<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: WSA External Authentication Service Type in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/wsa-external-authentication-service-type/m-p/3601567#M529945</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Currently, the RADIUS-IETF dictionary cannot be modified. You could try creating a NDG with WSAs, and then craft a policy set condition that reads NDG = WSA or Service-Type = Login to satisfy both in a single policy set.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 01 May 2017 14:11:59 GMT</pubDate>
    <dc:creator>howon</dc:creator>
    <dc:date>2017-05-01T14:11:59Z</dc:date>
    <item>
      <title>WSA External Authentication Service Type</title>
      <link>https://community.cisco.com/t5/network-access-control/wsa-external-authentication-service-type/m-p/3601566#M529944</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am setting up my WSA to use ISE as an external authentication method.&amp;nbsp; I have several other Cisco devices using ISE for Device Administration (RADIUS, not TACACS).&amp;nbsp; The routers and switches set their service type as Login.&amp;nbsp; The WSA sets its service type as&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 134217728.&amp;nbsp; I'd rather not create another Top Level Entry in my policy sets to handle the WSA.&amp;nbsp; I am looking to create a compound condition with a Boolean OR for the devices.&amp;nbsp; I can select RADIUS service type virtual for the routers and switched but I cannot enter 134217728 as a valid service type.&amp;nbsp; I only get the system provided drop downs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is is possible to add this to the existing RADIUS&amp;gt; Service Type dictionary or can I create my own dictionary with the service type of&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 134217728?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I know I can key on other attributes but I would like to use other attributes that come from the machine logins.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sam&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 30 Apr 2017 01:49:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wsa-external-authentication-service-type/m-p/3601566#M529944</guid>
      <dc:creator>scamarda</dc:creator>
      <dc:date>2017-04-30T01:49:18Z</dc:date>
    </item>
    <item>
      <title>Re: WSA External Authentication Service Type</title>
      <link>https://community.cisco.com/t5/network-access-control/wsa-external-authentication-service-type/m-p/3601567#M529945</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Currently, the RADIUS-IETF dictionary cannot be modified. You could try creating a NDG with WSAs, and then craft a policy set condition that reads NDG = WSA or Service-Type = Login to satisfy both in a single policy set.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 01 May 2017 14:11:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wsa-external-authentication-service-type/m-p/3601567#M529945</guid>
      <dc:creator>howon</dc:creator>
      <dc:date>2017-05-01T14:11:59Z</dc:date>
    </item>
    <item>
      <title>Re: WSA External Authentication Service Type</title>
      <link>https://community.cisco.com/t5/network-access-control/wsa-external-authentication-service-type/m-p/3601568#M529946</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Hosuk.&amp;nbsp; The customer ended up going with NDG configuration.&amp;nbsp; As an FYI, the WSA sends a Service-Type value of 134217728, not Login.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 01 May 2017 14:15:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wsa-external-authentication-service-type/m-p/3601568#M529946</guid>
      <dc:creator>scamarda</dc:creator>
      <dc:date>2017-05-01T14:15:43Z</dc:date>
    </item>
    <item>
      <title>Re: WSA External Authentication Service Type</title>
      <link>https://community.cisco.com/t5/network-access-control/wsa-external-authentication-service-type/m-p/3993807#M529947</link>
      <description>&lt;P&gt;Do you know if WSA can use TACACS+ as external authentication service in the latest version?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Dec 2019 01:13:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wsa-external-authentication-service-type/m-p/3993807#M529947</guid>
      <dc:creator>ricardocalvillo</dc:creator>
      <dc:date>2019-12-05T01:13:34Z</dc:date>
    </item>
  </channel>
</rss>

