<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE Multi-session User Login, NAC Web Agent and 2FA Query in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-multi-session-user-login-nac-web-agent-and-2fa-query/m-p/3584922#M536250</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There are couple of questions that I need confirmation for&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Same user logged in from multiple locations at the same time, wired/wireless (dot1x) or via VPN. I know there isn’t anything inbuilt in ISE (?) to alert on user logged in from more than 1 location. We can run active session report, export it and do the co-relation separately.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Q: Can StealthWatch report this easily? How can we stop/alert (the admin) if this happens?&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;A customer has 50% of its workforce as 3rd parties and they need to posture every endpoint. What would be the best solution for this. NAC Web Agent I would assume. Does that also need admin rights for the Web Agent to be installed? I know they cannot remediate with Web Agent but is there any other option other than using AC?&lt;/LI&gt;&lt;LI&gt;ISE support of 2FA. I guess we do that via ASA today with multi authentications options. Is there any other way?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks,&lt;/P&gt;&lt;P&gt;Abhi&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 03 Feb 2017 12:04:16 GMT</pubDate>
    <dc:creator>Abhishek Kumar</dc:creator>
    <dc:date>2017-02-03T12:04:16Z</dc:date>
    <item>
      <title>ISE Multi-session User Login, NAC Web Agent and 2FA Query</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-multi-session-user-login-nac-web-agent-and-2fa-query/m-p/3584922#M536250</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There are couple of questions that I need confirmation for&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Same user logged in from multiple locations at the same time, wired/wireless (dot1x) or via VPN. I know there isn’t anything inbuilt in ISE (?) to alert on user logged in from more than 1 location. We can run active session report, export it and do the co-relation separately.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Q: Can StealthWatch report this easily? How can we stop/alert (the admin) if this happens?&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;A customer has 50% of its workforce as 3rd parties and they need to posture every endpoint. What would be the best solution for this. NAC Web Agent I would assume. Does that also need admin rights for the Web Agent to be installed? I know they cannot remediate with Web Agent but is there any other option other than using AC?&lt;/LI&gt;&lt;LI&gt;ISE support of 2FA. I guess we do that via ASA today with multi authentications options. Is there any other way?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks,&lt;/P&gt;&lt;P&gt;Abhi&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Feb 2017 12:04:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-multi-session-user-login-nac-web-agent-and-2fa-query/m-p/3584922#M536250</guid>
      <dc:creator>Abhishek Kumar</dc:creator>
      <dc:date>2017-02-03T12:04:16Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Queries</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-multi-session-user-login-nac-web-agent-and-2fa-query/m-p/3584923#M536252</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Abhishek,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. This is easily accomplished with ISE 2.2.&amp;nbsp; Navigate to &lt;STRONG&gt;Administration &amp;gt; System &amp;gt; Settings &amp;gt; Max Sessions&lt;/STRONG&gt;.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;IMG alt="MaxSessions.PNG" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/104410_MaxSessions.PNG" style="height: 296px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2.&amp;nbsp; This is covered in the &lt;A href="http://www.cisco.com/c/en/us/td/docs/security/nac/appliance/configuration_guide/45/cam/45cam-book/m_webagt.html"&gt;Clean Access Manager Installation and Configuration Guide&lt;/A&gt;.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;IMG alt="WebAgent.PNG" class="jive-image image-2" src="https://community.cisco.com/legacyfs/online/fusion/104411_WebAgent.PNG" style="height: 50px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3. You can perform both authentications of the Two-Factor Authentication flow within ISE.&amp;nbsp; For example using RSA as the second factor as found &lt;A href="http://http//www.cisco.com/c/en/us/td/docs/security/ise/2-1/admin_guide/b_ise_admin_guide_21/b_ise_admin_guide_20_chapter_01101.html#ID1516"&gt;Here in the Admin Guide&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="RSATwoFactor.PNG" class="jive-image image-3" src="https://community.cisco.com/legacyfs/online/fusion/104412_RSATwoFactor.PNG" style="height: 72px; width: 620px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Feb 2017 12:42:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-multi-session-user-login-nac-web-agent-and-2fa-query/m-p/3584923#M536252</guid>
      <dc:creator>Charlie Moreton</dc:creator>
      <dc:date>2017-02-03T12:42:07Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Queries</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-multi-session-user-login-nac-web-agent-and-2fa-query/m-p/3584924#M536256</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Brilliant, thanks Charles.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Feb 2017 14:42:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-multi-session-user-login-nac-web-agent-and-2fa-query/m-p/3584924#M536256</guid>
      <dc:creator>Abhishek Kumar</dc:creator>
      <dc:date>2017-02-03T14:42:20Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Multi-session User Login, NAC Web Agent and 2FA Query</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-multi-session-user-login-nac-web-agent-and-2fa-query/m-p/3584925#M536265</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Abhishek,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Few things to remember,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Point 1 above shows how it can be done. Again this is supported in ISE 2.2. However, I dont think we generate alerts on these.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Point 2 above, CCA is an older solution.I would suggest going the ISE route. In ISE 2.2, we have a way to do posture with no URL-redirect that can be used in 3rd party environments. You need Anyconnect for that. Anyconnect has a headless mode where this can be installed without UI. Anyconnect also supports web agent that could be used for non-admin.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For point 3, apart from RSA secure ID, any solution that supports RFC 2865 compliant token server is supported. EAP-chaining can also be considered for two step verification. You can use Symantec VIP with guest for two factor or SAML 2.0 SSO with form-auth. The compatibility guide lists the external ID servers we support&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/td/docs/security/ise/2-2/compatibility/ise_sdt.html#pgfId-109660" title="http://www.cisco.com/c/en/us/td/docs/security/ise/2-2/compatibility/ise_sdt.html#pgfId-109660"&gt;Cisco Identity Services Engine Network Component Compatibility, Release 2.2 - Cisco&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.cisco.com/docs/DOC-64012"&gt;ISE Design &amp;amp;amp; Integration Guides&lt;/A&gt; talks about Symantec VIP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Krishnan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Feb 2017 18:35:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-multi-session-user-login-nac-web-agent-and-2fa-query/m-p/3584925#M536265</guid>
      <dc:creator>kthiruve</dc:creator>
      <dc:date>2017-02-03T18:35:36Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Multi-session User Login, NAC Web Agent and 2FA Query</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-multi-session-user-login-nac-web-agent-and-2fa-query/m-p/3584926#M536274</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Krish! Much appreciated..&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Feb 2017 10:42:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-multi-session-user-login-nac-web-agent-and-2fa-query/m-p/3584926#M536274</guid>
      <dc:creator>Abhishek Kumar</dc:creator>
      <dc:date>2017-02-06T10:42:22Z</dc:date>
    </item>
  </channel>
</rss>

