<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic External RADIUS Server Sequence Fallback RADIUS-Reject Design Qs in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/external-radius-server-sequence-fallback-radius-reject-design-qs/m-p/3796942#M485372</link>
    <description>&lt;P&gt;Hi team,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am having a hard time to solve a design issue. There are two companies who have a direct connection between them and time to time the employees move between the companies. Both of the companies are using ISE and have their ADs, Wired/Wireless NAC is also in place. Request is to have the User A from Company A to be able to Authenticate with his credentials on Company B's NADs and same the other way. I am trying to understand the possibility of External RADIUS Server as they don't want to have the Multi-AD integration. If I create a rule with RADIUS Sequence as far as I understand from the document, it will try the first ISE then if it doesn't receive a response, it will move on to the next-one. But how about the RADIUS-Reject scenario? Do we try each RADIUS Servers till we have RADIUS-Accept or finish all the RADIUSes or first time we receive a RADIUS-Reject we stop the process completely? Or how can I achieve the granularity on Authentication Policy based on the company that user belongs to?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any response or guidance will be much appreciated!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;BR /&gt;Efe&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 07 Feb 2019 15:55:57 GMT</pubDate>
    <dc:creator>hevyapan</dc:creator>
    <dc:date>2019-02-07T15:55:57Z</dc:date>
    <item>
      <title>External RADIUS Server Sequence Fallback RADIUS-Reject Design Qs</title>
      <link>https://community.cisco.com/t5/network-access-control/external-radius-server-sequence-fallback-radius-reject-design-qs/m-p/3796942#M485372</link>
      <description>&lt;P&gt;Hi team,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am having a hard time to solve a design issue. There are two companies who have a direct connection between them and time to time the employees move between the companies. Both of the companies are using ISE and have their ADs, Wired/Wireless NAC is also in place. Request is to have the User A from Company A to be able to Authenticate with his credentials on Company B's NADs and same the other way. I am trying to understand the possibility of External RADIUS Server as they don't want to have the Multi-AD integration. If I create a rule with RADIUS Sequence as far as I understand from the document, it will try the first ISE then if it doesn't receive a response, it will move on to the next-one. But how about the RADIUS-Reject scenario? Do we try each RADIUS Servers till we have RADIUS-Accept or finish all the RADIUSes or first time we receive a RADIUS-Reject we stop the process completely? Or how can I achieve the granularity on Authentication Policy based on the company that user belongs to?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any response or guidance will be much appreciated!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;BR /&gt;Efe&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Feb 2019 15:55:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/external-radius-server-sequence-fallback-radius-reject-design-qs/m-p/3796942#M485372</guid>
      <dc:creator>hevyapan</dc:creator>
      <dc:date>2019-02-07T15:55:57Z</dc:date>
    </item>
    <item>
      <title>Re: External RADIUS Server Sequence Fallback RADIUS-Reject Design Qs</title>
      <link>https://community.cisco.com/t5/network-access-control/external-radius-server-sequence-fallback-radius-reject-design-qs/m-p/3796949#M485374</link>
      <description>&lt;P&gt;I would do the following:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Company A defined Company B's ISE PSNs as an external RADIUS token server in their ISE deployment.&lt;/LI&gt;
&lt;LI&gt;Company A defined an identity source sequence that checks Company A AD then Company B external RADIUS server.&lt;/LI&gt;
&lt;LI&gt;Company B does the reverse of that.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;The only danger in that setup is if an AD account with the exact same name exists in Company A AD for a Company B user, but hopefully that risk should be minimal&lt;/P&gt;</description>
      <pubDate>Thu, 07 Feb 2019 16:00:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/external-radius-server-sequence-fallback-radius-reject-design-qs/m-p/3796949#M485374</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2019-02-07T16:00:53Z</dc:date>
    </item>
  </channel>
</rss>

