<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ISE Two Factor Authentication / Authorisation with different User Identity Store in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-two-factor-authentication-authorisation-with-different/m-p/3510293#M527148</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Mario,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Authorization policy is meant to send suitable privileges for network admins that includes TACACS+ profile and command sets.&lt;/P&gt;&lt;P&gt;In authorization policy you can also verify it the users are part of a certain group as in the case of AD.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Authentication policy is what you need to verify credentials.&lt;/P&gt;&lt;P&gt;If you need to authenticate different TACACS+ service(login vs enable), you can do it as Hsing pointed out above.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope it clarifies.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Krishnan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 30 Aug 2017 23:56:24 GMT</pubDate>
    <dc:creator>kthiruve</dc:creator>
    <dc:date>2017-08-30T23:56:24Z</dc:date>
    <item>
      <title>Cisco ISE Two Factor Authentication / Authorisation with different User Identity Store</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-two-factor-authentication-authorisation-with-different/m-p/3510291#M527138</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello everybody ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My customer would like the following scenario for Device Administration (TACAS):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Authentication is to take place via the RSA SecureID server (user name and RSA passcode).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The authorization is to be carried out via the ISE User Identity Store. &lt;/P&gt;&lt;P&gt;(User name and password or only the password)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;At the moment you can register with user name and RSA passcode&lt;/P&gt;&lt;P&gt;And for an ENABLE on the network component will be renewed&lt;/P&gt;&lt;P&gt;the RSA passcode.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here, however, the password from the ISE User Identity Store is to be queried.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a suitable authorization policy to implement this scenario?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Geetings Mario&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Aug 2017 08:27:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-two-factor-authentication-authorisation-with-different/m-p/3510291#M527138</guid>
      <dc:creator>data-dynamic</dc:creator>
      <dc:date>2017-08-30T08:27:13Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Two Factor Authentication / Authorisation with different User Identity Store</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-two-factor-authentication-authorisation-with-different/m-p/3510292#M527140</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think you are asking about this feature -- Login Authentication and Enable Authorization Differentiation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Given the usernames are the same in RSA and Internal Users, we may have the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE border="1" cellpadding="0" cellspacing="0" height="99" style="width: 604px; height: 85px;"&gt;&lt;THEAD&gt;&lt;TR&gt;&lt;TD colspan="3" style="border: inset 1.0pt; background: #CCCCCC; padding: .75pt .75pt .75pt .75pt;" width="504"&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&lt;SPAN style="font-size: 9.0pt;"&gt;Authentication Policy&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/THEAD&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD style="border: none; border-left: inset 1.0pt; background: white; padding: 0 1.45pt 0 1.45pt;" valign="top" width="18"&gt;&lt;DIV align="center"&gt;&lt;TABLE border="1" cellpadding="0" cellspacing="0" style="background-color: #00b304; border: none;"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD style="border: solid black 1.0pt;" valign="top" width="16"&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;TD colspan="2" style="border: none; border-right: outset 1.0pt; background: white; padding: 0 1.45pt 0 2.9pt;" valign="top" width="486"&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&lt;SPAN style="font-size: 9.0pt; background: #FFFFCC;"&gt;Enable Password&lt;/SPAN&gt;&lt;SPAN style="font-size: 9.0pt;"&gt; &lt;SPAN style="color: #7f7f7f;"&gt;: &lt;/SPAN&gt;If &lt;SPAN style="background: #FFFFCC;"&gt;TACACS:Service EQUALS Enable&lt;/SPAN&gt;&lt;SPAN style="color: #7f7f7f;"&gt; Allow Protocols : &lt;/SPAN&gt;&lt;SPAN style="background: #FFFFCC;"&gt;Default Device Admin&lt;/SPAN&gt;&amp;nbsp;&amp;nbsp; &lt;SPAN style="color: #7f7f7f;"&gt;and &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD style="border-top: none; border-left: inset 1.0pt; border-bottom: outset 1.0pt; border-right: none; background: white; padding: 0 1.45pt 0 1.45pt;" valign="top" width="18"&gt;&lt;P align="center" class="GoldTableText"&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD style="border: none; border-bottom: outset 1.0pt; background: #00B050; padding: 0 1.45pt 0 2.9pt;" valign="top" width="18"&gt;&lt;P&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD style="border-top: none; border-left: none; border-bottom: outset 1.0pt; border-right: outset 1.0pt; background: white; padding: 0 5.4pt 0 5.4pt;" valign="top" width="468"&gt;&lt;P class="GoldTableText"&gt;Default &lt;SPAN style="color: #7f7f7f;"&gt;use:&lt;/SPAN&gt; &lt;SPAN style="background-color: #ffffcc;"&gt;Internal Users&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD style="border: inset 1.0pt; border-top: none; background: white; padding: 0 1.45pt 0 1.45pt;" valign="top" width="18"&gt;&lt;TABLE border="1" cellpadding="0" cellspacing="0" style="background-color: #00b304; border: none;"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD style="border: solid black 1.0pt;" valign="top" width="16"&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/TD&gt;&lt;TD colspan="2" style="border-top: none; border-left: none; border-bottom: inset 1.0pt; border-right: inset 1.0pt; background: white; padding: 0 1.45pt 0 2.9pt;" valign="top" width="486"&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&lt;SPAN style="font-size: 9.0pt;"&gt;Default Rule (if no match) : Allow Protocols : Default Device Admin&amp;nbsp;&amp;nbsp; and use: &lt;SPAN style="background-color: #ffffcc;"&gt;RSA&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Aug 2017 15:56:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-two-factor-authentication-authorisation-with-different/m-p/3510292#M527140</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2017-08-30T15:56:12Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Two Factor Authentication / Authorisation with different User Identity Store</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-two-factor-authentication-authorisation-with-different/m-p/3510293#M527148</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Mario,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Authorization policy is meant to send suitable privileges for network admins that includes TACACS+ profile and command sets.&lt;/P&gt;&lt;P&gt;In authorization policy you can also verify it the users are part of a certain group as in the case of AD.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Authentication policy is what you need to verify credentials.&lt;/P&gt;&lt;P&gt;If you need to authenticate different TACACS+ service(login vs enable), you can do it as Hsing pointed out above.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope it clarifies.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Krishnan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Aug 2017 23:56:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-two-factor-authentication-authorisation-with-different/m-p/3510293#M527148</guid>
      <dc:creator>kthiruve</dc:creator>
      <dc:date>2017-08-30T23:56:24Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Two Factor Authentication / Authorisation with different User Identity Store</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-two-factor-authentication-authorisation-with-different/m-p/3510294#M527155</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello hslai,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the answer. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will test it and report back with the results.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Greeting Mario&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 Aug 2017 08:41:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-two-factor-authentication-authorisation-with-different/m-p/3510294#M527155</guid>
      <dc:creator>data-dynamic</dc:creator>
      <dc:date>2017-08-31T08:41:03Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Two Factor Authentication / Authorisation with different User Identity Store</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-two-factor-authentication-authorisation-with-different/m-p/3510295#M527161</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Krishnan , &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the answer. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Greeting Mario&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 Aug 2017 08:41:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-two-factor-authentication-authorisation-with-different/m-p/3510295#M527161</guid>
      <dc:creator>data-dynamic</dc:creator>
      <dc:date>2017-08-31T08:41:18Z</dc:date>
    </item>
  </channel>
</rss>

