<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA - ISE COA communications in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/asa-ise-coa-communications/m-p/3793445#M485676</link>
    <description>&lt;P&gt;As Mohammed stated, it will use the&amp;nbsp;&lt;SPAN&gt;NAS-IP-Address since the network device (ASA) is responsible for being the authenticator during the process that will ultimately grant access &amp;amp; authorize the supplicant based on your posture status conditions configured in ISE.&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Sat, 02 Feb 2019 13:33:05 GMT</pubDate>
    <dc:creator>Mike.Cifelli</dc:creator>
    <dc:date>2019-02-02T13:33:05Z</dc:date>
    <item>
      <title>ASA - ISE COA communications</title>
      <link>https://community.cisco.com/t5/network-access-control/asa-ise-coa-communications/m-p/3793216#M485671</link>
      <description>&lt;P&gt;Greetings,&lt;/P&gt;
&lt;P&gt;The following question is related to the RADIUS communication between an ASA and ISE for CoA:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am working with a customer who has a requirement to combine authorization attributes from both ISE (posture requirements) and Radiator (VLAN assignment) into a single RADIUS AAA response. Ideally we would like ISE to be the primary RADIUS server with Radiator as an external RADIUS server. However, it is our understanding that ISE cannot combine internal/external authorization attributes (either pass (proxy) on authorization attributes from external RADIUS or ignores attributes from the external RADIUS server and invoke ISE authorization attributes).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We would like to setup a test environment with Radiator as the primary RADIUS Server and ISE as the external RADIUS server. Any (posture-related) attributes from ISE will be passed on to the Radiator which will augment this with additional attributes (VLAN) and forward this to the ASA.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Question: What information does ISE use to identify the correct NAD (ASA) when sending a CoA? Does it use a RADIUS attribute ('Called-Station-ID" or "NAS-IP-Address) or the original IP address from the UDP packet?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Rob&lt;/P&gt;</description>
      <pubDate>Fri, 01 Feb 2019 21:30:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/asa-ise-coa-communications/m-p/3793216#M485671</guid>
      <dc:creator>Robertus Bleeker</dc:creator>
      <dc:date>2019-02-01T21:30:26Z</dc:date>
    </item>
    <item>
      <title>Re: ASA - ISE COA communications</title>
      <link>https://community.cisco.com/t5/network-access-control/asa-ise-coa-communications/m-p/3793227#M485674</link>
      <description>NAS-IP-Address is used. The source IP can be different if you nat the&lt;BR /&gt;packet, for example (which I haven't seen before to have radius behind nat).&lt;BR /&gt;</description>
      <pubDate>Fri, 01 Feb 2019 21:45:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/asa-ise-coa-communications/m-p/3793227#M485674</guid>
      <dc:creator>Mohammed al Baqari</dc:creator>
      <dc:date>2019-02-01T21:45:18Z</dc:date>
    </item>
    <item>
      <title>Re: ASA - ISE COA communications</title>
      <link>https://community.cisco.com/t5/network-access-control/asa-ise-coa-communications/m-p/3793445#M485676</link>
      <description>&lt;P&gt;As Mohammed stated, it will use the&amp;nbsp;&lt;SPAN&gt;NAS-IP-Address since the network device (ASA) is responsible for being the authenticator during the process that will ultimately grant access &amp;amp; authorize the supplicant based on your posture status conditions configured in ISE.&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 02 Feb 2019 13:33:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/asa-ise-coa-communications/m-p/3793445#M485676</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2019-02-02T13:33:05Z</dc:date>
    </item>
  </channel>
</rss>

