<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ise policy to modify RADIUS-Access-Request sent to RADIUS server in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-policy-to-modify-radius-access-request-sent-to-radius-server/m-p/3948228#M456193</link>
    <description>&lt;P&gt;Org1 will be providing Cisco wireless infrastructure for a multitenant building.&amp;nbsp; Org1 needs to deliver Org2 802.1x wireless network in the new building. Org2 WLC will anchor a Org2 802.1x wlan from Org1 WLC.&amp;nbsp; 802.1x must successfully complete on Org1 foreign WLC before the client is tunneled to Org2 anchor WLC. Since Org1 will not have access to Org2 RADIUS servers, we decided to use eduroam TLRSs 802.1x.&amp;nbsp; Both Orgs are member of eduroam RADIUS federation.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Standard wireless profile for Org2 wireless devices does not include domain name “@org2.edu” in the user name.&amp;nbsp; Org2 does not want to change the stadard wireless profile.&amp;nbsp; However, this is required to use eduroam TLRS to authenticate against Org2 eduroam radius client servers.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Org1 has ISE deployment.&amp;nbsp; Can Org1 ISE create a policy to take EAPOL-Response/Identity from Org2 client and add “@org2.edu” before sending it out as RADIUS-Access-Request to eduroam TLRSs?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There is “RADIUS Server Sequences List &amp;gt; Advanced Attribute Setting tab” that I thought might be the answer to my problem, but it did not work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any help would be greatly appreciated.&lt;/P&gt;</description>
    <pubDate>Fri, 25 Oct 2019 16:03:14 GMT</pubDate>
    <dc:creator>sungy</dc:creator>
    <dc:date>2019-10-25T16:03:14Z</dc:date>
    <item>
      <title>ise policy to modify RADIUS-Access-Request sent to RADIUS server</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-policy-to-modify-radius-access-request-sent-to-radius-server/m-p/3948228#M456193</link>
      <description>&lt;P&gt;Org1 will be providing Cisco wireless infrastructure for a multitenant building.&amp;nbsp; Org1 needs to deliver Org2 802.1x wireless network in the new building. Org2 WLC will anchor a Org2 802.1x wlan from Org1 WLC.&amp;nbsp; 802.1x must successfully complete on Org1 foreign WLC before the client is tunneled to Org2 anchor WLC. Since Org1 will not have access to Org2 RADIUS servers, we decided to use eduroam TLRSs 802.1x.&amp;nbsp; Both Orgs are member of eduroam RADIUS federation.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Standard wireless profile for Org2 wireless devices does not include domain name “@org2.edu” in the user name.&amp;nbsp; Org2 does not want to change the stadard wireless profile.&amp;nbsp; However, this is required to use eduroam TLRS to authenticate against Org2 eduroam radius client servers.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Org1 has ISE deployment.&amp;nbsp; Can Org1 ISE create a policy to take EAPOL-Response/Identity from Org2 client and add “@org2.edu” before sending it out as RADIUS-Access-Request to eduroam TLRSs?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There is “RADIUS Server Sequences List &amp;gt; Advanced Attribute Setting tab” that I thought might be the answer to my problem, but it did not work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any help would be greatly appreciated.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Oct 2019 16:03:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-policy-to-modify-radius-access-request-sent-to-radius-server/m-p/3948228#M456193</guid>
      <dc:creator>sungy</dc:creator>
      <dc:date>2019-10-25T16:03:14Z</dc:date>
    </item>
    <item>
      <title>Re: ise policy to modify RADIUS-Access-Request sent to RADIUS server</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-policy-to-modify-radius-access-request-sent-to-radius-server/m-p/3948360#M456194</link>
      <description>&lt;P&gt;maybe that was too much info...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I need ISE to change radius username, i.e. sungy, to append domain name, i.e. sungy@acme.edu, before sending radius packet off to the eduroam server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;is this possible?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 25 Oct 2019 19:57:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-policy-to-modify-radius-access-request-sent-to-radius-server/m-p/3948360#M456194</guid>
      <dc:creator>sungy</dc:creator>
      <dc:date>2019-10-25T19:57:23Z</dc:date>
    </item>
    <item>
      <title>Re: ise policy to modify RADIUS-Access-Request sent to RADIUS server</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-policy-to-modify-radius-access-request-sent-to-radius-server/m-p/3948411#M456195</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the screenshot you have &lt;STRONG&gt;ADD RADIUS:User-Name = @org1.edu&lt;/STRONG&gt; under Modify Attributes in the Request.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have you tried changing this to &lt;STRONG&gt;UPDATE RADIUS:User-Name = @org1.edu&lt;/STRONG&gt; - this would hopefully change the radius username "outer-id" attribute for all org1 users to @org1.edu (that are then proxied to eduroam).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;hth&lt;BR /&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 25 Oct 2019 21:29:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-policy-to-modify-radius-access-request-sent-to-radius-server/m-p/3948411#M456195</guid>
      <dc:creator>andrewswanson</dc:creator>
      <dc:date>2019-10-25T21:29:30Z</dc:date>
    </item>
    <item>
      <title>Re: ise policy to modify RADIUS-Access-Request sent to RADIUS server</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-policy-to-modify-radius-access-request-sent-to-radius-server/m-p/3948504#M456196</link>
      <description>with Update option, you have to specify a string to update in user-name and what you want to update to. this would not work. i was hoping that it supported variables and i could use that to make it work, but I am not finding any detail document on "modify attribute in the request" section.&lt;BR /&gt;&lt;BR /&gt;[X]&lt;BR /&gt;</description>
      <pubDate>Sat, 26 Oct 2019 07:45:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-policy-to-modify-radius-access-request-sent-to-radius-server/m-p/3948504#M456196</guid>
      <dc:creator>sungy</dc:creator>
      <dc:date>2019-10-26T07:45:53Z</dc:date>
    </item>
    <item>
      <title>Re: ise policy to modify RADIUS-Access-Request sent to RADIUS server</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-policy-to-modify-radius-access-request-sent-to-radius-server/m-p/3949099#M456197</link>
      <description>&lt;P&gt;Have you tried removing the existing RADIUS Username and then adding a generic one like screenshot below?&lt;/P&gt;&lt;P&gt;hth&lt;/P&gt;&lt;P&gt;andy&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ise modify attribute.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/48129i32B8D93CC3F1EA73/image-size/large?v=v2&amp;amp;px=999" role="button" title="ise modify attribute.png" alt="ise modify attribute.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Oct 2019 11:03:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-policy-to-modify-radius-access-request-sent-to-radius-server/m-p/3949099#M456197</guid>
      <dc:creator>andrewswanson</dc:creator>
      <dc:date>2019-10-28T11:03:33Z</dc:date>
    </item>
    <item>
      <title>Re: ise policy to modify RADIUS-Access-Request sent to RADIUS server</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-policy-to-modify-radius-access-request-sent-to-radius-server/m-p/3949355#M456198</link>
      <description>&lt;P&gt;I am not looking for a specific user.&amp;nbsp; I need to be able to take any username in EAPOL-Response from endpoint and add "@org1.edu" at the end.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;lt;username&amp;gt; --&amp;gt; &amp;lt;username&amp;gt;@org1.edu&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yong&lt;/P&gt;</description>
      <pubDate>Mon, 28 Oct 2019 17:18:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-policy-to-modify-radius-access-request-sent-to-radius-server/m-p/3949355#M456198</guid>
      <dc:creator>sungy</dc:creator>
      <dc:date>2019-10-28T17:18:41Z</dc:date>
    </item>
    <item>
      <title>Re: ise policy to modify RADIUS-Access-Request sent to RADIUS server</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-policy-to-modify-radius-access-request-sent-to-radius-server/m-p/3949739#M456199</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My apologies if I misunderstood.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My previous post (typo - should have read as org2 and not org1) was looking at a way of org1 proxying wireless org2 client requests to eduroam TLRs - eduroam TLRs would then send the request to org2 RADIUS for authentication.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The method above would hopefully replace the original org2 username with an anonymised outer-id of anon@org2.edu&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;lt;username&amp;gt; --&amp;gt; anon@org2.edu&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The eduroam TLRs don't need to see the actual username - they just need to know to send the request to&amp;nbsp;org2.edu RADIUS for authentication.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 29 Oct 2019 10:00:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-policy-to-modify-radius-access-request-sent-to-radius-server/m-p/3949739#M456199</guid>
      <dc:creator>andrewswanson</dc:creator>
      <dc:date>2019-10-29T10:00:56Z</dc:date>
    </item>
    <item>
      <title>Re: ise policy to modify RADIUS-Access-Request sent to RADIUS server</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-policy-to-modify-radius-access-request-sent-to-radius-server/m-p/3949855#M456200</link>
      <description>&lt;P&gt;see attached.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;it looks like it replaced username is the radius access request.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yong&lt;/P&gt;</description>
      <pubDate>Tue, 29 Oct 2019 14:03:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-policy-to-modify-radius-access-request-sent-to-radius-server/m-p/3949855#M456200</guid>
      <dc:creator>sungy</dc:creator>
      <dc:date>2019-10-29T14:03:27Z</dc:date>
    </item>
    <item>
      <title>Re: ise policy to modify RADIUS-Access-Request sent to RADIUS server</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-policy-to-modify-radius-access-request-sent-to-radius-server/m-p/3949877#M456201</link>
      <description>&lt;P&gt;Interesting&amp;nbsp; - so it seems that it worked as expected (in that it removed the original username and added an anonymised one). Did you use an actual account to test this that should have passed authentication?&lt;/P&gt;&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 29 Oct 2019 14:42:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-policy-to-modify-radius-access-request-sent-to-radius-server/m-p/3949877#M456201</guid>
      <dc:creator>andrewswanson</dc:creator>
      <dc:date>2019-10-29T14:42:25Z</dc:date>
    </item>
  </channel>
</rss>

