<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: External RADIUS attribute in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/external-radius-attribute/m-p/3798083#M485295</link>
    <description>&lt;P&gt;If you define it as an External RADIUS server then&amp;nbsp; you should be able to consume attributes sent from the the RADIUS server in the authorization phase.&amp;nbsp; Based on those authorization phase matches you should be able to set a VLAN assignment.&amp;nbsp; It wouldn't be a CoA, it would be part of the initial authentication/authorization.&amp;nbsp; In the advanced attributes settings of the RADIUS server sequence you can tell ISE to "On Access-Accept, continue to Authorization Policy".&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I haven't tested this, but in theory that is how it is supposed to work.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 08 Feb 2019 19:47:26 GMT</pubDate>
    <dc:creator>paul</dc:creator>
    <dc:date>2019-02-08T19:47:26Z</dc:date>
    <item>
      <title>External RADIUS attribute</title>
      <link>https://community.cisco.com/t5/network-access-control/external-radius-attribute/m-p/3797980#M485291</link>
      <description>&lt;P&gt;We have a custom build of FreeRADIUS that does some unique username based hashing for VLAN assignment.&amp;nbsp; I'd like to be able to utilize ISE as the authentication and authorization server, but have it send the username to an external RADIUS server, then "consume" the VLAN ID sent from that external server and send it as a CoA to the NAD.&amp;nbsp; Is this possible?&lt;/P&gt;</description>
      <pubDate>Fri, 08 Feb 2019 17:12:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/external-radius-attribute/m-p/3797980#M485291</guid>
      <dc:creator>blandrum</dc:creator>
      <dc:date>2019-02-08T17:12:31Z</dc:date>
    </item>
    <item>
      <title>Re: External RADIUS attribute</title>
      <link>https://community.cisco.com/t5/network-access-control/external-radius-attribute/m-p/3798083#M485295</link>
      <description>&lt;P&gt;If you define it as an External RADIUS server then&amp;nbsp; you should be able to consume attributes sent from the the RADIUS server in the authorization phase.&amp;nbsp; Based on those authorization phase matches you should be able to set a VLAN assignment.&amp;nbsp; It wouldn't be a CoA, it would be part of the initial authentication/authorization.&amp;nbsp; In the advanced attributes settings of the RADIUS server sequence you can tell ISE to "On Access-Accept, continue to Authorization Policy".&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I haven't tested this, but in theory that is how it is supposed to work.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Feb 2019 19:47:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/external-radius-attribute/m-p/3798083#M485295</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2019-02-08T19:47:26Z</dc:date>
    </item>
  </channel>
</rss>

