<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: proxy dot1x request to third party RADIUS in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/proxy-dot1x-request-to-third-party-radius/m-p/3532295#M537559</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Great, thanks Hari, I will give it a try&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Francesca&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;==========================================================&lt;/P&gt;&lt;P&gt;Francesca Martucci – CISSP # 481718&lt;/P&gt;&lt;P&gt;CONSULTING SYSTEMS ENGINEER.SECURITY SALES&lt;/P&gt;&lt;P&gt;UKI&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;==========================================================&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 19 Sep 2016 07:07:50 GMT</pubDate>
    <dc:creator>martucci</dc:creator>
    <dc:date>2016-09-19T07:07:50Z</dc:date>
    <item>
      <title>proxy dot1x request to third party RADIUS</title>
      <link>https://community.cisco.com/t5/network-access-control/proxy-dot1x-request-to-third-party-radius/m-p/3532292#M537551</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello, &lt;/P&gt;&lt;P&gt;my customer would like to offload a dot1x request to an external RADIUS, but only after checking that the client is in&amp;nbsp; a specific group of known MAC addresses on the local server.&lt;/P&gt;&lt;P&gt;This is not easily implemented as the proxy is configured inthe authentication policy, before I can actually perform a check on the local database.&lt;/P&gt;&lt;P&gt;I was wondering if anyone has any creative idea on how it would be possible to satisfy the request&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Sep 2016 07:08:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/proxy-dot1x-request-to-third-party-radius/m-p/3532292#M537551</guid>
      <dc:creator>martucci</dc:creator>
      <dc:date>2016-09-15T07:08:09Z</dc:date>
    </item>
    <item>
      <title>Re: proxy dot1x request to third party RADIUS</title>
      <link>https://community.cisco.com/t5/network-access-control/proxy-dot1x-request-to-third-party-radius/m-p/3532293#M537553</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Per internal discussion, this is not possible using proxy.&amp;nbsp; We cannot authenticate via ISE using MAB and then proxy same request to another RADIUS server for a secondary 802.1X auth.&amp;nbsp;&amp;nbsp; I recommend using RADIUS Token to authenticate user in ISE and then use external RADIUS server for authorization only. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To use proxy, you can leverage RADIUS, VSAs, Network Access and Device attributes to determine whether to proxy or to which server to proxy request.&amp;nbsp; You can then process response through local ISE policy for authorization (for example, match on local profile or endpoint ID group).&amp;nbsp; However, you cannot authorize first, and then send to proxy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Craig&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Sep 2016 19:05:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/proxy-dot1x-request-to-third-party-radius/m-p/3532293#M537553</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2016-09-16T19:05:33Z</dc:date>
    </item>
    <item>
      <title>Re: proxy dot1x request to third party RADIUS</title>
      <link>https://community.cisco.com/t5/network-access-control/proxy-dot1x-request-to-third-party-radius/m-p/3532294#M537556</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You may explore IBNS 2.0 for this. ISE can authorize the MAB request with a service template name, and the switch can then clear the session and initiate a new 802.1X session (with a different RADIUS server) on the service-template active status. Haven’t validated this, but a policy something like this could do the trick:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;TABLE border="1"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;
&lt;P&gt;aaa new-model&lt;/P&gt;
&lt;P&gt;&lt;STRONG style="font-size: 10pt;"&gt;aaa group server radius mab-servers&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt; server name ise&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;aaa group server radius 1x-servers&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt; server name non-ise&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;aaa authentication login default group radius&lt;/P&gt;
&lt;P&gt;aaa authentication login console none&lt;/P&gt;
&lt;P&gt;aaa authentication dot1x default group radius&lt;/P&gt;
&lt;P&gt;aaa authentication dot1x mab-servers group mab-servers&lt;/P&gt;
&lt;P&gt;aaa authentication dot1x 1x-servers group 1x-servers&lt;/P&gt;
&lt;P&gt;aaa authorization exec default local &lt;/P&gt;
&lt;P&gt;aaa authorization network default group radius &lt;/P&gt;
&lt;P&gt;aaa authorization network 1x-servers group 1x-servers &lt;/P&gt;
&lt;P&gt;aaa authorization network mab-servers group mab-servers &lt;/P&gt;
&lt;P&gt;aaa authorization auth-proxy default group radius &lt;/P&gt;
&lt;P&gt;aaa accounting identity default start-stop group radius&lt;/P&gt;
&lt;P&gt;aaa session-id common&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;radius-server dead-criteria time 15 tries 3&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;radius server ise&lt;/P&gt;
&lt;P&gt; address ipv4 172.20.254.4 auth-port 1645 acct-port 1646&lt;/P&gt;
&lt;P&gt; automate-tester username dummy&lt;/P&gt;
&lt;P&gt; key xxxxxx&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;radius server non-ise&lt;/P&gt;
&lt;P&gt; address ipv4 172.20.254.8 auth-port 1645 acct-port 1646&lt;/P&gt;
&lt;P&gt; automate-tester username dummy&lt;/P&gt;
&lt;P&gt; key xxxxxx&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;policy-map type control subscriber ent-access-pol&lt;/P&gt;
&lt;P&gt; event session-started match-all&lt;/P&gt;
&lt;P&gt;&amp;nbsp; 10 class always do-until-failure&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp; 10 authenticate using mab aaa authc-list 1x-servers authz-list mab-servers&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt; event template-activated match-all&lt;/P&gt;
&lt;P&gt;&amp;nbsp; 10 class mab-classified do-all&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp; 10 terminate mab&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp; 20 authenticate using dot1x aaa authc-list non-ise authz-list &lt;SPAN style="font-family: 'Lucida Grande', Arial, Helvetica, sans-serif;"&gt;non-ise&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp; 30 deactivate service-template mab-classified&lt;/P&gt;
&lt;P&gt; event authentication-failure match-first&lt;/P&gt;
&lt;P&gt;&amp;nbsp; 10 class DOT1X_NO_RESP do-until-failure&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp; 10 terminate dot1x&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp; 20 authentication-restart 60&lt;/P&gt;
&lt;P&gt;&amp;nbsp; 20 class MAB_FAILED do-until-failure&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp; 10 terminate mab&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp; 20 authentication-restart 60&lt;/P&gt;
&lt;P&gt;&amp;nbsp; 30 class always do-until-failure&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp; 10 terminate dot1x&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp; 20 terminate mab&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp; 30 authentication-restart 60&lt;/P&gt;
&lt;P&gt; event agent-found match-all&lt;/P&gt;
&lt;P&gt;&amp;nbsp; 10 class always do-until-failure&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp; 10 terminate mab&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp; 20 authenticate using dot1x priority 10&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;class-map type control subscriber match-all DOT1X_NO_RESP&lt;/P&gt;
&lt;P&gt; match method dot1x&lt;/P&gt;
&lt;P&gt; match result-type method dot1x agent-not-found&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;class-map type control subscriber match-all MAB_FAILED&lt;/P&gt;
&lt;P&gt; match method mab&lt;/P&gt;
&lt;P&gt; match result-type method mab authoritative&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;class-map type control subscriber match-all mab-classified&lt;/P&gt;
&lt;P&gt; match service-template mab-classified&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;service-template mab-classified&lt;/P&gt;
&lt;P&gt; description dummy template&lt;/P&gt;
&lt;P&gt; tag dummy&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/BLOCKQUOTE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Sep 2016 20:57:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/proxy-dot1x-request-to-third-party-radius/m-p/3532294#M537556</guid>
      <dc:creator>hariholla</dc:creator>
      <dc:date>2016-09-16T20:57:01Z</dc:date>
    </item>
    <item>
      <title>Re: proxy dot1x request to third party RADIUS</title>
      <link>https://community.cisco.com/t5/network-access-control/proxy-dot1x-request-to-third-party-radius/m-p/3532295#M537559</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Great, thanks Hari, I will give it a try&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Francesca&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;==========================================================&lt;/P&gt;&lt;P&gt;Francesca Martucci – CISSP # 481718&lt;/P&gt;&lt;P&gt;CONSULTING SYSTEMS ENGINEER.SECURITY SALES&lt;/P&gt;&lt;P&gt;UKI&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;==========================================================&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Sep 2016 07:07:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/proxy-dot1x-request-to-third-party-radius/m-p/3532295#M537559</guid>
      <dc:creator>martucci</dc:creator>
      <dc:date>2016-09-19T07:07:50Z</dc:date>
    </item>
  </channel>
</rss>

