<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic RSA on ISE login. in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/rsa-on-ise-login/m-p/3500567#M518144</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So, I see ISE supports RSA as of 2.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, I have instructions and such, but was wondering if it works on the login to ISE itself.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Basically, I don't need RSA for users into their PC, but for an admin logging into ISE itself.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 01 Feb 2018 21:46:15 GMT</pubDate>
    <dc:creator>Dustin Anderson</dc:creator>
    <dc:date>2018-02-01T21:46:15Z</dc:date>
    <item>
      <title>RSA on ISE login.</title>
      <link>https://community.cisco.com/t5/network-access-control/rsa-on-ise-login/m-p/3500567#M518144</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So, I see ISE supports RSA as of 2.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, I have instructions and such, but was wondering if it works on the login to ISE itself.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Basically, I don't need RSA for users into their PC, but for an admin logging into ISE itself.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Feb 2018 21:46:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/rsa-on-ise-login/m-p/3500567#M518144</guid>
      <dc:creator>Dustin Anderson</dc:creator>
      <dc:date>2018-02-01T21:46:15Z</dc:date>
    </item>
    <item>
      <title>Re: RSA on ISE login.</title>
      <link>https://community.cisco.com/t5/network-access-control/rsa-on-ise-login/m-p/3500568#M518147</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Since Release 1.1.0, &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-3/admin_guide/b_ise_admin_guide_23/b_ise_admin_guide_23_chapter_0101.html#ID766"&gt;Administrative Access to Cisco ISE Using an External Identity Store&lt;/A&gt;&lt;SPAN style="font-size: 10pt;"&gt; is available. Note that &lt;/SPAN&gt;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;TABLE border="1"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;SPAN style="margin-top: 12px; margin-bottom: 12px; font-family: inherit; font-size: 10pt; font-style: inherit;"&gt;External Authentication and Internal Authorization—The administrator’s authentication credentials come from the external identity source, and authorization and administrator role assignment take place using the local Cisco ISE database. This model is used for &lt;STRONG&gt;RSA SecurID&lt;/STRONG&gt; authentication. This method requires you to configure the same username in both the external identity store and the local Cisco ISE database.&lt;/SPAN&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;ISE 2.1.0 added &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-3/admin_guide/b_ise_admin_guide_23/b_ise_admin_guide_23_chapter_01110.html#id_19010"&gt;Authenticate Internal User Against External Identity Store Password&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt; but CSCvb64350 documented that&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;TABLE border="1"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;SPAN style="color: #58585b; font-size: 10pt; font-family: CiscoSans, Arial, sans-serif;"&gt;If an internal user is configured with an external identity store for authentication, while logging in to the ISE Admin portal, the internal user must select the external identity store as the Identity Source. Authentication will fail if Internal Identity Source is selected.&lt;/SPAN&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;CSCvg68768 is an enhancement for the above caveat.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Feb 2018 22:39:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/rsa-on-ise-login/m-p/3500568#M518147</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-02-01T22:39:10Z</dc:date>
    </item>
  </channel>
</rss>

