<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Using ISE with Microsoft Direct Access (DA) VPN in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/using-ise-with-microsoft-direct-access-da-vpn/m-p/3570385#M540948</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We have a customer evaluating ISE for his global Deployment. They are currently using&amp;nbsp; Microsoft Direct Access as their VPN solution. Can we use ISE as a Policy engine for VPN Users while he continues to use Microsoft Direct Access as their VPN&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 09 Feb 2016 06:27:39 GMT</pubDate>
    <dc:creator>angogate</dc:creator>
    <dc:date>2016-02-09T06:27:39Z</dc:date>
    <item>
      <title>Using ISE with Microsoft Direct Access (DA) VPN</title>
      <link>https://community.cisco.com/t5/network-access-control/using-ise-with-microsoft-direct-access-da-vpn/m-p/3570385#M540948</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We have a customer evaluating ISE for his global Deployment. They are currently using&amp;nbsp; Microsoft Direct Access as their VPN solution. Can we use ISE as a Policy engine for VPN Users while he continues to use Microsoft Direct Access as their VPN&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Feb 2016 06:27:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/using-ise-with-microsoft-direct-access-da-vpn/m-p/3570385#M540948</guid>
      <dc:creator>angogate</dc:creator>
      <dc:date>2016-02-09T06:27:39Z</dc:date>
    </item>
    <item>
      <title>Re: Using ISE with Microsoft Direct Access (DA) VPN</title>
      <link>https://community.cisco.com/t5/network-access-control/using-ise-with-microsoft-direct-access-da-vpn/m-p/3570386#M540952</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;if you're looking at pointing their VPN solution to use for RADIUS AAA then yes it should work via standard radius support, not really sure what you're gaining by doing this as to me it would seem that just using Microsoft DA against AD would be enough? Unless the solution requires RADIUS?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;micrsoft direct access requires special servers that terminate ipsec tunnel and then forward access to their services&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For ise posture services &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA VPN supports radius coa and URL redirect to correctly work with ISE posture&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;otherwise for non cisco deployment you would use the following setup&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ise requires special setup to work with IPN (inline posture node) where the radius server needs to talk to ISE&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/td/docs/security/ise/1-2/user_guide/ise_user_guide/ise_ipep_deploy.html#pgfId-1261555" title="http://www.cisco.com/c/en/us/td/docs/security/ise/1-2/user_guide/ise_user_guide/ise_ipep_deploy.html#pgfId-1261555"&gt;Cisco Identity Services Engine User Guide, Release 1.2 - Setting up Inline Posture [Cisco Identity Services Engine] - Ci…&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Feb 2016 11:35:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/using-ise-with-microsoft-direct-access-da-vpn/m-p/3570386#M540952</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2016-02-09T11:35:00Z</dc:date>
    </item>
    <item>
      <title>Re: Using ISE with Microsoft Direct Access (DA) VPN</title>
      <link>https://community.cisco.com/t5/network-access-control/using-ise-with-microsoft-direct-access-da-vpn/m-p/3570387#M540956</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Keep in mind if you are on ISE 2.0 or plan to upgrade to 2.0, IPNs are no longer supported.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is best to design ISE without IPNs at this point as ISE 2.0 and above will see an increase in 3rd party devices support.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Feb 2016 14:48:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/using-ise-with-microsoft-direct-access-da-vpn/m-p/3570387#M540956</guid>
      <dc:creator>Cory Peterson</dc:creator>
      <dc:date>2016-02-09T14:48:44Z</dc:date>
    </item>
    <item>
      <title>Re: Using ISE with Microsoft Direct Access (DA) VPN</title>
      <link>https://community.cisco.com/t5/network-access-control/using-ise-with-microsoft-direct-access-da-vpn/m-p/3570388#M540961</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Very good point&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We will be making third party support better in future releases but not likely to help with Microsoft direct access, will direct to the team to make sure&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Feb 2016 14:59:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/using-ise-with-microsoft-direct-access-da-vpn/m-p/3570388#M540961</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2016-02-09T14:59:13Z</dc:date>
    </item>
  </channel>
</rss>

