<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE 2.x Guest with Comware 5 (or 7) in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-2-x-guest-with-comware-5-or-7/m-p/3516210#M505007</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;﻿You will need to ask the vendor what they support for standards and lab it up and see what you can get to work&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please read over the following information&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;https://communities.cisco.com/docs/DOC-75329&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 14 May 2018 15:54:36 GMT</pubDate>
    <dc:creator>Jason Kunst</dc:creator>
    <dc:date>2018-05-14T15:54:36Z</dc:date>
    <item>
      <title>ISE 2.x Guest with Comware 5 (or 7)</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-x-guest-with-comware-5-or-7/m-p/3516209#M505006</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;is it possible to integrate ISE Guest with comware 5 or comware 7 switches (HPE).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Basic example, failed authentication puts user in Guest VLAN where we redirect web traffic to ISE Guest Portal. After successful portal authentication we do CoA and apply new authorization rights.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;I think that NAD profile delivered with ISE does not support this but not sure is there a way to create custom profile and make it work.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 May 2018 15:52:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-x-guest-with-comware-5-or-7/m-p/3516209#M505006</guid>
      <dc:creator>sstanic6112</dc:creator>
      <dc:date>2018-05-14T15:52:01Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.x Guest with Comware 5 (or 7)</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-x-guest-with-comware-5-or-7/m-p/3516210#M505007</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;﻿You will need to ask the vendor what they support for standards and lab it up and see what you can get to work&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please read over the following information&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;https://communities.cisco.com/docs/DOC-75329&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 May 2018 15:54:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-x-guest-with-comware-5-or-7/m-p/3516210#M505007</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-05-14T15:54:36Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.x Guest with Comware 5 (or 7)</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-x-guest-with-comware-5-or-7/m-p/3516211#M505008</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Same response from both vendors. &lt;/P&gt;&lt;P&gt;I'll try with the lab and see where it goes..&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 May 2018 16:05:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-x-guest-with-comware-5-or-7/m-p/3516211#M505008</guid>
      <dc:creator>sstanic6112</dc:creator>
      <dc:date>2018-05-14T16:05:19Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.x Guest with Comware 5 (or 7)</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-x-guest-with-comware-5-or-7/m-p/3516212#M505009</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;See &lt;A href="https://community.cisco.com/docs/DOC-64547"&gt;ISE Third-Party NAD Profiles and Configs&lt;/A&gt; NAD profiles and sample working configs working with Comware (HP H3C) for wired and wireless.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 May 2018 20:55:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-x-guest-with-comware-5-or-7/m-p/3516212#M505009</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2018-05-14T20:55:04Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.x Guest with Comware 5 (or 7)</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-x-guest-with-comware-5-or-7/m-p/3516213#M505010</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for all links but i am already familiar with all of them. I am also in contact with other vendor.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What i know so far:&lt;/P&gt;&lt;P&gt;1. Cisco ISE has 2 NAD profiles for H3C devices (HPWired, HPWired_SNMP_CoA) and none of them has redirect action and Web Authentication flow type by default - so i have to play with custom profiles.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. Comware documentation describes few concepts (Com5 or Com7, local or external portal) and neither is describing requirements for ISE. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3. Comware 7 seems more advanced but is using some aditional VSA atributes. We are able to add them to RADIUS dictionary on ISE but not sure are they supported on comware 5 (actually question fro HPE).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;4. From design point of view, it looks to me that Cisco is performing CWA and Comware 5 some kind of hybrid Web Auth.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What is surprising me is that i cannot find working example of such integration. Lab that i have to set up will be based on partial information from each vendor form different concepts and that will be time consuming so before i dig into that i would like to rephrase my question.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it possible? &lt;/P&gt;&lt;P&gt;Is there anybody who has done it?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 May 2018 12:13:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-x-guest-with-comware-5-or-7/m-p/3516213#M505010</guid>
      <dc:creator>sstanic6112</dc:creator>
      <dc:date>2018-05-15T12:13:50Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.x Guest with Comware 5 (or 7)</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-x-guest-with-comware-5-or-7/m-p/3516214#M505011</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is it possible?&amp;nbsp; YES&lt;/P&gt;&lt;P&gt;Is there anybody who has done it?&amp;nbsp; Not sure.&amp;nbsp; Sounds like your particular combination not covered by current examples.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To clarify, ISE will ALWAYS use CWA for web auth, unless the switch is using another mechanism completely outside of ISE to capture credentials and submit them separately via RADIUS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If switch supports option to return a URL redirect/portal page via RADIUS, that may work like Cisco switches.&amp;nbsp; Otherwise, if portal URL is local to switch, then need to leverage option in ISE to set a specific portal string derived from AuthZ Profile config.&amp;nbsp; If switch has no portal redirect capabilities, then need to implement ISE as DNS/DHCP server in Auth VLAN.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 May 2018 12:46:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-x-guest-with-comware-5-or-7/m-p/3516214#M505011</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2018-05-15T12:46:57Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.x Guest with Comware 5 (or 7)</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-x-guest-with-comware-5-or-7/m-p/3516215#M505012</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Still not convinced but i think we are getting somewhere.. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Comware 5 has two options for portal authentication. Local Guest Portal (on the switch) or external Guest Portal. With external portal, switch uses its Layer 3 interface to communicate with Portal (capture credentials) and RADIUS (submit credentials), in my case both of this communication are targeting ISE.&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;Not sure is ISE OK with that approach.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Comware 5 expect this...&lt;/P&gt;&lt;P&gt;&lt;SPAN class="fontstyle0"&gt;1. C&lt;/SPAN&gt;&lt;SPAN class="fontstyle2"&gt;lient access Portal to start authentication (enter user/pass)&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class="fontstyle0"&gt;2. &lt;/SPAN&gt;&lt;SPAN class="fontstyle2"&gt;Portal &lt;SPAN style="font-size: 13.3333px;"&gt;server &lt;/SPAN&gt;and switch exchange CHAP messages if CHAP is used. If PAP is used this step is skipped.&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class="fontstyle0"&gt;3. &lt;/SPAN&gt;&lt;SPAN class="fontstyle2"&gt;Portal &lt;SPAN style="font-size: 13.3333px;"&gt;server &lt;/SPAN&gt;assembles username and password into an authentication request message and sends it to the switch. &lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class="fontstyle0"&gt;4. Switch&lt;/SPAN&gt;&lt;SPAN class="fontstyle2"&gt; and RADIUS server exchange RADIUS packets to authenticate the user.&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class="fontstyle0"&gt;5. Switch&lt;/SPAN&gt;&lt;SPAN class="fontstyle2"&gt; sends an authentication reply to the portal.&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class="fontstyle0"&gt;6. &lt;/SPAN&gt;&lt;SPAN class="fontstyle2"&gt;Portal server sends an authentication success message to the client.&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class="fontstyle0"&gt;7. &lt;/SPAN&gt;&lt;SPAN class="fontstyle2"&gt;Portal server sends an authentication reply acknowledgment message to the switch.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As i said earlier, this example is not based on ISE as both Portal and RADIUS server, so not sure where would this guide lead me to. Some of this can be configured on ISE and some of it can be configured on HPE switch but i am affraid i do not have complete information.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would like to understand it before i start setting up lab.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 May 2018 12:42:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-x-guest-with-comware-5-or-7/m-p/3516215#M505012</guid>
      <dc:creator>sstanic6112</dc:creator>
      <dc:date>2018-05-16T12:42:46Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.x Guest with Comware 5 (or 7)</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-x-guest-with-comware-5-or-7/m-p/3516216#M505013</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The flow sounds similar to LWA to local or external portal in Cisco switches/controllers.&amp;nbsp; However, there are specific requirements on the web portal to support the credential exchange which Comware must have documented.&amp;nbsp; Not sure if their external portal requirements can be met by ISE guest portal, but sounds like you can minimally use switches LWA capability to local or some other web server portal and have it exchange credentials to ISE via RADIUS, or force the CWA flow via ISE portal.&amp;nbsp; This would need to override switches basic LWA flow and ISE would handle the web auth directly without a separate RADIUS transaction.&amp;nbsp; Switch may not need to even know it is occurring.&amp;nbsp; After completion of web login on ISE, a CoA would be sent before completion of LWA flow and allowed access based on session state.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 May 2018 13:11:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-x-guest-with-comware-5-or-7/m-p/3516216#M505013</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2018-05-16T13:11:06Z</dc:date>
    </item>
  </channel>
</rss>

