<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE + OKTA for 2FA/OTP in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-okta-for-2fa-otp/m-p/3802306#M518659</link>
    <description>&lt;P&gt;Sorry to barge in to this thread, but it fits right in with the topic at hand...is it possible to use ISE for the Primary authc and authz, and add an OKTA RADIUS agent as a secondary RADIUS server just for the 2nd factor? (I.E. Okta Push)&lt;/P&gt;</description>
    <pubDate>Thu, 14 Feb 2019 22:25:05 GMT</pubDate>
    <dc:creator>Nathaniel Bell</dc:creator>
    <dc:date>2019-02-14T22:25:05Z</dc:date>
    <item>
      <title>ISE + OKTA for 2FA/OTP</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-okta-for-2fa-otp/m-p/3580726#M518653</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a customer that is interested in ISE that is currently using OKTA for their 2FA/OTP. They want to know if ISE and OKTA can integrate together to provide:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;2FA/OTP for RA-VPN users utilizing ASAs and AnyConnect&lt;/LI&gt;&lt;LI&gt;2FA/OTP for RADIUS/TACACS+ based device administration&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From what I was able to find on OKTA's support pages and documentation this should not be an issue. It appears that OKTA will just be referenced as an external RADIUS server in ISE (Similarly to other OTP providers such as DUO, RSA, etc). However, I wanted to see if anyone can confirm this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Neno&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Jan 2018 02:50:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-okta-for-2fa-otp/m-p/3580726#M518653</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2018-01-12T02:50:59Z</dc:date>
    </item>
    <item>
      <title>Re: ISE + OKTA for 2FA/OTP</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-okta-for-2fa-otp/m-p/3580727#M518655</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ISE can integrate with any RADIUS token server compliant with RFC 2865. Our teams are not testing OKTA as an OTP so we do not have info which OKTA product(s) work.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Jan 2018 15:37:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-okta-for-2fa-otp/m-p/3580727#M518655</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-01-12T15:37:32Z</dc:date>
    </item>
    <item>
      <title>Re: ISE + OKTA for 2FA/OTP</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-okta-for-2fa-otp/m-p/3580728#M518656</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have used OKTA on several installs without an issue mostly for VPN authentication.&amp;nbsp; As you said OKTA is just an external RADIUS server to ISE and it runs the whole authentication.&amp;nbsp; You probably want to crank up your RADIUS timeouts to something like 2-3 minutes because depending on the verification OKTA is doing (OKTA App, App Push, SMS Text, call) it can take a while for the person to type in their password.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Jan 2018 21:01:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-okta-for-2fa-otp/m-p/3580728#M518656</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2018-01-12T21:01:52Z</dc:date>
    </item>
    <item>
      <title>Re: ISE + OKTA for 2FA/OTP</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-okta-for-2fa-otp/m-p/3580729#M518657</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey Paul, nice to "hear" from you! &lt;IMG src="https://community.cisco.com/legacyfs/online/emoticons/happy.png" /&gt; Thank you for the reply/confirmation Paul!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Neno&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Jan 2018 05:55:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-okta-for-2fa-otp/m-p/3580729#M518657</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2018-01-16T05:55:53Z</dc:date>
    </item>
    <item>
      <title>Re: ISE + OKTA for 2FA/OTP</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-okta-for-2fa-otp/m-p/3580730#M518658</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;To be clear, in that scenario,&amp;nbsp; is the ASA the original RADIUS client and ISE just proxies the RADIUS message back and forth between the Okta agent and ASA?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Apr 2018 18:22:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-okta-for-2fa-otp/m-p/3580730#M518658</guid>
      <dc:creator>hugh.kelley</dc:creator>
      <dc:date>2018-04-19T18:22:49Z</dc:date>
    </item>
    <item>
      <title>Re: ISE + OKTA for 2FA/OTP</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-okta-for-2fa-otp/m-p/3802306#M518659</link>
      <description>&lt;P&gt;Sorry to barge in to this thread, but it fits right in with the topic at hand...is it possible to use ISE for the Primary authc and authz, and add an OKTA RADIUS agent as a secondary RADIUS server just for the 2nd factor? (I.E. Okta Push)&lt;/P&gt;</description>
      <pubDate>Thu, 14 Feb 2019 22:25:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-okta-for-2fa-otp/m-p/3802306#M518659</guid>
      <dc:creator>Nathaniel Bell</dc:creator>
      <dc:date>2019-02-14T22:25:05Z</dc:date>
    </item>
    <item>
      <title>Re: ISE + OKTA for 2FA/OTP</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-okta-for-2fa-otp/m-p/4498758#M570901</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have Cisco ISE 3.0 trying to integrate OKTA&amp;nbsp; for&amp;nbsp; 2FA/OTP for RADIUS/TACACS+ based device administration&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Authentication via OKTA Push + AD&lt;/P&gt;&lt;P&gt;Authorization Via AD&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you please help me with any reference configuration ??&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Nov 2021 20:11:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-okta-for-2fa-otp/m-p/4498758#M570901</guid>
      <dc:creator>Mustafa9046</dc:creator>
      <dc:date>2021-11-05T20:11:26Z</dc:date>
    </item>
    <item>
      <title>Re: ISE + OKTA for 2FA/OTP</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-okta-for-2fa-otp/m-p/4498759#M570902</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have Cisco ISE 3.0 trying to integrate OKTA&amp;nbsp; for&amp;nbsp; 2FA/OTP for RADIUS/TACACS+ based device administration&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Authentication via OKTA Push + AD&lt;/P&gt;&lt;P&gt;Authorization Via AD&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you please help me with any reference configuration ??&lt;/P&gt;</description>
      <pubDate>Fri, 05 Nov 2021 20:12:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-okta-for-2fa-otp/m-p/4498759#M570902</guid>
      <dc:creator>Mustafa9046</dc:creator>
      <dc:date>2021-11-05T20:12:01Z</dc:date>
    </item>
    <item>
      <title>Re: ISE + OKTA for 2FA/OTP</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-okta-for-2fa-otp/m-p/4600833#M574387</link>
      <description>&lt;P&gt;Thank you so much, is it work well for Cisco CLI MFA authentications? like App Push / approve.? Thank you. !&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Apr 2022 12:58:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-okta-for-2fa-otp/m-p/4600833#M574387</guid>
      <dc:creator>kdurai12</dc:creator>
      <dc:date>2022-04-27T12:58:18Z</dc:date>
    </item>
  </channel>
</rss>

