<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Authorization without Authentication in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/authorization-without-authentication/m-p/3486477#M535797</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Around 06:00 in this labminutes video &lt;A href="http://www.labminutes.com/sec0127_ssl_vpn_anyconnect_client_certificate_double_authentication_2" style="font-size: 10pt;"&gt;How to Configure Cisco SSL VPN AnyConnect Client Certificate and Double Authentication (Part 2)&lt;/A&gt;&lt;SPAN style="font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;shows the key is to continue with authentication failures.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 24 May 2017 19:55:31 GMT</pubDate>
    <dc:creator>hslai</dc:creator>
    <dc:date>2017-05-24T19:55:31Z</dc:date>
    <item>
      <title>Authorization without Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/authorization-without-authentication/m-p/3486474#M535789</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is it possible to use ISE for authorization without authentication?&amp;nbsp; My use case centers around using ISE to authorize SSLVPN connections in an SSO configuration, without having to supply credentials for authentication.&amp;nbsp; In this use case we would validate a user certificate on an ASA, and if it's accepted the ASA would pass the username over to ISE for group membership lookup in AD.&amp;nbsp; Based on the group memberships that are returned from AD, ISE would send back authorization permissions to the ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Matt&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 May 2017 19:56:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authorization-without-authentication/m-p/3486474#M535789</guid>
      <dc:creator>matthen</dc:creator>
      <dc:date>2017-05-23T19:56:13Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization without Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/authorization-without-authentication/m-p/3486475#M535791</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;See &lt;A _jive_internal="true" href="https://community.cisco.com/thread/80616"&gt;VPN certificate auth using ISE?&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 May 2017 20:05:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authorization-without-authentication/m-p/3486475#M535791</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2017-05-23T20:05:52Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization without Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/authorization-without-authentication/m-p/3486476#M535795</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you!&amp;nbsp; This was helpful, but do you know if there is a way to pass back a name from the certificate itself, like UPN or CN, and look that up in AD to get group membership(s) to determine which authorization policy to apply?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 May 2017 21:20:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authorization-without-authentication/m-p/3486476#M535795</guid>
      <dc:creator>matthen</dc:creator>
      <dc:date>2017-05-23T21:20:59Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization without Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/authorization-without-authentication/m-p/3486477#M535797</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Around 06:00 in this labminutes video &lt;A href="http://www.labminutes.com/sec0127_ssl_vpn_anyconnect_client_certificate_double_authentication_2" style="font-size: 10pt;"&gt;How to Configure Cisco SSL VPN AnyConnect Client Certificate and Double Authentication (Part 2)&lt;/A&gt;&lt;SPAN style="font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;shows the key is to continue with authentication failures.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 May 2017 19:55:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authorization-without-authentication/m-p/3486477#M535797</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2017-05-24T19:55:31Z</dc:date>
    </item>
  </channel>
</rss>

