<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re:Problem with getting LDAP attributes on ISE when EAPChaining  in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/problem-with-getting-ldap-attributes-on-ise-when-eapchaining-is/m-p/2056048#M200292</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It's not LDAP group based, just additional attribute WLANProfile which returns to which VLAN should the user be connected.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the it matches ie Employees, then access is granted. &lt;/P&gt;&lt;P&gt;This works fine when EAP Chaining is disabled in protocols, when I enable it stops matching.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 10 Oct 2012 07:31:48 GMT</pubDate>
    <dc:creator>Karel Navratil</dc:creator>
    <dc:date>2012-10-10T07:31:48Z</dc:date>
    <item>
      <title>Problem with getting LDAP attributes on ISE when EAPChaining is enabled</title>
      <link>https://community.cisco.com/t5/network-access-control/problem-with-getting-ldap-attributes-on-ise-when-eapchaining-is/m-p/2056044#M200284</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;has anybody and idea how to set LDAP attributes retrieval with EAPChaining enabled?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My scenarios is:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- user with AnyConnect (EAP-FAST) connects to WLAN and sends it's credentials&lt;/P&gt;&lt;P&gt;- ISE authenticates username and password against Active Directory&lt;/P&gt;&lt;P&gt;- ISE should check if the same userid contains in LDAP Directory (not AD, different store) special attribute which controls access to our WLAN&lt;/P&gt;&lt;P&gt;- If the attribute is found, then authorization profile is matched.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This works when I disable EAP-Chaining Policy -&amp;gt; Policy Elements -&amp;gt; Results -&amp;gt; Authentication -&amp;gt; Allowed Protocols ...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In logs I've found that the user was not found in LDAP, but the user exists.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Maybe the workaround can be if just user from EAPChaining is used and not also the hostname, then it could match. But I cannot find any similar parameter which returns only user.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does anybody have an idea how to solve this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;K.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 02:39:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problem-with-getting-ldap-attributes-on-ise-when-eapchaining-is/m-p/2056044#M200284</guid>
      <dc:creator>Karel Navratil</dc:creator>
      <dc:date>2019-03-11T02:39:16Z</dc:date>
    </item>
    <item>
      <title>Re:Problem with getting LDAP attributes on ISE when EAPChaining</title>
      <link>https://community.cisco.com/t5/network-access-control/problem-with-getting-ldap-attributes-on-ise-when-eapchaining-is/m-p/2056045#M200285</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This seems like a corner issue, because eap-fast with ldap is not supported. LDAP as the protocol doest support hash based authentication hence the reason ISE is failing to hit the ldap database.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Referencing acs material since ise docs are not complete:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_system/5.2/user/guide/eap_pap_phase.html&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support Android App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Oct 2012 14:55:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problem-with-getting-ldap-attributes-on-ise-when-eapchaining-is/m-p/2056045#M200285</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-10-09T14:55:18Z</dc:date>
    </item>
    <item>
      <title>Re:Problem with getting LDAP attributes on ISE when EAPChaining</title>
      <link>https://community.cisco.com/t5/network-access-control/problem-with-getting-ldap-attributes-on-ise-when-eapchaining-is/m-p/2056046#M200288</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm not using LDAP to authenticate just as additional attribute retrieval. Authentication is done via Active Directory.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just want to have control who can access our WLAN and who not and take advantage of EAP-Chaining&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;K.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Oct 2012 14:58:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problem-with-getting-ldap-attributes-on-ise-when-eapchaining-is/m-p/2056046#M200288</guid>
      <dc:creator>Karel Navratil</dc:creator>
      <dc:date>2012-10-09T14:58:55Z</dc:date>
    </item>
    <item>
      <title>Re:Problem with getting LDAP attributes on ISE when EAPChaining</title>
      <link>https://community.cisco.com/t5/network-access-control/problem-with-getting-ldap-attributes-on-ise-when-eapchaining-is/m-p/2056047#M200290</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you have your ldap group configured as an authorization condition?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I remember an topic on the forums where the retrieval is done when the authorization rule has the ldap group as a condition. Then ise will attempt the lookup.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support Android App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Oct 2012 01:30:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problem-with-getting-ldap-attributes-on-ise-when-eapchaining-is/m-p/2056047#M200290</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-10-10T01:30:45Z</dc:date>
    </item>
    <item>
      <title>Re:Problem with getting LDAP attributes on ISE when EAPChaining</title>
      <link>https://community.cisco.com/t5/network-access-control/problem-with-getting-ldap-attributes-on-ise-when-eapchaining-is/m-p/2056048#M200292</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It's not LDAP group based, just additional attribute WLANProfile which returns to which VLAN should the user be connected.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the it matches ie Employees, then access is granted. &lt;/P&gt;&lt;P&gt;This works fine when EAP Chaining is disabled in protocols, when I enable it stops matching.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Oct 2012 07:31:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problem-with-getting-ldap-attributes-on-ise-when-eapchaining-is/m-p/2056048#M200292</guid>
      <dc:creator>Karel Navratil</dc:creator>
      <dc:date>2012-10-10T07:31:48Z</dc:date>
    </item>
    <item>
      <title>Re:Problem with getting LDAP attributes on ISE when EAPChaining</title>
      <link>https://community.cisco.com/t5/network-access-control/problem-with-getting-ldap-attributes-on-ise-when-eapchaining-is/m-p/2056049#M200294</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Any ideas here?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 14 Oct 2012 21:20:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problem-with-getting-ldap-attributes-on-ise-when-eapchaining-is/m-p/2056049#M200294</guid>
      <dc:creator>Karel Navratil</dc:creator>
      <dc:date>2012-10-14T21:20:36Z</dc:date>
    </item>
  </channel>
</rss>

