<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: bluecoat proxy ssg 300-25 administration access using ISE in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/bluecoat-proxy-ssg-300-25-administration-access-using-ise/m-p/3715526#M507489</link>
    <description>&lt;P&gt;Hi Chris,&lt;/P&gt;
&lt;P&gt;Add Bluecoat Proxy under Radius Vendor in ISE Dictionary with vendor id&amp;nbsp;14501&lt;/P&gt;
&lt;P&gt;Under dictionary attribute add 2 new attribute with&lt;/P&gt;
&lt;P&gt;Attribute Name :&amp;nbsp;Blue-Coat-Authorization&lt;/P&gt;
&lt;P&gt;Data Type:&amp;nbsp;UINT32&lt;/P&gt;
&lt;P&gt;Direction: Both&lt;/P&gt;
&lt;P&gt;ID: 2&lt;/P&gt;
&lt;P&gt;Another attribute with &lt;SPAN&gt;Attribute Name&lt;/SPAN&gt;:&amp;nbsp;Blue-Coat-Group&lt;/P&gt;
&lt;P&gt;Data Type:&amp;nbsp;UINT32&lt;/P&gt;
&lt;P&gt;Direction: Both&lt;/P&gt;
&lt;P&gt;ID: 1&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Under Authorization profile,use network device profile as Bluecoat,then in Advance attribute call the above 2 attributes as:&lt;/P&gt;
&lt;P&gt;Blue-Coat-Authorization = 2&lt;BR /&gt;Blue-Coat-Group = 2&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sat, 29 Sep 2018 15:50:19 GMT</pubDate>
    <dc:creator>Aravind Ravichandran</dc:creator>
    <dc:date>2018-09-29T15:50:19Z</dc:date>
    <item>
      <title>bluecoat proxy ssg 300-25 administration access using ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/bluecoat-proxy-ssg-300-25-administration-access-using-ise/m-p/3710229#M507487</link>
      <description>&lt;P&gt;Hi experts,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;my customer needs to migrate from acs to ise. this will be for administration access of their devices. they have non-cisco devices and 1 of them is bluecoat proxy. i have tried to configure the way i think it will work but unfortunately no luck. so far below are what have i done:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. added bluecoat vendor id(14501) on ise dictionary&lt;/P&gt;
&lt;P&gt;2.&amp;nbsp; added attribute for admin access. admin access id = 2&lt;/P&gt;
&lt;P&gt;3. added attribute for read only access. read only = 1&lt;/P&gt;
&lt;P&gt;4. created device profile for bluecoat. using the newly added radius attribute&lt;/P&gt;
&lt;P&gt;5. created a policy with the result of "administrative" for admin access. and "login" for read only access.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;during testing authentication is successful but doesnt go thru to proxy gui access. the device is re-prompting to username and password window.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;anybody have tried this setup ? or maybe can point me to a good document. thanks in advance.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;regards,&lt;/P&gt;
&lt;P&gt;chris&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Sep 2018 08:29:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/bluecoat-proxy-ssg-300-25-administration-access-using-ise/m-p/3710229#M507487</guid>
      <dc:creator>Meuserid1979</dc:creator>
      <dc:date>2018-09-20T08:29:38Z</dc:date>
    </item>
    <item>
      <title>Re: bluecoat proxy ssg 300-25 administration access using ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/bluecoat-proxy-ssg-300-25-administration-access-using-ise/m-p/3715526#M507489</link>
      <description>&lt;P&gt;Hi Chris,&lt;/P&gt;
&lt;P&gt;Add Bluecoat Proxy under Radius Vendor in ISE Dictionary with vendor id&amp;nbsp;14501&lt;/P&gt;
&lt;P&gt;Under dictionary attribute add 2 new attribute with&lt;/P&gt;
&lt;P&gt;Attribute Name :&amp;nbsp;Blue-Coat-Authorization&lt;/P&gt;
&lt;P&gt;Data Type:&amp;nbsp;UINT32&lt;/P&gt;
&lt;P&gt;Direction: Both&lt;/P&gt;
&lt;P&gt;ID: 2&lt;/P&gt;
&lt;P&gt;Another attribute with &lt;SPAN&gt;Attribute Name&lt;/SPAN&gt;:&amp;nbsp;Blue-Coat-Group&lt;/P&gt;
&lt;P&gt;Data Type:&amp;nbsp;UINT32&lt;/P&gt;
&lt;P&gt;Direction: Both&lt;/P&gt;
&lt;P&gt;ID: 1&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Under Authorization profile,use network device profile as Bluecoat,then in Advance attribute call the above 2 attributes as:&lt;/P&gt;
&lt;P&gt;Blue-Coat-Authorization = 2&lt;BR /&gt;Blue-Coat-Group = 2&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 29 Sep 2018 15:50:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/bluecoat-proxy-ssg-300-25-administration-access-using-ise/m-p/3715526#M507489</guid>
      <dc:creator>Aravind Ravichandran</dc:creator>
      <dc:date>2018-09-29T15:50:19Z</dc:date>
    </item>
    <item>
      <title>Re: bluecoat proxy ssg 300-25 administration access using ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/bluecoat-proxy-ssg-300-25-administration-access-using-ise/m-p/3720725#M507491</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks for the reply. I have tried what you have suggested but sorry to say that it doesn't work. im talking to cisco tac about it. thanks&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;regards,&lt;/P&gt;
&lt;P&gt;Chris&lt;/P&gt;</description>
      <pubDate>Mon, 08 Oct 2018 02:44:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/bluecoat-proxy-ssg-300-25-administration-access-using-ise/m-p/3720725#M507491</guid>
      <dc:creator>Meuserid1979</dc:creator>
      <dc:date>2018-10-08T02:44:18Z</dc:date>
    </item>
    <item>
      <title>Re: bluecoat proxy ssg 300-25 administration access using ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/bluecoat-proxy-ssg-300-25-administration-access-using-ise/m-p/3867062#M507492</link>
      <description>&lt;P&gt;I see that there has not been anything posted as to a resolution on this. I have tried the same process and found it to not work as expected.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can someone that has been able to verify a working configuration please respond.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jun 2019 21:06:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/bluecoat-proxy-ssg-300-25-administration-access-using-ise/m-p/3867062#M507492</guid>
      <dc:creator>scottbushey</dc:creator>
      <dc:date>2019-06-03T21:06:00Z</dc:date>
    </item>
    <item>
      <title>Re: bluecoat proxy ssg 300-25 administration access using ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/bluecoat-proxy-ssg-300-25-administration-access-using-ise/m-p/3867083#M507494</link>
      <description>&lt;P&gt;Hello &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;on the authorization profile how did you create it and what was the response from ISE, kindly note i don't have a verified test&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;however will help you here to have the profile as per this&lt;/P&gt;
&lt;TABLE class="highlight tab-size js-file-line-container" data-tab-size="8"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD class="blob-code blob-code-inner js-file-line"&gt;VENDOR BlueCoat 14501&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;TABLE class="highlight tab-size js-file-line-container" data-tab-size="8"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD class="blob-code blob-code-inner js-file-line"&gt;&amp;nbsp;&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;TABLE class="highlight tab-size js-file-line-container" data-tab-size="8"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD class="blob-code blob-code-inner js-file-line"&gt;BEGIN-VENDOR BlueCoat&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;TABLE class="highlight tab-size js-file-line-container" data-tab-size="8"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD class="blob-code blob-code-inner js-file-line"&gt;&amp;nbsp;&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;TABLE class="highlight tab-size js-file-line-container" data-tab-size="8"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD class="blob-code blob-code-inner js-file-line"&gt;ATTRIBUTE Blue-Coat-Group 1 string&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;TABLE class="highlight tab-size js-file-line-container" data-tab-size="8"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD class="blob-code blob-code-inner js-file-line"&gt;# Accepts multiple groups as comma-separated list.&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;TABLE class="highlight tab-size js-file-line-container" data-tab-size="8"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD class="blob-code blob-code-inner js-file-line"&gt;&amp;nbsp;&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;TABLE class="highlight tab-size js-file-line-container" data-tab-size="8"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD class="blob-code blob-code-inner js-file-line"&gt;ATTRIBUTE Blue-Coat-Authorization 2 integer&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;TABLE class="highlight tab-size js-file-line-container" data-tab-size="8"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD class="blob-code blob-code-inner js-file-line"&gt;&amp;nbsp;&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;TABLE class="highlight tab-size js-file-line-container" data-tab-size="8"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD class="blob-code blob-code-inner js-file-line"&gt;VALUE Blue-Coat-Authorization No-Access 0&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;TABLE class="highlight tab-size js-file-line-container" data-tab-size="8"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD class="blob-code blob-code-inner js-file-line"&gt;VALUE Blue-Coat-Authorization Read-Only-Access 1&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;TABLE class="highlight tab-size js-file-line-container" data-tab-size="8"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD class="blob-code blob-code-inner js-file-line"&gt;VALUE Blue-Coat-Authorization Read-Write-Access 2&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;TABLE class="highlight tab-size js-file-line-container" data-tab-size="8"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD class="blob-code blob-code-inner js-file-line"&gt;&amp;nbsp;&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;END-VENDOR BlueCoat&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;in some of the answers i am seeing a respond for group with integer which is not correct since in group we should send group name,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;based on your explanation you are only pushing read only or read-write which is identified as integer&lt;/P&gt;
&lt;P&gt;1 for read&lt;/P&gt;
&lt;P&gt;2 for read write&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;can you please double check the dictionary&lt;/P&gt;
&lt;P&gt;then make sure your authorization profile pushing something like this.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Access Type = ACCESS_ACCEPT&lt;BR /&gt;Blue-Coat-Authorization = 2&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;let me know how it goes&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Wishes,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jun 2019 21:47:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/bluecoat-proxy-ssg-300-25-administration-access-using-ise/m-p/3867083#M507494</guid>
      <dc:creator>yalbikaw</dc:creator>
      <dc:date>2019-06-03T21:47:33Z</dc:date>
    </item>
    <item>
      <title>Re: bluecoat proxy ssg 300-25 administration access using ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/bluecoat-proxy-ssg-300-25-administration-access-using-ise/m-p/3869812#M507495</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;for bluecoat admin access "result":&lt;/P&gt;&lt;P&gt;under "Advanced attributes settings" choose:&lt;/P&gt;&lt;P&gt;Radius:Service-Type = Administrative&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;this will give attribute details as:&lt;/P&gt;&lt;P&gt;access type = ACCESS_ACCEPT&lt;/P&gt;&lt;P&gt;service-type = 5&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;for bluecoat read-only&amp;nbsp;access "result":&lt;/P&gt;&lt;P&gt;under "Advanced attributes settings" choose:&lt;/P&gt;&lt;P&gt;Radius:Service-Type = Login&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;this will give attribute details as:&lt;/P&gt;&lt;P&gt;access type = ACCESS_ACCEPT&lt;/P&gt;&lt;P&gt;service-type = 1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i believe on bluecoat side you also need to do some configurations unfortunately i cant remember what and where it should be configured.&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;hope this helps.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 08 Jun 2019 09:27:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/bluecoat-proxy-ssg-300-25-administration-access-using-ise/m-p/3869812#M507495</guid>
      <dc:creator>Meuserid1979</dc:creator>
      <dc:date>2019-06-08T09:27:36Z</dc:date>
    </item>
    <item>
      <title>Re: bluecoat proxy ssg 300-25 administration access using ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/bluecoat-proxy-ssg-300-25-administration-access-using-ise/m-p/3869813#M507499</link>
      <description>p.s. that usnig the built-in ietf radius attributes</description>
      <pubDate>Sat, 08 Jun 2019 09:28:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/bluecoat-proxy-ssg-300-25-administration-access-using-ise/m-p/3869813#M507499</guid>
      <dc:creator>Meuserid1979</dc:creator>
      <dc:date>2019-06-08T09:28:35Z</dc:date>
    </item>
  </channel>
</rss>

