<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE 2.4 third party apps compatibility in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-2-4-third-party-apps-compatibility/m-p/3584225#M509453</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I really don’t understand what you’re trying to accomplish&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Perhaps you can explain another way&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 30 May 2018 23:14:44 GMT</pubDate>
    <dc:creator>Jason Kunst</dc:creator>
    <dc:date>2018-05-30T23:14:44Z</dc:date>
    <item>
      <title>ISE 2.4 third party apps compatibility</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-third-party-apps-compatibility/m-p/3584224#M509450</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear all &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Doing some research I'm aware that the cisco ISE is able to use an external identity source (such as LDAP, ODBC etc) to validate information like a username and password provided by an end-user who tries to access the network. Is there a way to configure the ISE so it can validate itself (via local database)&amp;nbsp; a username and password provided by a third party application? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;More precisely what are the options (standards, protocols) ISE has to interact with third party applications in the way explained previously where the App is the one providing the ISE with the username and password and the ISE just has to validate that info against the local database? or is this not possible at all?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 May 2018 23:01:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-third-party-apps-compatibility/m-p/3584224#M509450</guid>
      <dc:creator>alan.ramirez</dc:creator>
      <dc:date>2018-05-30T23:01:43Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.4 third party apps compatibility</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-third-party-apps-compatibility/m-p/3584225#M509453</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I really don’t understand what you’re trying to accomplish&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Perhaps you can explain another way&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 May 2018 23:14:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-third-party-apps-compatibility/m-p/3584225#M509453</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-05-30T23:14:44Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.4 third party apps compatibility</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-third-party-apps-compatibility/m-p/3584226#M509455</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sure, &lt;SPAN style="font-size: 10pt;"&gt;let's say we have users in a LAN that are trying to access an application from a third party vendor which is hosted in a server also in that LAN. What I want to know is if the following procedure can be done:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;1.- Users try to access the application &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;2.- The application ask the user to provide a username and password&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;3.- The application receives the username and password provided by the user &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;4.- The application forwards this information to ISE&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;5.- ISE checks if the username and password exist in the ISE local database&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;6.- ISE communicates back to the application the validity of the info&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;7.- Application permits/denies access to the user &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Is that better? as far as I know cisco ISE can authenticate users who want to gain access to the network through RADIUS or if users want to manage network devices such as switches, routers etc. ISE uses TACACS but I don't know if what i described on the seven steps is possible since the user is not trying to get access to the network nor the network devices. The users are trying to get access to an app instead&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 May 2018 01:26:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-third-party-apps-compatibility/m-p/3584226#M509455</guid>
      <dc:creator>alan.ramirez</dc:creator>
      <dc:date>2018-05-31T01:26:02Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.4 third party apps compatibility</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-third-party-apps-compatibility/m-p/3584227#M509457</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sounds like you’re looking for an IAM Type of service&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No ISE doesn’t provide that, we only communicate via radius and tacacs like you said, if the service can use that then it will work&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 May 2018 01:36:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-third-party-apps-compatibility/m-p/3584227#M509457</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-05-31T01:36:40Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.4 third party apps compatibility</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-third-party-apps-compatibility/m-p/3584228#M509459</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The app could also use pxGrid or TrustSec to make decision on access based on its auth status or role assignment in ISE.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 May 2018 18:18:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-third-party-apps-compatibility/m-p/3584228#M509459</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2018-05-31T18:18:43Z</dc:date>
    </item>
  </channel>
</rss>

