<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Integration between ISE and ADFS in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/integration-between-ise-and-adfs/m-p/3699276#M519934</link>
    <description>&lt;P&gt;In my notes, I put this as a bullet item:&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;FONT color="#000080"&gt;(ADFS) Update the global settings of the primary authentication to Forms Authentication, because ISE is not supporting other authentication methods (CSCvb32728)&lt;/FONT&gt;&lt;/EM&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 02 Sep 2018 02:11:55 GMT</pubDate>
    <dc:creator>hslai</dc:creator>
    <dc:date>2018-09-02T02:11:55Z</dc:date>
    <item>
      <title>Integration between ISE and ADFS</title>
      <link>https://community.cisco.com/t5/network-access-control/integration-between-ise-and-adfs/m-p/3562712#M519928</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="font-size: 12pt; font-family: Calibri, sans-serif; color: #000000;"&gt;&lt;SPAN style="font-size: 11pt;"&gt;Hi team, &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 12pt; font-family: Calibri, sans-serif; color: #000000;"&gt;&lt;SPAN style="font-size: 11pt;"&gt;I am looking from some help, we are doing an onsite demo with one of our customers in Ecuador. For this, we need to use MS ADFS as SAML provider to ISE. We have been searching about how to do this integration but looks like it is not well documented. As we understand the main problem with this is how to map the attributes returning from ADFS to ISE.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 12pt; font-family: Calibri, sans-serif; color: #000000;"&gt;&lt;SPAN style="font-size: 11pt;"&gt;&lt;A href="https://cisco-marketing.hosted.jivesoftware.com/message/248362" style="color: #954f72; text-decoration: underline;"&gt;https://cisco-marketing.hosted.jivesoftware.com/message/248362&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 12pt; font-family: Calibri, sans-serif; color: #000000;"&gt;&lt;SPAN style="font-size: 11pt;"&gt;Also we have opened a case with TAC and they suggest to use a third party vendor for this integration (Ping Federate).&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 12pt; font-family: Calibri, sans-serif; color: #000000;"&gt;&lt;SPAN style="font-size: 11pt;"&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine-21/200545-Configure-ISE-2-1-Sponsor-Portal-with-Pi.html" style="color: #954f72; text-decoration: underline;"&gt;https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine-21/200545-Configure-ISE-2-1-Sponsor-Portal-with-Pi.html&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 12pt; font-family: Calibri, sans-serif; color: #000000;"&gt;&lt;SPAN style="font-size: 11pt;"&gt;Please may you confirm if this integration is possible without using a third party vendor? if the answer is yes please may you provide some details about how to do this integration?&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 12pt; font-family: Calibri, sans-serif; color: #000000;"&gt;&lt;SPAN style="font-size: 11pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 12pt; font-family: Calibri, sans-serif; color: #000000;"&gt;&lt;SPAN style="font-size: 11pt;"&gt;Best regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 12pt; font-family: Calibri, sans-serif; color: #000000;"&gt;&lt;SPAN style="font-size: 11pt;"&gt;Robert Landires&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Nov 2017 20:35:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/integration-between-ise-and-adfs/m-p/3562712#M519928</guid>
      <dc:creator>rlandire</dc:creator>
      <dc:date>2017-11-13T20:35:29Z</dc:date>
    </item>
    <item>
      <title>Re: Integration between ISE and ADFS</title>
      <link>https://community.cisco.com/t5/network-access-control/integration-between-ise-and-adfs/m-p/3562713#M519929</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, I will unicast you the info I have.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Nov 2017 20:39:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/integration-between-ise-and-adfs/m-p/3562713#M519929</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2017-11-13T20:39:41Z</dc:date>
    </item>
    <item>
      <title>Re: Integration between ISE and ADFS</title>
      <link>https://community.cisco.com/t5/network-access-control/integration-between-ise-and-adfs/m-p/3562714#M519930</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you very much Hsing-tsu&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Nov 2017 23:45:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/integration-between-ise-and-adfs/m-p/3562714#M519930</guid>
      <dc:creator>rlandire</dc:creator>
      <dc:date>2017-11-13T23:45:36Z</dc:date>
    </item>
    <item>
      <title>Re: Integration between ISE and ADFS</title>
      <link>https://community.cisco.com/t5/network-access-control/integration-between-ise-and-adfs/m-p/3562715#M519931</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, got the same problem. Would like to know how to integrate the ISE (version 2.3) with the ADFS.&lt;/P&gt;&lt;P&gt;Thanks a lot!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 May 2018 08:38:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/integration-between-ise-and-adfs/m-p/3562715#M519931</guid>
      <dc:creator>jan.murin</dc:creator>
      <dc:date>2018-05-07T08:38:56Z</dc:date>
    </item>
    <item>
      <title>Re: Integration between ISE and ADFS</title>
      <link>https://community.cisco.com/t5/network-access-control/integration-between-ise-and-adfs/m-p/3562716#M519932</link>
      <description>&lt;P&gt;&lt;SPAN style="text-decoration: line-through;"&gt;I need your email address&lt;/SPAN&gt; to share a copy of my notes, which were written for our internal use only ~ 20 months ago. It needs re-validated before publishing here. Incidentally, Cisco TAC is working on a similar article.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;[2018-May-11] I published it a blog -- &lt;A id="link_149" class="page-link lia-link-navigation lia-custom-event" href="https://community.cisco.com/t5/security-blogs/notes-on-adfs-as-saml-idp-for-ise-user-portals/ba-p/3661806" target="_blank"&gt;Notes on ADFS as SAML IdP for ISE User Portals&lt;/A&gt;&lt;SPAN style="font-size: 10pt;"&gt;&amp;nbsp;after some clean-ups.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 02 Sep 2018 02:10:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/integration-between-ise-and-adfs/m-p/3562716#M519932</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-09-02T02:10:46Z</dc:date>
    </item>
    <item>
      <title>Re: Integration between ISE and ADFS</title>
      <link>https://community.cisco.com/t5/network-access-control/integration-between-ise-and-adfs/m-p/3688773#M519933</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I came back here after some time. I have read the official document how to integrate sponsor portal with AD FS (&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine-23/213352-configure-ise-2-3-sponsor-portal-with-ms.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine-23/213352-configure-ise-2-3-sponsor-portal-with-ms.html&lt;/A&gt;).&lt;/P&gt;
&lt;P&gt;I have to admit that I do not&amp;nbsp;have any knowledge how ADFS works, but we got a problem with the SSO.&lt;/P&gt;
&lt;P&gt;We done all the steps described in the document, however the domain user (on a domain computer) is always redirected to the ADFS webpage to enter his credentials before entering the sponsor portal.&lt;/P&gt;
&lt;P&gt;I thought that when using ADFS for SSO, the domain user will not be required to enter the credentials anywhere. The user has logged into the computer so the ADFS system should have the credentials and therefore should automatically log the user into the sponsor portal without any intervention from the user.&lt;/P&gt;
&lt;P&gt;Or I am missing something?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks a lot!&lt;/P&gt;</description>
      <pubDate>Wed, 15 Aug 2018 09:41:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/integration-between-ise-and-adfs/m-p/3688773#M519933</guid>
      <dc:creator>jan.murin</dc:creator>
      <dc:date>2018-08-15T09:41:38Z</dc:date>
    </item>
    <item>
      <title>Re: Integration between ISE and ADFS</title>
      <link>https://community.cisco.com/t5/network-access-control/integration-between-ise-and-adfs/m-p/3699276#M519934</link>
      <description>&lt;P&gt;In my notes, I put this as a bullet item:&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;FONT color="#000080"&gt;(ADFS) Update the global settings of the primary authentication to Forms Authentication, because ISE is not supporting other authentication methods (CSCvb32728)&lt;/FONT&gt;&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 02 Sep 2018 02:11:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/integration-between-ise-and-adfs/m-p/3699276#M519934</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-09-02T02:11:55Z</dc:date>
    </item>
    <item>
      <title>Re: Integration between ISE and ADFS</title>
      <link>https://community.cisco.com/t5/network-access-control/integration-between-ise-and-adfs/m-p/3699725#M519935</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;we have that set as described, but still no luck. The user is still redirected to the ADFS portal where the credentials are requested.&lt;/P&gt;
&lt;P&gt;To be sure, does the SSO working for the sponsor portal without any interaction from the user?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Sep 2018 12:46:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/integration-between-ise-and-adfs/m-p/3699725#M519935</guid>
      <dc:creator>jan.murin</dc:creator>
      <dc:date>2018-09-03T12:46:29Z</dc:date>
    </item>
    <item>
      <title>Re: Integration between ISE and ADFS</title>
      <link>https://community.cisco.com/t5/network-access-control/integration-between-ise-and-adfs/m-p/3699828#M519936</link>
      <description>&lt;P&gt;Using SAML with ISE is currently supported with form-based authentication so it's expected to redirect to the ADFS portal to login.&lt;/P&gt;
&lt;P&gt;I think you are expecting Kerberos auth. For ISE Sponsor Portal, ISE 2.4 has a new option for Kerberos auth --&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/admin_guide/b_ise_admin_guide_24/b_ise_admin_guide_24_new_chapter_011100.html#reference_5F10051EBA9046468988DCEB54C60853" target="_blank"&gt;Portal Settings for Sponsor Portals&lt;/A&gt;:&lt;/P&gt;
&lt;P&gt;...&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN class="ph uicontrol"&gt;Allow Kerberos&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;EM&gt;—Use Kerberos to authenticate a sponsor for access to the sponsor portal. Kerberos SSO is performed inside the secure tunnel after the browser establishes the SSL connection with ISE.&lt;/EM&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;...&lt;/P&gt;</description>
      <pubDate>Mon, 03 Sep 2018 15:28:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/integration-between-ise-and-adfs/m-p/3699828#M519936</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-09-03T15:28:53Z</dc:date>
    </item>
    <item>
      <title>Re: Integration between ISE and ADFS</title>
      <link>https://community.cisco.com/t5/network-access-control/integration-between-ise-and-adfs/m-p/3700113#M519937</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;thanks for that information. Going to test&amp;nbsp;version 2.4.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Jan&lt;/P&gt;</description>
      <pubDate>Tue, 04 Sep 2018 06:08:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/integration-between-ise-and-adfs/m-p/3700113#M519937</guid>
      <dc:creator>jan.murin</dc:creator>
      <dc:date>2018-09-04T06:08:08Z</dc:date>
    </item>
    <item>
      <title>Re: Integration between ISE and ADFS</title>
      <link>https://community.cisco.com/t5/network-access-control/integration-between-ise-and-adfs/m-p/3711235#M519938</link>
      <description>&lt;P&gt;Hi Jan,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm curious if you had luck with getting SSO working with 2.4?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;Scott&lt;/P&gt;</description>
      <pubDate>Fri, 21 Sep 2018 16:45:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/integration-between-ise-and-adfs/m-p/3711235#M519938</guid>
      <dc:creator>scott.stapleton</dc:creator>
      <dc:date>2018-09-21T16:45:29Z</dc:date>
    </item>
    <item>
      <title>Re: Integration between ISE and ADFS</title>
      <link>https://community.cisco.com/t5/network-access-control/integration-between-ise-and-adfs/m-p/3711844#M519939</link>
      <description>&lt;P&gt;Hi Scott,&lt;/P&gt;
&lt;P&gt;Not for now,&amp;nbsp;I played with it for a long time without success.&lt;/P&gt;
&lt;P&gt;Still waiting for some help from the local cisco guy, so maybe in the near future I will have more information.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Sep 2018 06:44:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/integration-between-ise-and-adfs/m-p/3711844#M519939</guid>
      <dc:creator>jan.murin</dc:creator>
      <dc:date>2018-09-24T06:44:11Z</dc:date>
    </item>
  </channel>
</rss>

