>&lt;P&gt;The bug was originally reported by me &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 15 Jan 2015 20:54:41 GMT</pubDate>
    <dc:creator>cciesec2011</dc:creator>
    <dc:date>2015-01-15T20:54:41Z</dc:date>
    <item>
      <title>ISE Admin Access Authentication to RADIUS Token Server</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-admin-access-authentication-to-radius-token-server/m-p/2213387#M126336</link>
      <description>&lt;DIV&gt;&lt;P&gt;Hi all!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I want to use an External&amp;nbsp; RADIUS Token Server for ISE Admin Access Authentication and Authorization. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Authentication works, but how do I map the users&amp;nbsp; to Admin Groups? Is there a way&amp;nbsp; to map a returned RADIUS Attribute&amp;nbsp; (IETF "Class" or Cisco-AVPair "CiscoSecure-Group-Id") to an Admin Group?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="min-height: 8pt; height: 8pt;"&gt;Thanks in advance,&lt;/P&gt;&lt;P&gt;Michael Langerreiter&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Mon, 11 Mar 2019 03:35:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-admin-access-authentication-to-radius-token-server/m-p/2213387#M126336</guid>
      <dc:creator>Michael Langerreiter</dc:creator>
      <dc:date>2019-03-11T03:35:04Z</dc:date>
    </item>
    <item>
      <title>ISE Admin Access Authentication to RADIUS Token Server</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-admin-access-authentication-to-radius-token-server/m-p/2213388#M126406</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Michael,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-top: px; margin-bottom: px; line-height: normal;"&gt;As you are using external radius token server for ISE admin access authentication and Authorization, you need to create a admin group on radius server and assign the user to this group whom you want to give full permission. When they will be authenticated by ISE they will get full rights automatically&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Jun 2013 08:52:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-admin-access-authentication-to-radius-token-server/m-p/2213388#M126406</guid>
      <dc:creator>Ravi Singh</dc:creator>
      <dc:date>2013-06-25T08:52:03Z</dc:date>
    </item>
    <item>
      <title>Hi Michael,Just wondering if</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-admin-access-authentication-to-radius-token-server/m-p/2213389#M126448</link>
      <description>&lt;P&gt;Hi Michael,&lt;/P&gt;&lt;P&gt;Just wondering if you were successful to sort this out? I have a similar requirement to achieve. If you have sorted this out, please let me know what has to be done. I don't see any specific documents explaining this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Vivek&lt;/P&gt;</description>
      <pubDate>Thu, 14 Aug 2014 05:46:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-admin-access-authentication-to-radius-token-server/m-p/2213389#M126448</guid>
      <dc:creator>Vivek Ganapathi</dc:creator>
      <dc:date>2014-08-14T05:46:31Z</dc:date>
    </item>
    <item>
      <title>Hi Michael You have to add</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-admin-access-authentication-to-radius-token-server/m-p/2213390#M126499</link>
      <description>&lt;P&gt;Hi Michael&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You have to add each and every ISE Admin-User locally, and specify the external Radius-Token users to be external.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI class="pBu1_Bullet1"&gt;You do not need to specify any particular external administrator groups for the administrator.&lt;/LI&gt;&lt;LI class="pBu1_Bullet1"&gt;You must configure the same username in both the external identity store and the local Cisco ISE database.&lt;/LI&gt;&lt;/UL&gt;&lt;HR noshade="noshade" /&gt;&lt;P class="pSF_StepFirst"&gt;&lt;B&gt;Step 1&lt;/B&gt;&lt;IMG alt="" border="0" height="2" src="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" width="5" /&gt; Choose Administration &amp;gt; System &amp;gt; Admin Access &lt;B class="cBold"&gt; &amp;gt; Administrators &amp;gt; Local Administrators.&lt;/B&gt;&lt;/P&gt;&lt;P class="pSN_StepNext"&gt;&lt;B&gt;Step 2&lt;/B&gt;&lt;IMG alt="" border="0" height="2" src="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" width="5" /&gt; Follow the guidelines at &lt;A href="http://www.cisco.com/c/en/us/td/docs/security/ise/1-1/user_guide/ise11_user_guide/ise_man_identities.html#70253"&gt;&lt;U&gt;&lt;FONT color="#0066cc"&gt;Creating a New Cisco ISE Administrator&lt;/FONT&gt;&lt;/U&gt;&lt;/A&gt; to ensure that the administrator username on the external RSA identity store is also present in Cisco ISE. Be sure to click the &lt;B class="cCN_CmdName"&gt;External&lt;/B&gt; option under Password.&lt;/P&gt;&lt;P class="pSN_StepNext"&gt;&lt;B&gt;Step 3&lt;/B&gt;&lt;IMG alt="" border="0" height="2" src="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" width="5" /&gt; Click &lt;B class="cCN_CmdName"&gt; Save&lt;/B&gt; .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Jan 2015 09:47:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-admin-access-authentication-to-radius-token-server/m-p/2213390#M126499</guid>
      <dc:creator>jsteffensen</dc:creator>
      <dc:date>2015-01-15T09:47:09Z</dc:date>
    </item>
    <item>
      <title>ISE 1.3 does have an bug:</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-admin-access-authentication-to-radius-token-server/m-p/2213391#M126568</link>
      <description>&lt;P&gt;&lt;SPAN style="font-size: 12px;"&gt;ISE 1.3 does have an bug: Authentication failed due to zero RBAC Groups.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 12px;"&gt;Cisco Bug: CSCur76447 - External Admin access fails with shadow user &amp;amp; Radius token&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 12px;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 12px;"&gt;Last Modified&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV class="bugDtailsWrapper"&gt;&lt;DIV class="dataCont"&gt;&lt;DIV class="dataValue"&gt;&lt;SPAN style="font-size: 12px;"&gt;Nov 25, 2014&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;
&lt;DIV class="dataCont"&gt;&lt;H2 class="dataLable"&gt;&lt;SPAN style="font-size: 12px;"&gt;Product&lt;/SPAN&gt;&lt;/H2&gt;
&lt;DIV class="dataValue"&gt;&lt;SPAN style="font-size: 12px;"&gt;Cisco Identity Services Engine (ISE) 3300 Series Appliances&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;
&lt;DIV class="dataContKnown"&gt;&lt;H2 class="dataLable"&gt;&lt;SPAN style="font-size: 12px;"&gt;Known Affected Releases&lt;/SPAN&gt;&lt;/H2&gt;
&lt;DIV class="bugknownAffect" id="bugknownAffectedD"&gt;&lt;SPAN style="font-size: 12px;"&gt;1.3(0.876)&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;
&lt;DIV class="dataCont"&gt;&lt;H2 class="dataLable"&gt;&lt;SPAN style="font-size: 12px;"&gt;Description &lt;SPAN class="dataLablespan"&gt;(partial)&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H2&gt;
&lt;DIV class="dataValue"&gt;
&lt;PRE class="sympText"&gt;
&lt;SPAN style="font-size: 12px;"&gt;&lt;B&gt;Symptom:&lt;/B&gt;
ISE 1.3 RBAC fails with shadow user &amp;amp; Radius token
Operations &amp;gt; Reports &amp;gt; Deployment Status &amp;gt; Administrator Logins report shows
Authentication failed due to zero RBAC Groups

&lt;B&gt;Conditions:&lt;/B&gt;
RBAC with shadow user &amp;amp; Radius token&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 12px;"&gt;&lt;!-- preview messaging Section--&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV class="previewMessaging"&gt;&lt;DIV class="loginSection"&gt;&lt;DIV class="bugDetaiLink" id="previewMsgSection"&gt;&lt;SPAN style="font-size: 12px;"&gt;&lt;SPAN id="bugDetailspan"&gt;&lt;A class="bugDetaiLink" href="https://tools.cisco.com/bugsearch/bug/CSCur76447/?referring_site=bugquickviewclick" rel="nofollow"&gt;&lt;U&gt;&lt;FONT color="#0066cc"&gt;View Bug Details in Bug Search Tool&lt;/FONT&gt;&lt;/U&gt;&lt;/A&gt; &lt;/SPAN&gt; &lt;SPAN class="iconLock"&gt;&lt;IMG alt="Login Required" src="https://www.cisco.com/etc/designs/cdc/fw/i/icon_lock_small.png" /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;
&lt;DIV class="bugDetaiLinkInner" id="openPanel"&gt;&lt;SPAN style="font-size: 12px;"&gt;&lt;A&gt;&lt;U&gt;&lt;FONT color="#0066cc"&gt;Why Is Login Required?&lt;/FONT&gt;&lt;/U&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;
&lt;DIV id="panel" style="display: none;"&gt;&lt;DIV class="paneltext"&gt;&lt;SPAN style="font-size: 12px;"&gt;Bug details contain sensitive information and therefore require a Cisco.com account to be viewed.&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="panelbutDiv"&gt;&lt;SPAN style="font-size: 12px;"&gt;&lt;BUTTON class="closeButton" id="close" name="close" title="close"&gt;&lt;/BUTTON&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;
&lt;DIV class="hline"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="loginBugSection"&gt;&lt;H3 class="listHeading"&gt;&lt;SPAN style="font-size: 12px;"&gt;Bug Details Include&lt;/SPAN&gt;&lt;/H3&gt;
&lt;UL class="bugdetailList"&gt;&lt;LI&gt;&lt;SPAN style="font-size: 12px;"&gt;Full Description (including symptoms, conditions and workarounds)&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-size: 12px;"&gt;Status&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-size: 12px;"&gt;Severity&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-size: 12px;"&gt;Known Fixed Releases&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-size: 12px;"&gt;Related Community Discussions&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-size: 12px;"&gt;Number of Related Support Cases&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/DIV&gt;
&lt;DIV class="message"&gt;&lt;SPAN style="font-size: 12px;"&gt;Bug information is viewable for customers and partners who have a service contract. Registered users can view up to 200 bugs per month without a service contract.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;
&lt;DIV class="previewMessaging"&gt;&lt;DIV class="message"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;
&lt;DIV class="previewMessaging"&gt;&lt;DIV class="message"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 15 Jan 2015 09:54:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-admin-access-authentication-to-radius-token-server/m-p/2213391#M126568</guid>
      <dc:creator>jsteffensen</dc:creator>
      <dc:date>2015-01-15T09:54:45Z</dc:date>
    </item>
    <item>
      <title>The bug was originally</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-admin-access-authentication-to-radius-token-server/m-p/2213392#M126612</link>
      <description>&lt;P&gt;The bug was originally reported by me &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Jan 2015 20:54:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-admin-access-authentication-to-radius-token-server/m-p/2213392#M126612</guid>
      <dc:creator>cciesec2011</dc:creator>
      <dc:date>2015-01-15T20:54:41Z</dc:date>
    </item>
  </channel>
</rss>

