<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE as RADIUS Proxy and Attribute &amp;quot;Reply-Message&amp;quot; in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-as-radius-proxy-and-attribute-quot-reply-message-quot/m-p/3488087#M535725</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;HI,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One of our customer would like to use ISE as RADIUS proxy and forward the requests to external RADIUS&lt;/P&gt;&lt;P&gt;(to check username/password against DB and responds with "group" information in "Reply-Message" attribute).&lt;/P&gt;&lt;P&gt;When the response is received by ISE, they want to compare the "Reply-Message" sent &lt;SPAN style="font-size: 10pt;"&gt;by the external RADIUS &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;with &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;some &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;value and do authorization based on the comparison result. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Our questions are:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Is "Reply-Message" attribute supported in ISE Authorization process ? We couldn't find it in the attribute options.&lt;/P&gt;&lt;P&gt;2) If "Reply-Message" it not supported, any way we can achieve it using ISE ? (The setup currently works with 3-rd party RADIUS server).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is "Continue to authorization policy" setting the way to go ? We know there is RADIUS proxy enhancements in new ISE release but aren't quite sure &lt;SPAN style="font-size: 10pt;"&gt;if it supports the "Reply-Message" attribute.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please advise or comment. Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jim&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 31 May 2017 10:13:44 GMT</pubDate>
    <dc:creator>kaiychen</dc:creator>
    <dc:date>2017-05-31T10:13:44Z</dc:date>
    <item>
      <title>ISE as RADIUS Proxy and Attribute "Reply-Message"</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-as-radius-proxy-and-attribute-quot-reply-message-quot/m-p/3488087#M535725</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;HI,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One of our customer would like to use ISE as RADIUS proxy and forward the requests to external RADIUS&lt;/P&gt;&lt;P&gt;(to check username/password against DB and responds with "group" information in "Reply-Message" attribute).&lt;/P&gt;&lt;P&gt;When the response is received by ISE, they want to compare the "Reply-Message" sent &lt;SPAN style="font-size: 10pt;"&gt;by the external RADIUS &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;with &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;some &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;value and do authorization based on the comparison result. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Our questions are:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Is "Reply-Message" attribute supported in ISE Authorization process ? We couldn't find it in the attribute options.&lt;/P&gt;&lt;P&gt;2) If "Reply-Message" it not supported, any way we can achieve it using ISE ? (The setup currently works with 3-rd party RADIUS server).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is "Continue to authorization policy" setting the way to go ? We know there is RADIUS proxy enhancements in new ISE release but aren't quite sure &lt;SPAN style="font-size: 10pt;"&gt;if it supports the "Reply-Message" attribute.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please advise or comment. Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jim&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 31 May 2017 10:13:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-as-radius-proxy-and-attribute-quot-reply-message-quot/m-p/3488087#M535725</guid>
      <dc:creator>kaiychen</dc:creator>
      <dc:date>2017-05-31T10:13:44Z</dc:date>
    </item>
    <item>
      <title>Re: ISE as RADIUS Proxy and Attribute "Reply-Message"</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-as-radius-proxy-and-attribute-quot-reply-message-quot/m-p/3488088#M535729</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Per RFC2865, this attribute is only valid for responses, not requests...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;5.44.&amp;nbsp; Table of Attributes&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; The following table provides a guide to which attributes may be found&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; in which kinds of packets, and in what quantity.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; Request&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Accept&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Reject&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Challenge&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; #&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Attribute&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0+&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0+&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0+&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 18&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Reply-Message&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To change the "direction" specified for this default System dictionary attribute would require enhancement request, but due to nature, would require ability to override standard dictionary rules.&amp;nbsp; Another option would be to have customer leverage a different attribute in RADIUS response from external server which has been flagged for "both" directions, i.e. inbound and outbound.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Craig&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 31 May 2017 13:27:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-as-radius-proxy-and-attribute-quot-reply-message-quot/m-p/3488088#M535729</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2017-05-31T13:27:20Z</dc:date>
    </item>
    <item>
      <title>Re: ISE as RADIUS Proxy and Attribute "Reply-Message"</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-as-radius-proxy-and-attribute-quot-reply-message-quot/m-p/3488089#M535730</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Isn't the external radius server in this case following the rfc?  It appears to be responding with an accept which includes the reply message.  Seems to conform to the rfc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Warning: I either dictated this to my device, or typed it with my thumbs. Erroneous words are a feature, not a typo.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 31 May 2017 13:55:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-as-radius-proxy-and-attribute-quot-reply-message-quot/m-p/3488089#M535730</guid>
      <dc:creator>gbekmezi-DD</dc:creator>
      <dc:date>2017-05-31T13:55:23Z</dc:date>
    </item>
    <item>
      <title>Re: ISE as RADIUS Proxy and Attribute "Reply-Message"</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-as-radius-proxy-and-attribute-quot-reply-message-quot/m-p/3488090#M535731</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Correct.&amp;nbsp; The external server is using it in a response, but the ask is to now to have ISE interpret the response as an INBOUND attribute in order to allow Authorization Policy matching.&amp;nbsp; This capability would require dictionary change.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 31 May 2017 14:03:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-as-radius-proxy-and-attribute-quot-reply-message-quot/m-p/3488090#M535731</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2017-05-31T14:03:59Z</dc:date>
    </item>
    <item>
      <title>Re: ISE as RADIUS Proxy and Attribute "Reply-Message"</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-as-radius-proxy-and-attribute-quot-reply-message-quot/m-p/3488091#M535732</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is the remote Radius server defined as a RADIUS Token server in ISE?&amp;nbsp; If yes, then the answer is simple.&amp;nbsp; The remote server will have to reply with a Cisco AVPair&amp;nbsp;&amp;nbsp; ACS:&amp;lt;whatever_attr_name_you_want&amp;gt; - and then you define that under RADIUS Token Identity Sources 'Authorization'.&amp;nbsp; You will have the &amp;lt;whatever_attr_name_you_want&amp;gt; available in your AuthZ policies.&amp;nbsp; If you don't use a custom name, then ISE defaults to &lt;STRONG&gt;&lt;EM&gt;CiscoSecure-Group-Id.&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That means your external radius server needs to return a Cisco AVPair that looks like this (the User is in GroupXYZ) - you can't use anything other than a CiscoAVPair containing ACS...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cisco-AVPair = '&lt;SPAN style="color: #e84c22;"&gt;ACS&lt;/SPAN&gt;:CiscoSecure-Group-Id=GroupXYZ'&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If your ISE 'RADIUS Token server' definition is called 'MyExtRadius' then create a new Rule, containing a new Condition (using policy Condition 'Advance Option) and select the attribute from the 'MyExtRadius' dictionary. Your AuthZ policy rule looks something like&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If MyExtRadius:CiscoSecure-Group-Id EQUALS blah then &amp;lt;Permissions&amp;gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Jun 2017 00:55:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-as-radius-proxy-and-attribute-quot-reply-message-quot/m-p/3488091#M535732</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2017-06-01T00:55:08Z</dc:date>
    </item>
    <item>
      <title>Re: ISE as RADIUS Proxy and Attribute "Reply-Message"</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-as-radius-proxy-and-attribute-quot-reply-message-quot/m-p/3488092#M535733</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Craig,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the clarification and suggestion. It helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jim&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Jun 2017 05:38:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-as-radius-proxy-and-attribute-quot-reply-message-quot/m-p/3488092#M535733</guid>
      <dc:creator>kaiychen</dc:creator>
      <dc:date>2017-06-01T05:38:58Z</dc:date>
    </item>
    <item>
      <title>Re: ISE as RADIUS Proxy and Attribute "Reply-Message"</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-as-radius-proxy-and-attribute-quot-reply-message-quot/m-p/3488093#M535734</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Arne,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the information and detail instructions.&lt;/P&gt;&lt;P&gt;We will try it out to see if it helps in our case. Appreciate the input and help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jim&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Jun 2017 05:41:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-as-radius-proxy-and-attribute-quot-reply-message-quot/m-p/3488093#M535734</guid>
      <dc:creator>kaiychen</dc:creator>
      <dc:date>2017-06-01T05:41:04Z</dc:date>
    </item>
    <item>
      <title>Re: ISE as RADIUS Proxy and Attribute "Reply-Message"</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-as-radius-proxy-and-attribute-quot-reply-message-quot/m-p/3488094#M535735</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;SPAN style="color: #3d3d3d; font-family: arial; font-size: 12px;"&gt;Arne,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have same issue for ISE and FreeRadius Server. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We try the "RADIUS Token" with freeradius. It's work. The ISE RADIUS log can see the attribute&amp;nbsp; "CiscoSecure-Group-Id = GroupXYZ'. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But I have other issue, RADIUS Token only support EAP-GTC.&amp;nbsp; So, when I use the iPhone auth method is PEAP (EAP-MSCHAPv2), the authentication method is no supported.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If use the External Radius proxy, the Authentication is pass for windows NB and iPhone.&lt;/P&gt;&lt;P&gt;We try add the attribute in freeRadius users file, but the ISE Radius log can't see anyone attribute value. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Our question is which one attribute support freeradius reply value to ISE? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;eq:&lt;/P&gt;&lt;P&gt;aa05 Cleartext-Password := "qazxsw"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; service-type = NAS-Prompt-User,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Cisco-AVPair = "ACS:Campus-GroupInfo=GroupXYZ"&lt;/P&gt;&lt;P&gt;#&lt;/P&gt;&lt;P&gt;aa06 Cleartext-Password := "qazxsw"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Filter-ID = GroupXYZ&lt;/P&gt;&lt;P&gt;#&lt;/P&gt;&lt;P&gt;aa07 Auth-Type := EAP,Cleartext-Password := "qazxsw"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Service-Type = Framed-User,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Tunnel-Type = 13,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Tunnel-Medium-Type = 6,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Tunnel-Private-Group-ID := "GroupXYZ"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt; Jimmy &lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Jun 2017 15:18:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-as-radius-proxy-and-attribute-quot-reply-message-quot/m-p/3488094#M535735</guid>
      <dc:creator>jimmy.wucy</dc:creator>
      <dc:date>2017-06-19T15:18:41Z</dc:date>
    </item>
    <item>
      <title>Re: ISE as RADIUS Proxy and Attribute "Reply-Message"</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-as-radius-proxy-and-attribute-quot-reply-message-quot/m-p/3488095#M535736</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;IOS devices do support PEAP(GTC). However, you have no way of selecting it on the client. You have to modify Allowed Protocols authentication result to only allow GTC.&lt;/P&gt;&lt;P&gt;Apple tries to make it easier for users to use their devices, so they don't let you choose the authentication scheme.&lt;/P&gt;&lt;P&gt;This can be exploited like shown in this video: &lt;A href="https://www.youtube.com/watch?v=HoihKhQWZ7k" title="https://www.youtube.com/watch?v=HoihKhQWZ7k"&gt;Stealing 802.1x Credentials with Rogue AP &amp;amp; RADIUS server - YouTube&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Jun 2017 01:20:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-as-radius-proxy-and-attribute-quot-reply-message-quot/m-p/3488095#M535736</guid>
      <dc:creator>vibobrov</dc:creator>
      <dc:date>2017-06-20T01:20:07Z</dc:date>
    </item>
  </channel>
</rss>

