<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE as RADIUS proxy, would CoA work? in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-as-radius-proxy-would-coa-work/m-p/3782297#M486221</link>
    <description>&lt;P&gt;kindly please do not forget to share your finding with us.&lt;/P&gt;</description>
    <pubDate>Thu, 17 Jan 2019 17:41:18 GMT</pubDate>
    <dc:creator>Sheraz.Salim</dc:creator>
    <dc:date>2019-01-17T17:41:18Z</dc:date>
    <item>
      <title>ISE as RADIUS proxy, would CoA work?</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-as-radius-proxy-would-coa-work/m-p/3781304#M486213</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm currently investigating ISE and DUO integration with ASA for remote access VPN. One of the options is to have ISE proxy RADIUS requests to the DUO Auth Proxy.&lt;/P&gt;
&lt;P&gt;I was wondering if CoA (sent by ISE to ASA) would still be functional in that scenario. I'm ultimately seeking to understand if posture would be possible in that type of setup.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best Regards,&lt;/P&gt;
&lt;P&gt;Martin&lt;/P&gt;</description>
      <pubDate>Wed, 16 Jan 2019 16:46:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-as-radius-proxy-would-coa-work/m-p/3781304#M486213</guid>
      <dc:creator>mabriand</dc:creator>
      <dc:date>2019-01-16T16:46:18Z</dc:date>
    </item>
    <item>
      <title>Re: ISE as RADIUS proxy, would CoA work?</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-as-radius-proxy-would-coa-work/m-p/3781371#M486215</link>
      <description>&lt;P&gt;I usually don't use the RADIUS proxy setup.&amp;nbsp; I prefer the RADIUS token server setup when integrating with 2FA vendors.&amp;nbsp; In that scenario I know CoA and posturing works just fine.&amp;nbsp; I would assume it should work with the RADIUS proxy setup.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can test it easily enough.&amp;nbsp; Get a device connected on VPN with DUO as RADIUS proxy in ISE.&amp;nbsp; Go to the live sessions screen and find the session.&amp;nbsp; Click Reauthentication for CoA actions and see if you see an authentication in the live logs.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Jan 2019 18:04:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-as-radius-proxy-would-coa-work/m-p/3781371#M486215</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2019-01-16T18:04:17Z</dc:date>
    </item>
    <item>
      <title>Re: ISE as RADIUS proxy, would CoA work?</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-as-radius-proxy-would-coa-work/m-p/3781825#M486218</link>
      <description>&lt;P&gt;Thanks Paul, spot on.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Not sure why I drifted from Radius Token server to RADIUS proxy instead.&lt;/P&gt;
&lt;P&gt;Indeed with usage of DUO Auth Proxy as a RADIUS token server, there's no concern anymore.&lt;/P&gt;
&lt;P&gt;I'm still curious about RADIUS proxy and CoA and will test that whenever I get access to a lab setup with ISE and another RADIUS server.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best Regards,&lt;/P&gt;
&lt;P&gt;Martin&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jan 2019 08:10:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-as-radius-proxy-would-coa-work/m-p/3781825#M486218</guid>
      <dc:creator>mabriand</dc:creator>
      <dc:date>2019-01-17T08:10:43Z</dc:date>
    </item>
    <item>
      <title>Re: ISE as RADIUS proxy, would CoA work?</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-as-radius-proxy-would-coa-work/m-p/3782297#M486221</link>
      <description>&lt;P&gt;kindly please do not forget to share your finding with us.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jan 2019 17:41:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-as-radius-proxy-would-coa-work/m-p/3782297#M486221</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2019-01-17T17:41:18Z</dc:date>
    </item>
  </channel>
</rss>

