<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE LDAP to MFA server in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-ldap-to-mfa-server/m-p/3988155#M455507</link>
    <description>&lt;P&gt;I don't think this is possible integration point. You can link together like DUO via a RADIUS proxy server like here but not via LDAP that i know of unless your RADIUS proxy can integrate&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/security-documents/how-to-deploy-ise-device-admin-with-duo-mfa/ta-p/3821231" target="_blank"&gt;https://community.cisco.com/t5/security-documents/how-to-deploy-ise-device-admin-with-duo-mfa/ta-p/3821231&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I also tag my coworker&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/113005"&gt;@hslai&lt;/a&gt;&amp;nbsp;to see if she can take a look&lt;/P&gt;</description>
    <pubDate>Fri, 22 Nov 2019 23:02:35 GMT</pubDate>
    <dc:creator>Jason Kunst</dc:creator>
    <dc:date>2019-11-22T23:02:35Z</dc:date>
    <item>
      <title>ISE LDAP to MFA server</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ldap-to-mfa-server/m-p/3986708#M455506</link>
      <description>&lt;P&gt;I am in the process of trying to setup an LDAP connection to a MFA proxy server.&amp;nbsp; I am able to test bind the connection and can see the connection on the MFA proxy server.&amp;nbsp; The issue is when I try to login to a Nexus switch I have setup in ISE using tacacs+ for device admin.&amp;nbsp; I never see anything from ISE on the MFA server when this request is done.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is what I am seeing in ISE:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;TABLE border="0" cellpadding="3"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;13005&lt;/TD&gt;&lt;TD&gt;Received TACACS+ Authorization Request&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;15049&lt;/TD&gt;&lt;TD&gt;Evaluating Policy Group&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;15008&lt;/TD&gt;&lt;TD&gt;Evaluating Service Selection Policy&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;15048&lt;/TD&gt;&lt;TD&gt;Queried PIP - Network Access.Protocol&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;15048&lt;/TD&gt;&lt;TD&gt;Queried PIP - DEVICE.Device Type&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;15041&lt;/TD&gt;&lt;TD&gt;Evaluating Identity Policy&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;15013&lt;/TD&gt;&lt;TD&gt;Selected Identity Source - MFA_test&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;24031&lt;/TD&gt;&lt;TD&gt;Sending request to primary LDAP server - MFA_test&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;24016&lt;/TD&gt;&lt;TD&gt;Looking up user in LDAP Server - MFA_test&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;24019&lt;/TD&gt;&lt;TD&gt;LDAP connection error was encountered - MFA_test (&lt;IMG src="https://172.23.10.185/admin/css/images/alarm_n_16.png" border="0" title="Step latency=45001ms" /&gt; Step latency=45001ms)&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;22059&lt;/TD&gt;&lt;TD&gt;The advanced option that is configured for process failure is used&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;22062&lt;/TD&gt;&lt;TD&gt;The 'Drop' advanced option is configured in case of a failed authentication request&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am still learning so I am sure there is something I am missing.&amp;nbsp; Are there any other tools on ISe that would assist with investigating this?&amp;nbsp; I am working on setting up sniffer so I don't have that info yet.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Nov 2019 16:18:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ldap-to-mfa-server/m-p/3986708#M455506</guid>
      <dc:creator>cscotty1972</dc:creator>
      <dc:date>2019-11-20T16:18:40Z</dc:date>
    </item>
    <item>
      <title>Re: ISE LDAP to MFA server</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ldap-to-mfa-server/m-p/3988155#M455507</link>
      <description>&lt;P&gt;I don't think this is possible integration point. You can link together like DUO via a RADIUS proxy server like here but not via LDAP that i know of unless your RADIUS proxy can integrate&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/security-documents/how-to-deploy-ise-device-admin-with-duo-mfa/ta-p/3821231" target="_blank"&gt;https://community.cisco.com/t5/security-documents/how-to-deploy-ise-device-admin-with-duo-mfa/ta-p/3821231&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I also tag my coworker&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/113005"&gt;@hslai&lt;/a&gt;&amp;nbsp;to see if she can take a look&lt;/P&gt;</description>
      <pubDate>Fri, 22 Nov 2019 23:02:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ldap-to-mfa-server/m-p/3988155#M455507</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2019-11-22T23:02:35Z</dc:date>
    </item>
    <item>
      <title>Re: ISE LDAP to MFA server</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ldap-to-mfa-server/m-p/3989209#M455508</link>
      <description>&lt;P&gt;Please note MFA may need longer timeouts because it usually waits for the user to respond (e.g. generating a new one-time password).&lt;/P&gt;
&lt;P&gt;A couple of things to check:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;ISE able to connect to the MFA proxy server via LDAP
&lt;UL&gt;
&lt;LI&gt;In ISE, verify the test connection&lt;/LI&gt;
&lt;LI&gt;In MFA proxy, check the connection logs&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;LDAP server timeouts
&lt;UL&gt;
&lt;LI&gt;In ISE, each LDAP server connection may have its own timeout and 99 seconds max&lt;/LI&gt;
&lt;LI&gt;In MFA proxy, check the vendor doc.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Nov 2019 22:27:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ldap-to-mfa-server/m-p/3989209#M455508</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2019-11-25T22:27:27Z</dc:date>
    </item>
  </channel>
</rss>

