<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE 2.2 FMC user radius authentication in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-2-2-fmc-user-radius-authentication/m-p/3401728#M548327</link>
    <description>&lt;P&gt;Hello Marvin,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for the reply.&lt;/P&gt;
&lt;P&gt;The problem I have is the authorization through AD.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;check_auth_radius: szUser: XXX&lt;BR /&gt;RADIUS config file: /var/tmp/fF3Rri8AVH/radiusclient_0.conf&lt;BR /&gt;radiusauth - response: |User-Name=xxx|&lt;BR /&gt;radiusauth - response: |State=ReauthSession:0ac7c82cbjeyc4zZNkNstxPVbwVeRV79i9a1aaxK74wxv27M7rQ|&lt;BR /&gt;radiusauth - response: |Class=[x.x.x/S-1-5-32-545, S-1-5-21-588942262-2422670607-1746572812-94476]|&lt;BR /&gt;radiusauth - response: |Class=CACS:0ac7c82cbjeyc4zZNkNstxPVbwVeRV79i9a1aaxK74wxv27M7rQ:DKIX09INF-ISE-1/313846743/128638|&lt;BR /&gt;"xxx" RADIUS Authentication OK&lt;BR /&gt;No Access&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The authentication is working, though, I'm not able to authorized myself.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Not sure how the Class and Groups needs to be setup in the FMC or what attribute the ASA VPN should have in ISE.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Still working on this.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best regards.&lt;/P&gt;</description>
    <pubDate>Tue, 19 Jun 2018 08:44:19 GMT</pubDate>
    <dc:creator>stomoroga</dc:creator>
    <dc:date>2018-06-19T08:44:19Z</dc:date>
    <item>
      <title>ISE 2.2 FMC user radius authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-2-fmc-user-radius-authentication/m-p/3401086#M548325</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm working to have the user FMC user authentication through cisco ISE (with AD), but I cannot find a proper documentation, just some old stuff like &lt;A href="https://www.cisco.com/c/en/us/support/docs/security/firesight-management-center/118541-configure-firesight-00.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/firesight-management-center/118541-configure-firesight-00.html&lt;/A&gt; .&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does anyone has a proper example about how this must be done?&lt;/P&gt;
&lt;P&gt;ISE is on version 2.2 (already integrated with AD0, FMC on 6.2.3.1.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you!&lt;/P&gt;
&lt;P&gt;Best regards.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 18:58:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-2-fmc-user-radius-authentication/m-p/3401086#M548325</guid>
      <dc:creator>Erik Svendsen</dc:creator>
      <dc:date>2020-02-21T18:58:44Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.2 FMC user radius authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-2-fmc-user-radius-authentication/m-p/3401257#M548326</link>
      <description>&lt;P&gt;Even though it's several years old the basics of using ISE (or any other external RADIUS server) for FMC use authentication haven't changed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I use the method described in the article you mentioned with my&amp;nbsp; installation (ISE 2.4 and FMC 6.2.3.2) just fine.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jun 2018 15:27:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-2-fmc-user-radius-authentication/m-p/3401257#M548326</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2018-06-18T15:27:23Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.2 FMC user radius authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-2-fmc-user-radius-authentication/m-p/3401728#M548327</link>
      <description>&lt;P&gt;Hello Marvin,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for the reply.&lt;/P&gt;
&lt;P&gt;The problem I have is the authorization through AD.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;check_auth_radius: szUser: XXX&lt;BR /&gt;RADIUS config file: /var/tmp/fF3Rri8AVH/radiusclient_0.conf&lt;BR /&gt;radiusauth - response: |User-Name=xxx|&lt;BR /&gt;radiusauth - response: |State=ReauthSession:0ac7c82cbjeyc4zZNkNstxPVbwVeRV79i9a1aaxK74wxv27M7rQ|&lt;BR /&gt;radiusauth - response: |Class=[x.x.x/S-1-5-32-545, S-1-5-21-588942262-2422670607-1746572812-94476]|&lt;BR /&gt;radiusauth - response: |Class=CACS:0ac7c82cbjeyc4zZNkNstxPVbwVeRV79i9a1aaxK74wxv27M7rQ:DKIX09INF-ISE-1/313846743/128638|&lt;BR /&gt;"xxx" RADIUS Authentication OK&lt;BR /&gt;No Access&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The authentication is working, though, I'm not able to authorized myself.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Not sure how the Class and Groups needs to be setup in the FMC or what attribute the ASA VPN should have in ISE.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Still working on this.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best regards.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jun 2018 08:44:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-2-fmc-user-radius-authentication/m-p/3401728#M548327</guid>
      <dc:creator>stomoroga</dc:creator>
      <dc:date>2018-06-19T08:44:19Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.2 FMC user radius authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-2-fmc-user-radius-authentication/m-p/3814074#M548328</link>
      <description>&lt;P&gt;I've just configured this on FMC version&amp;nbsp;&lt;SPAN&gt;6.2.3.8 following this guide:&amp;nbsp;&lt;A href="https://goo.gl/pm1e4G" target="_blank"&gt;https://goo.gl/pm1e4G&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Just a note: under the RADIUS-Specific Parameters section, instead of "Class=User Identity Groups:Sourcefire Administrator" I've set it to "Class=Administrator".&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Best regards,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Matteo&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Mar 2019 08:54:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-2-fmc-user-radius-authentication/m-p/3814074#M548328</guid>
      <dc:creator>Matteo Comisso</dc:creator>
      <dc:date>2019-03-05T08:54:07Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.2 FMC user radius authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-2-fmc-user-radius-authentication/m-p/3824603#M548331</link>
      <description>&lt;P&gt;For what it's worth, I am having the very same problem/frustration.&lt;/P&gt;&lt;P&gt;I'd like to know the exact strings to enter into the FMC's&amp;nbsp;&lt;SPAN&gt;RADIUS-Specific Parameters Administrator field, and exactly what to use for the corresponding av-pair in the ISE authorization profile.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have tried&amp;nbsp;User-Category=Administrator on the FMC and&amp;nbsp;Access Type = ACCESS_ACCEPT&lt;BR /&gt;cisco-av-pair = User-Category=Administrator in ISE, as well as replacing the = with a :.&lt;/P&gt;&lt;P&gt;Also tried Class=Administrator and&amp;nbsp;cisco-av-pair = Class=Administrator (as well as replacing = with &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; but those don't work either.&lt;/P&gt;&lt;P&gt;Authentication is successful, but the user role assignment is NOT working.&amp;nbsp; I always end up with the default role of Security Analyst read-only.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can someone please clear this up once and for all??? So frustrated!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks very much.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Mar 2019 20:28:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-2-fmc-user-radius-authentication/m-p/3824603#M548331</guid>
      <dc:creator>N3t W0rK3r</dc:creator>
      <dc:date>2019-03-22T20:28:21Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.2 FMC user radius authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-2-fmc-user-radius-authentication/m-p/3824613#M548334</link>
      <description>&lt;P&gt;Of course, right after I made my earlier post I figured it out from this document:&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/firesight-management-center/118541-configure-firesight-00.html" target="_self"&gt;https://www.cisco.com/c/en/us/support/docs/security/firesight-management-center/118541-configure-firesight-00.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Pay close attention to the Tip!&lt;/P&gt;&lt;P&gt;Hopefully this helps someone else!&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="Capture.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/32607i8057010E1417F488/image-size/large?v=v2&amp;amp;px=999" role="button" title="Capture.PNG" alt="Capture.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Mar 2019 21:00:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-2-fmc-user-radius-authentication/m-p/3824613#M548334</guid>
      <dc:creator>N3t W0rK3r</dc:creator>
      <dc:date>2019-03-22T21:00:44Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.2 FMC user radius authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-2-fmc-user-radius-authentication/m-p/3858244#M548336</link>
      <description>&lt;P&gt;I just got this working. Heres how i did it:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In ISE 2.3:&lt;/P&gt;&lt;P&gt;AuthZ profile in Policy results, call your policy "FMC_Admin". When using the ASA VPN checkbox, clicke the dropdown menu and overwrite it with "Administrator", or whatever you want to call it. Lets say "Paladin" to make a point. Just make sure that name is carried over to FMC later.&lt;/P&gt;&lt;P&gt;The bottom of the attritbute details box should now say:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Access Type: ACCESS_ACCEPT&lt;/P&gt;&lt;P&gt;Class = Administrator (or Paladin)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Add this to your Authz policy as usual.&lt;/P&gt;&lt;P&gt;In the authentication conditions on the same policy, select the AD group that your admins will be a member of. This is local only to ISE and AD. FMC has no sight of this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now, in the example on the page, for the Administrator role on FMC, that box is filled with "Class = User Identity Groups: Sourcefire Administrator, overwrite this with "Class=Administrator (or Paladin)", where this is the name you created in your authz profile. Note this is local only to ISE and FMC&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And away you go!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 May 2019 11:49:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-2-fmc-user-radius-authentication/m-p/3858244#M548336</guid>
      <dc:creator>4qbuddy</dc:creator>
      <dc:date>2019-05-17T11:49:08Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.2 FMC user radius authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-2-fmc-user-radius-authentication/m-p/3902063#M548339</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have configured today Cisco FMC 6.2.3.10 with Aruba Clear Pass with Radius.&lt;/P&gt;&lt;P&gt;All went good until I had to pick the authentication method. I ended up with PAP. Does anyone know how can I "convince" FMC to agree for MSCHAP at least? How can I edit / choose Radius AUTH methold on Firepower Management Center?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Florin.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Aug 2019 13:34:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-2-fmc-user-radius-authentication/m-p/3902063#M548339</guid>
      <dc:creator>Florin Barhala</dc:creator>
      <dc:date>2019-08-02T13:34:56Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.2 FMC user radius authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-2-fmc-user-radius-authentication/m-p/3959516#M548341</link>
      <description>&lt;P&gt;Hello,&amp;nbsp; I was just wondering if you ever got your "a&lt;SPAN&gt;uthentication is successful, but the user role assignment is NOT working" working.&amp;nbsp;&lt;/SPAN&gt;&amp;nbsp; I can get full access to work but I am trying to get a read-only one working.&amp;nbsp; &amp;nbsp;Seems like they are all logging in as administrators.&amp;nbsp; Thanks!&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Nov 2019 20:14:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-2-fmc-user-radius-authentication/m-p/3959516#M548341</guid>
      <dc:creator>chad.drier</dc:creator>
      <dc:date>2019-11-15T20:14:04Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.2 FMC user radius authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-2-fmc-user-radius-authentication/m-p/3959899#M548343</link>
      <description>?You have your default role set as Admin. Did you create access profiles in ISE to pass role details to FMC?&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Sun, 17 Nov 2019 17:55:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-2-fmc-user-radius-authentication/m-p/3959899#M548343</guid>
      <dc:creator>4qbuddy</dc:creator>
      <dc:date>2019-11-17T17:55:53Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.2 FMC user radius authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-2-fmc-user-radius-authentication/m-p/3985367#M548345</link>
      <description>&lt;P&gt;Yes, you are correct, my default is admin.&amp;nbsp; I have not&amp;nbsp;&lt;SPAN&gt;created access profiles in ISE.&amp;nbsp; I will try that.&amp;nbsp; Thanks for the reply and help.&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Nov 2019 16:50:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-2-fmc-user-radius-authentication/m-p/3985367#M548345</guid>
      <dc:creator>chad.drier</dc:creator>
      <dc:date>2019-11-18T16:50:03Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.2 FMC user radius authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-2-fmc-user-radius-authentication/m-p/3985382#M548347</link>
      <description>&lt;P&gt;So I have this as my authorization result and still not working.&amp;nbsp; Is there something else I need to do?&amp;nbsp; Thanks again for the help!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2019-11-18 at 11.05.16 AM.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/61740iC577E9D7188A2E1D/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2019-11-18 at 11.05.16 AM.png" alt="Screen Shot 2019-11-18 at 11.05.16 AM.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Nov 2019 17:07:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-2-fmc-user-radius-authentication/m-p/3985382#M548347</guid>
      <dc:creator>chad.drier</dc:creator>
      <dc:date>2019-11-18T17:07:23Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.2 FMC user radius authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-2-fmc-user-radius-authentication/m-p/3985856#M548349</link>
      <description>&lt;P&gt;Good good. Now go to FMC and map that authz profile text to a role in FMC&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Nov 2019 12:36:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-2-fmc-user-radius-authentication/m-p/3985856#M548349</guid>
      <dc:creator>4qbuddy</dc:creator>
      <dc:date>2019-11-19T12:36:59Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.2 FMC user radius authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-2-fmc-user-radius-authentication/m-p/3987478#M548350</link>
      <description>&lt;P&gt;Thanks for the follow-up and help.&amp;nbsp; I am getting closer but not quite there.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So these are my ISE authorization profiles in ISE.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2019-11-21 at 1.59.59 PM.png" style="width: 200px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/62040iB9D65C1FF39724FF/image-size/small?v=v2&amp;amp;px=200" role="button" title="Screen Shot 2019-11-21 at 1.59.59 PM.png" alt="Screen Shot 2019-11-21 at 1.59.59 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Created these users on the FMC&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2019-11-21 at 2.04.21 PM.png" style="width: 200px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/62041i408769FE40A9FA6E/image-size/small?v=v2&amp;amp;px=200" role="button" title="Screen Shot 2019-11-21 at 2.04.21 PM.png" alt="Screen Shot 2019-11-21 at 2.04.21 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Do I set these custom roles as default users or something else?&amp;nbsp; &amp;nbsp;Didn't seem to work as expected but wondering if I can get your help?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2019-11-21 at 2.07.25 PM.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/62042iDD5598F4B00388C2/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screen Shot 2019-11-21 at 2.07.25 PM.png" alt="Screen Shot 2019-11-21 at 2.07.25 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Thu, 21 Nov 2019 20:08:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-2-fmc-user-radius-authentication/m-p/3987478#M548350</guid>
      <dc:creator>chad.drier</dc:creator>
      <dc:date>2019-11-21T20:08:27Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.2 FMC user radius authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-2-fmc-user-radius-authentication/m-p/3992358#M548351</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/600758"&gt;@4qbuddy&lt;/a&gt;&amp;nbsp; &amp;nbsp;Wondering if you can help me with this last step so I can cross this off my to-do list?&amp;nbsp; Thanks in advance.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Dec 2019 21:22:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-2-fmc-user-radius-authentication/m-p/3992358#M548351</guid>
      <dc:creator>chad.drier</dc:creator>
      <dc:date>2019-12-02T21:22:47Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.2 FMC user radius authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-2-fmc-user-radius-authentication/m-p/3992695#M548352</link>
      <description>&lt;P&gt;&lt;SPAN&gt;I see what you have done. You have created custom user roles on FMC. This is like creating another user on ISE for logging in to the GUI – its only controlled by ISE and not by an external authority like AD, if that makes sense? &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Rather than create usernames for the ISE roles being passed, tick the checkboxes for “Administrator” and “Security Analyst (Read Only)” that are on your bottom picture. Its different layout than mine but I would imagine that a box appears where you can add “Class = Cisco_FMC_Admin” and “Class = Cisco_FMC_ReadOnly”.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Try it out, let me know&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Dec 2019 12:35:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-2-fmc-user-radius-authentication/m-p/3992695#M548352</guid>
      <dc:creator>4qbuddy</dc:creator>
      <dc:date>2019-12-03T12:35:08Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.2 FMC user radius authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-2-fmc-user-radius-authentication/m-p/3993143#M548353</link>
      <description>&lt;P&gt;I got this working today and want to put an update on here to maybe help others.&lt;/P&gt;&lt;P&gt;Create your authorization profile in ISE&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2019-12-03 at 4.10.56 PM.png" style="width: 200px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/62702iADCA21076052DCB0/image-size/small?v=v2&amp;amp;px=200" role="button" title="Screen Shot 2019-12-03 at 4.10.56 PM.png" alt="Screen Shot 2019-12-03 at 4.10.56 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then on FMC side, go to users, external authentication, and add the following.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2019-12-03 at 4.11.24 PM.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/62703i31181E15F292C156/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screen Shot 2019-12-03 at 4.11.24 PM.png" alt="Screen Shot 2019-12-03 at 4.11.24 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now any user part of that AD group will have Admin access. At the bottom, I changed my default user role to read-only.&amp;nbsp; &amp;nbsp;You could create more ISE authorization profiles as needed if you have more roles.&amp;nbsp; Hope this helps!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your help also&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/600758"&gt;@4qbuddy&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Dec 2019 22:18:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-2-fmc-user-radius-authentication/m-p/3993143#M548353</guid>
      <dc:creator>chad.drier</dc:creator>
      <dc:date>2019-12-03T22:18:51Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.2 FMC user radius authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-2-fmc-user-radius-authentication/m-p/4062902#M559507</link>
      <description>&lt;P&gt;Thanks your reply was helpful.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a question, does setting in RADIUS-Specific Parameter overrides the permissions we have set for users on the FMC itself under System&amp;gt;Users&amp;gt;Users?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I had mixed results&lt;/P&gt;&lt;P&gt;on FMC "USER1" was given role of Intrusion Admin&lt;/P&gt;&lt;P&gt;Through ISE USER1 was set to get the Administrator role.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This worked, when USER1 logged on to FMC it got the full access at the same time Role on FMC got updated to Administrator Automatically&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On second test&lt;/P&gt;&lt;P&gt;On FMC USER1 was given rule of Administrator&lt;/P&gt;&lt;P&gt;Through ISE USER1 was set to get the Intrusion Admin role.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But it will still get the Administrator role.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have you run into similar situation before?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also is it MUST to configure user as external user on FMC for Radius External Authentication to work?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also How can I give multiple permission to a single user through Radius&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Apr 2020 16:36:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-2-fmc-user-radius-authentication/m-p/4062902#M559507</guid>
      <dc:creator>Nayan.Patel85</dc:creator>
      <dc:date>2020-04-09T16:36:01Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.2 FMC user radius authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-2-fmc-user-radius-authentication/m-p/4064764#M559560</link>
      <description>&lt;P&gt;I would check what the default role is set as on FMC external authentication. It sounds like you have set it to administrator&lt;/P&gt;</description>
      <pubDate>Mon, 13 Apr 2020 16:15:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-2-fmc-user-radius-authentication/m-p/4064764#M559560</guid>
      <dc:creator>4qbuddy</dc:creator>
      <dc:date>2020-04-13T16:15:18Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.2 FMC user radius authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-2-fmc-user-radius-authentication/m-p/4090340#M560596</link>
      <description>I have it working except, how can I assign multiple roles to same user. for example I want to assign Security Analyst and Intrusion Admin role to same user, how can I configure the Class attribute, I tried to use comma (did not work) I created separate Authz profiles one for Security Analyst and second for Intrusion Admin, and then assigned both on Authz Rule, but it takes only one.</description>
      <pubDate>Thu, 21 May 2020 20:46:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-2-fmc-user-radius-authentication/m-p/4090340#M560596</guid>
      <dc:creator>Nayan.Patel85</dc:creator>
      <dc:date>2020-05-21T20:46:13Z</dc:date>
    </item>
  </channel>
</rss>

