<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE1.4 external admin access in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise1-4-external-admin-access/m-p/3498746#M539380</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was testing multiple scenarios for external (AD) admin access. As per &lt;A href="http://www.cisco.com/c/en/us/td/docs/security/ise/1-4/admin_guide/b_ise_admin_guide_14/b_ise_admin_guide_14_chapter_0110.html" title="http://www.cisco.com/c/en/us/td/docs/security/ise/1-4/admin_guide/b_ise_admin_guide_14/b_ise_admin_guide_14_chapter_0110.html"&gt;Cisco Identity Services Engine Administrator Guide, Release 1.4 - Manage Administrators and Admin Access Policies [Cisc…&lt;/A&gt;&lt;/P&gt;&lt;P&gt;we have two types of external admin access:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. external authentication and external authorization&lt;/P&gt;&lt;P&gt;2. external authentication and internal authorization&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;First one is clear for me and works without any problem, but I tried to test second one where we don't need to create RBAC policies for external admin groups. Here the problem comes. I am not able to successfully login unless I create RBAC policy with the &lt;SPAN style="text-decoration: underline;"&gt;external&lt;/SPAN&gt; identity group as a condition (internal doesn't work). As per the documentation, there is no need to create such policy. I tested this in 1.4 and 2.0 - the same result.&lt;/P&gt;&lt;P&gt;Did I misunderstand something in the documenation or this is new bug?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Veronika&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 17 Mar 2016 10:29:20 GMT</pubDate>
    <dc:creator>vchrenek</dc:creator>
    <dc:date>2016-03-17T10:29:20Z</dc:date>
    <item>
      <title>ISE1.4 external admin access</title>
      <link>https://community.cisco.com/t5/network-access-control/ise1-4-external-admin-access/m-p/3498746#M539380</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was testing multiple scenarios for external (AD) admin access. As per &lt;A href="http://www.cisco.com/c/en/us/td/docs/security/ise/1-4/admin_guide/b_ise_admin_guide_14/b_ise_admin_guide_14_chapter_0110.html" title="http://www.cisco.com/c/en/us/td/docs/security/ise/1-4/admin_guide/b_ise_admin_guide_14/b_ise_admin_guide_14_chapter_0110.html"&gt;Cisco Identity Services Engine Administrator Guide, Release 1.4 - Manage Administrators and Admin Access Policies [Cisc…&lt;/A&gt;&lt;/P&gt;&lt;P&gt;we have two types of external admin access:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. external authentication and external authorization&lt;/P&gt;&lt;P&gt;2. external authentication and internal authorization&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;First one is clear for me and works without any problem, but I tried to test second one where we don't need to create RBAC policies for external admin groups. Here the problem comes. I am not able to successfully login unless I create RBAC policy with the &lt;SPAN style="text-decoration: underline;"&gt;external&lt;/SPAN&gt; identity group as a condition (internal doesn't work). As per the documentation, there is no need to create such policy. I tested this in 1.4 and 2.0 - the same result.&lt;/P&gt;&lt;P&gt;Did I misunderstand something in the documenation or this is new bug?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Veronika&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Mar 2016 10:29:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise1-4-external-admin-access/m-p/3498746#M539380</guid>
      <dc:creator>vchrenek</dc:creator>
      <dc:date>2016-03-17T10:29:20Z</dc:date>
    </item>
    <item>
      <title>Re: ISE1.4 external admin access</title>
      <link>https://community.cisco.com/t5/network-access-control/ise1-4-external-admin-access/m-p/3498747#M539381</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyone experienced the same issue as me?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Veronika&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 Mar 2016 07:27:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise1-4-external-admin-access/m-p/3498747#M539381</guid>
      <dc:creator>vchrenek</dc:creator>
      <dc:date>2016-03-21T07:27:52Z</dc:date>
    </item>
    <item>
      <title>Re: ISE1.4 external admin access</title>
      <link>https://community.cisco.com/t5/network-access-control/ise1-4-external-admin-access/m-p/3498748#M539382</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I believe this is on a customer case. If so, please contact me offline for further discussions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;External auth with internal authorization is for token-based authentications, such as using RSA.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 Mar 2016 19:05:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise1-4-external-admin-access/m-p/3498748#M539382</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2016-03-21T19:05:11Z</dc:date>
    </item>
  </channel>
</rss>

