<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Radius Attribute forwarding in ISE in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/radius-attribute-forwarding-in-ise/m-p/3063956#M22867</link>
    <description>&lt;P&gt;Hello&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I'm trying to forward a radius attribute (cisco-ip-pool-definition) &amp;nbsp;from an external identity source to my CISCO ASA vpn device.&lt;/P&gt;
&lt;P&gt;I can see in the TCP Dump that the attribute is received from my external Radius server,&lt;/P&gt;
&lt;P&gt;but I &amp;nbsp;am not able to create an authorization policy that matches and forwards this attribute.&lt;/P&gt;
&lt;P&gt;In the configuration of the External Identity source, in the authorization tab I have Cisco.Secure.ID.&lt;/P&gt;
&lt;P&gt;How can &amp;nbsp;I match this attribute in an authorization policy ?&lt;/P&gt;
&lt;P&gt;Thanks in advance for your help&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 07:42:38 GMT</pubDate>
    <dc:creator>a.ascione</dc:creator>
    <dc:date>2019-03-11T07:42:38Z</dc:date>
    <item>
      <title>Radius Attribute forwarding in ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-attribute-forwarding-in-ise/m-p/3063956#M22867</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I'm trying to forward a radius attribute (cisco-ip-pool-definition) &amp;nbsp;from an external identity source to my CISCO ASA vpn device.&lt;/P&gt;
&lt;P&gt;I can see in the TCP Dump that the attribute is received from my external Radius server,&lt;/P&gt;
&lt;P&gt;but I &amp;nbsp;am not able to create an authorization policy that matches and forwards this attribute.&lt;/P&gt;
&lt;P&gt;In the configuration of the External Identity source, in the authorization tab I have Cisco.Secure.ID.&lt;/P&gt;
&lt;P&gt;How can &amp;nbsp;I match this attribute in an authorization policy ?&lt;/P&gt;
&lt;P&gt;Thanks in advance for your help&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 07:42:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-attribute-forwarding-in-ise/m-p/3063956#M22867</guid>
      <dc:creator>a.ascione</dc:creator>
      <dc:date>2019-03-11T07:42:38Z</dc:date>
    </item>
    <item>
      <title>Oh this is a classic. I had</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-attribute-forwarding-in-ise/m-p/3063957#M22869</link>
      <description>&lt;P&gt;Oh this is a classic. I had the same problem and the solution is not documented by Cisco anywhere.&lt;/P&gt;
&lt;P&gt;Here is the answer:&lt;/P&gt;
&lt;P&gt;Your external radius server has to return a new&amp;nbsp;CiscoAVPair&amp;nbsp;attribute in the format:&lt;/P&gt;
&lt;P&gt;CiscoAVPair:ACS:cisco-ip-pool-definition&lt;/P&gt;
&lt;P&gt;The key thing in that Cisco AVPair is the prefix 'ACS' ... yes. I died laughing too...&lt;/P&gt;
&lt;P&gt;The final value shown above (cisco-ip-pool-definition) can be replaced with anything and it does not relate to any IETF radius attribute - it's just a label.&amp;nbsp; Just make sure that the label is the same as the value you enter into the Authorization Tab under Radius Token Identity Services in ISE GUI.&lt;/P&gt;
&lt;P&gt;Let's say your Radius Token Identity Service is called EXTRADIUS, then in your actual Policies, you will refer to the returned value as&lt;/P&gt;
&lt;P&gt;EXTRADIUS:cisco-ip-pool-definition&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;cheers&lt;/P&gt;</description>
      <pubDate>Wed, 17 May 2017 02:16:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-attribute-forwarding-in-ise/m-p/3063957#M22869</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2017-05-17T02:16:57Z</dc:date>
    </item>
  </channel>
</rss>

