<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: TACACS two factor authentication with DUO in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/tacacs-two-factor-authentication-with-duo/m-p/3777570#M486409</link>
    <description>With &lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/213239-configure-external-radius-servers-on-ise.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/213239-configure-external-radius-servers-on-ise.html&lt;/A&gt; ,&lt;BR /&gt;&lt;BR /&gt;1. ISE forwards/proxies the request to DUO. &lt;BR /&gt;2. DUO validates the credentials entered by the user.&lt;BR /&gt;3. DUO sends an access-accept back to ISE if the credentials are correct.&lt;BR /&gt;4. ISE will lookup the user in the AD.&lt;BR /&gt;5. Sned a final access-accept back to the network device.</description>
    <pubDate>Fri, 11 Jan 2019 09:19:56 GMT</pubDate>
    <dc:creator>Surendra</dc:creator>
    <dc:date>2019-01-11T09:19:56Z</dc:date>
    <item>
      <title>TACACS two factor authentication with DUO</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-two-factor-authentication-with-duo/m-p/3777167#M486406</link>
      <description>&lt;P&gt;Hi folks,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I haven't worked much on multi factor authentication on ISE. So it would be great if I get more details on this, The customer needs the below design to support from ISE, is it possible? So basically they want to do TACACS auth for the below devices where the authentication request should go to AD and then once successful it should go to DUO server for phonecall or token? Is there any configuration example which helps the scenerio&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2019-01-10 at 2.43.53 PM.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/27531i8EC986DB93BD5E1D/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2019-01-10 at 2.43.53 PM.png" alt="Screen Shot 2019-01-10 at 2.43.53 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;List of network devices we will use for testing:&lt;/P&gt;
&lt;DIV&gt;&lt;FONT color="#000000"&gt;Nexus 7710&amp;nbsp; - 8.2.1 Code&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT color="#000000"&gt;Nexus 93180&amp;nbsp; - 7.x&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT color="#000000"&gt;ASR1009&amp;nbsp; - 16.6.4&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT color="#000000"&gt;ASR9K - 6.2.3&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT color="#000000"&gt;Catalyst 4510 - 3.02.10.SG&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT color="#000000"&gt;WLC 8540&amp;nbsp; - 8.5.143.0&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT color="#000000"&gt;WLC 5508 - 8.3.133.10&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT color="#000000"&gt;WLC 5760 - 03.07.05E&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT color="#000000"&gt;Cisco PI - 3.4&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT color="#000000"&gt;Cisco ISE - 2.3 Patch 5&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT color="#000000"&gt;Cisco Prime Assurance - &lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT color="#000000"&gt;F5 LTM/GTM - &lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT color="#000000"&gt;InfoBlox - 8.2.2&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT color="#000000"&gt;Cisco VG350 – &lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT color="#000000"&gt;Cisco Call Manager – 11.5.x&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT color="#000000"&gt;Cisco ASA5580 – 8.4.x&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT color="#000000"&gt;FTD - 6.x&lt;/FONT&gt;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jan 2019 19:53:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-two-factor-authentication-with-duo/m-p/3777167#M486406</guid>
      <dc:creator>smano</dc:creator>
      <dc:date>2019-01-10T19:53:19Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS two factor authentication with DUO</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-two-factor-authentication-with-duo/m-p/3777242#M486407</link>
      <description>Configure ISE as a TACACS server and DUO as a RADIUS server on the Network device.&lt;BR /&gt;&lt;BR /&gt;Configure authentication to be done against ISE (Configure ISE to look for the user in AD) and authorization to be done against DUO.&lt;BR /&gt;&lt;BR /&gt;This will work as long as the network device supports different servers for authentication and authorization.&lt;BR /&gt;&lt;BR /&gt;ISE in itself does not support MFA but utilizes the third party device capability to do so. TACACS has a very limited scope when it some to MFA on ISE. For instance : &lt;A href="https://community.cisco.com/t5/security-documents/using-duo-with-ise-2-3-and-acs-5-x-for-2fa-cisco-network-admin/ta-p/3642171" target="_blank"&gt;https://community.cisco.com/t5/security-documents/using-duo-with-ise-2-3-and-acs-5-x-for-2fa-cisco-network-admin/ta-p/3642171&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;If you plan to use RADIUS, then you can probably try this &lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/213239-configure-external-radius-servers-on-ise.html#anc7" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/213239-configure-external-radius-servers-on-ise.html#anc7&lt;/A&gt; . Here you can check with DUO call or OTP first and then lookup the user in the AD in authorization policies if you choose the option to continue with authorization on Access-Accept.&lt;BR /&gt;&lt;BR /&gt;You cannot do the other way around with ISE with either of the protocols i.e., AD first and then DUO.&lt;BR /&gt;</description>
      <pubDate>Thu, 10 Jan 2019 21:09:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-two-factor-authentication-with-duo/m-p/3777242#M486407</guid>
      <dc:creator>Surendra</dc:creator>
      <dc:date>2019-01-10T21:09:04Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS two factor authentication with DUO</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-two-factor-authentication-with-duo/m-p/3777374#M486408</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/361506"&gt;@Surendra&lt;/a&gt;&amp;nbsp;for responding, so my understanding is ISE cannot support the customer ask (which is auth goes to AD first and then to token server). ISE can only forward the authentication request to DUO proxy first and then the proxy forwards to AD and duo token server i.e as shown in diagram below. Am I right?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2019-01-07 at 2.54.51 PM.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/27564iB946225CF25FB120/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2019-01-07 at 2.54.51 PM.png" alt="Screen Shot 2019-01-07 at 2.54.51 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Jan 2019 02:50:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-two-factor-authentication-with-duo/m-p/3777374#M486408</guid>
      <dc:creator>smano</dc:creator>
      <dc:date>2019-01-11T02:50:58Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS two factor authentication with DUO</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-two-factor-authentication-with-duo/m-p/3777570#M486409</link>
      <description>With &lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/213239-configure-external-radius-servers-on-ise.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/213239-configure-external-radius-servers-on-ise.html&lt;/A&gt; ,&lt;BR /&gt;&lt;BR /&gt;1. ISE forwards/proxies the request to DUO. &lt;BR /&gt;2. DUO validates the credentials entered by the user.&lt;BR /&gt;3. DUO sends an access-accept back to ISE if the credentials are correct.&lt;BR /&gt;4. ISE will lookup the user in the AD.&lt;BR /&gt;5. Sned a final access-accept back to the network device.</description>
      <pubDate>Fri, 11 Jan 2019 09:19:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-two-factor-authentication-with-duo/m-p/3777570#M486409</guid>
      <dc:creator>Surendra</dc:creator>
      <dc:date>2019-01-11T09:19:56Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS two factor authentication with DUO</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-two-factor-authentication-with-duo/m-p/3777726#M486410</link>
      <description>&lt;P&gt;Yes, you are correct.&amp;nbsp;&amp;nbsp;What is the reason to hit AD first?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Jan 2019 12:55:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-two-factor-authentication-with-duo/m-p/3777726#M486410</guid>
      <dc:creator>faylee</dc:creator>
      <dc:date>2019-01-11T12:55:26Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS two factor authentication with DUO</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-two-factor-authentication-with-duo/m-p/3832347#M486411</link>
      <description>&lt;P&gt;So the auth proxy will check with the AD ( primary auth ) and then with Duo Cloud ( Secondary auth)&amp;nbsp;&lt;BR /&gt;Why does ISE have to check with AD again?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can ISE Integrate with Duo for 2FA, after doing primary auth with AD ( without a auth proxy in the middle)&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Apr 2019 14:36:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-two-factor-authentication-with-duo/m-p/3832347#M486411</guid>
      <dc:creator>nupur jain</dc:creator>
      <dc:date>2019-04-04T14:36:59Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS two factor authentication with DUO</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-two-factor-authentication-with-duo/m-p/3832843#M486412</link>
      <description>&lt;P&gt;Hi Surendra,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) Do we need only to add ISE as a radius token server on achieving 2 FA?&lt;/P&gt;&lt;P&gt;2) Without doing ISE for authentication and DUO for authorization, can we done same authentication request get authenticated by ISE and DUO.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;hasitha&lt;/P&gt;</description>
      <pubDate>Fri, 05 Apr 2019 10:14:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-two-factor-authentication-with-duo/m-p/3832843#M486412</guid>
      <dc:creator>hasitha siriwardhana</dc:creator>
      <dc:date>2019-04-05T10:14:07Z</dc:date>
    </item>
  </channel>
</rss>

