<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE as Two Factor Authentication Tool? in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-as-two-factor-authentication-tool/m-p/3450394#M512719</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The chaining options are not true MFA.&amp;nbsp; MFA typically refers to multiple factors (such as something you have, something you know, something you are) being used for a specific identity.&amp;nbsp; The chaining options are separate, discreet auth events, but combined together to provide a single access policy decision.&amp;nbsp; This is similar to the ASA double authentication feature.&amp;nbsp; It is not MFA in pure sense.&amp;nbsp; That said, you need to decide what is the outcome you are trying to achieve. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We do not have any special integration with DUO, although I have received reports of successful integration with ISE.&amp;nbsp; DUO is more of a true MFA type function which can work outside ISE, but may have the needed hooks via RADIUS, LDAP, or other integration into web auth flow.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 13 Mar 2018 14:20:03 GMT</pubDate>
    <dc:creator>Craig Hyps</dc:creator>
    <dc:date>2018-03-13T14:20:03Z</dc:date>
    <item>
      <title>ISE as Two Factor Authentication Tool?</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-as-two-factor-authentication-tool/m-p/3450391#M512716</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can ISE be configured to create a two-factor authentication protocol without the use of an external identity source like an RSA token? Or at least can it be configured to work with other Cisco products in a way that acts as two-factor authentication like in conjunction with Anyconnect? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Mar 2018 18:38:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-as-two-factor-authentication-tool/m-p/3450391#M512716</guid>
      <dc:creator>mweintraub</dc:creator>
      <dc:date>2018-03-12T18:38:14Z</dc:date>
    </item>
    <item>
      <title>Re: ISE as Two Factor Authentication Tool?</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-as-two-factor-authentication-tool/m-p/3450392#M512717</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Suggest review this session from Cisco Live 2017: &lt;A href="https://www.ciscolive.com/global/on-demand-library/?search=brksec-3697#/session/1475057171505001duty" title="https://www.ciscolive.com/global/on-demand-library/?search=brksec-3697#/session/1475057171505001duty"&gt;On-Demand Library - Cisco Live Global Events&lt;/A&gt;&amp;nbsp; (see Reference presentation).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Specific OTP, that is something requires integration with external RSA/RADIUS-based token server, as ISE is not a OTP server.&amp;nbsp; Some examples that may address the customer goal (and not all technically qualify as pure MFA) include EAP Chaining, CWA Chaining, EZC Chaining, Machine Access Restrictions (MAR).&amp;nbsp; Some methods are NAD based (for example, ASA can perform double auth), or are client based (for example, biometric reader or PIN to unluck credentials/certificate).&amp;nbsp; The session I cite above also gets into the options to handle the device + user auth, which is not MFA, but multiple identity auth.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Craig&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Mar 2018 20:57:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-as-two-factor-authentication-tool/m-p/3450392#M512717</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2018-03-12T20:57:49Z</dc:date>
    </item>
    <item>
      <title>Re: ISE as Two Factor Authentication Tool?</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-as-two-factor-authentication-tool/m-p/3450393#M512718</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;so it is not a problem to implement MFA (lets say DUO) with dot1x for user auth? do I need to use some xy chaining? thank you&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Mar 2018 12:27:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-as-two-factor-authentication-tool/m-p/3450393#M512718</guid>
      <dc:creator>peter.matuska1</dc:creator>
      <dc:date>2018-03-13T12:27:42Z</dc:date>
    </item>
    <item>
      <title>Re: ISE as Two Factor Authentication Tool?</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-as-two-factor-authentication-tool/m-p/3450394#M512719</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The chaining options are not true MFA.&amp;nbsp; MFA typically refers to multiple factors (such as something you have, something you know, something you are) being used for a specific identity.&amp;nbsp; The chaining options are separate, discreet auth events, but combined together to provide a single access policy decision.&amp;nbsp; This is similar to the ASA double authentication feature.&amp;nbsp; It is not MFA in pure sense.&amp;nbsp; That said, you need to decide what is the outcome you are trying to achieve. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We do not have any special integration with DUO, although I have received reports of successful integration with ISE.&amp;nbsp; DUO is more of a true MFA type function which can work outside ISE, but may have the needed hooks via RADIUS, LDAP, or other integration into web auth flow.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Mar 2018 14:20:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-as-two-factor-authentication-tool/m-p/3450394#M512719</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2018-03-13T14:20:03Z</dc:date>
    </item>
  </channel>
</rss>

