<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE support for VPN users in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-support-for-vpn-users/m-p/3521690#M511580</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I agreed with George.&lt;/P&gt;&lt;P&gt;ASA supports multiple authentications so it's possible to have an OTP that only managers have access to and for them to provide the passcodes to the VPN users. Or, some MFA with one factor to send SMS or the like to the managers to accept the requests.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 15 Mar 2018 03:48:33 GMT</pubDate>
    <dc:creator>hslai</dc:creator>
    <dc:date>2018-03-15T03:48:33Z</dc:date>
    <item>
      <title>ISE support for VPN users</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-support-for-vpn-users/m-p/3521688#M511578</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;Hello Experts!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;My customer wants to VPN user AAA using AD+OTP and management approval.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;- This is for VPN solution only and applied to all devices including personal devices (laptop, iPad etc) and company-owned device (laptop)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;- The approval process from management needs to be done every time of VPN access. Currently, they have VPN solution with AD auth and OTP. They need an extra layer of security with management approval before establishing VPN connection.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;What I understand is, the customer can do it RSA-AD authentication and there’s no way we can combine management approval on top of it. &lt;/SPAN&gt;Does anyone know if we can combine management approval feature with other methods like AD, RSA, LDAP etc? I only could see that management approval is supported for guest service that self-registered guest request will be sent to the sponsor for approval, and we can't combine it with AD or OTP service, but I would like to check if there's any method we can work around. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;Any comments or design would be highly appreciated! &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;Jina&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Mar 2018 09:31:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-support-for-vpn-users/m-p/3521688#M511578</guid>
      <dc:creator>jinapark</dc:creator>
      <dc:date>2018-03-14T09:31:55Z</dc:date>
    </item>
    <item>
      <title>Re: ISE support for VPN users</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-support-for-vpn-users/m-p/3521689#M511579</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is an odd request.  I don’t see how ISE can help you with this.  One way you could accomplish this is by creating a portal/web page for the VPN request.  Have that page send an email or text to the manager.  Then the manager clicks on a link that adds the requestor to a VPN approved group for some amount of time (maybe 10 minutes).  Then you can authorize the user based on group membership.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;George&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Mar 2018 18:27:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-support-for-vpn-users/m-p/3521689#M511579</guid>
      <dc:creator>gbekmezi-DD</dc:creator>
      <dc:date>2018-03-14T18:27:23Z</dc:date>
    </item>
    <item>
      <title>Re: ISE support for VPN users</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-support-for-vpn-users/m-p/3521690#M511580</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I agreed with George.&lt;/P&gt;&lt;P&gt;ASA supports multiple authentications so it's possible to have an OTP that only managers have access to and for them to provide the passcodes to the VPN users. Or, some MFA with one factor to send SMS or the like to the managers to accept the requests.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Mar 2018 03:48:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-support-for-vpn-users/m-p/3521690#M511580</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-03-15T03:48:33Z</dc:date>
    </item>
    <item>
      <title>Re: ISE support for VPN users</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-support-for-vpn-users/m-p/3521691#M511581</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just to add to what has already been said.&amp;nbsp; You could craft something with REST API integration as well, but it seems like you are trying to solve what is a non-technical problem.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A person just doesn't get an RSA token on their own.&amp;nbsp; The customer has no management approval required to hand out RSA tokens?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A person doesn't automatically get added to the AD group required for VPN access.&amp;nbsp; The customer has no management approval required to get added to the AD group required for VPN access?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Mar 2018 13:30:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-support-for-vpn-users/m-p/3521691#M511581</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2018-03-15T13:30:17Z</dc:date>
    </item>
  </channel>
</rss>

