<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE 2.4 Configuration of external Radius in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-2-4-configuration-of-external-radius/m-p/3401226#M548348</link>
    <description>&lt;P&gt;ISE is a Radius Server. Starting on version 1.3 TACACS service was added&amp;nbsp;because ACS is going end of life. You can use a Cisco switch with the proper IOS and practice wired authentication (MAB, 802.11x) on your laptop&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Go to youtube and look for LABMINUTES videos. They have good examples for practices&lt;/P&gt;</description>
    <pubDate>Mon, 18 Jun 2018 15:03:22 GMT</pubDate>
    <dc:creator>ajc</dc:creator>
    <dc:date>2018-06-18T15:03:22Z</dc:date>
    <item>
      <title>ISE 2.4 Configuration of external Radius</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-configuration-of-external-radius/m-p/3400926#M548342</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Could someone help me with the configuration of external radius between my two ISE severs?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have installed two trial versions of ISE&lt;/P&gt;
&lt;P&gt;isetest1 and isetest2&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;isetest1 is the front end server and isetest2 is the backend server. If I only need one, let me know. I only installed two as per the documentation which I linked to below.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Im trying to configure my ISE servers to preform radius authenticition in my lab environment. Once I get this working I want to move on to Tacacs. Right now I have a VM running Windows server 2016, Windows 7, and two ISE server instances. All configured with different static IPs. Both the winserver and 7 can ping both the ISE servers.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The ISE servers know nothing of the other devices on the network. I have attempted to follow the guide on Cisco document site found here:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/213239-configure-external-radius-servers-on-ise.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/213239-configure-external-radius-servers-on-ise.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is it possible to have the ISE server preform radius authenticiton for this small network? I can add more network host if need be. But I figured I would start small then work my way up.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Anyone offer a short and sweet how to that’s a bit more clearer then the document of which I linked to above?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I find it odd that neither ISE server sees anything on the network. No traffic what so ever.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have much to learn about ISE&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any help would be much appreciated&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Michael&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 18:58:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-configuration-of-external-radius/m-p/3400926#M548342</guid>
      <dc:creator>mpbaker82</dc:creator>
      <dc:date>2020-02-21T18:58:40Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.4 Configuration of external Radius</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-configuration-of-external-radius/m-p/3400940#M548344</link>
      <description>&lt;P&gt;I think you need to share a bit more about your test setup.&lt;/P&gt;
&lt;P&gt;What are you using to generate radius access requests into the front-end ISE server?&amp;nbsp; If ISE01 (front end server) is supposed to act as the proxy, then it needs to be able to receive the traffic from the NAS (client)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Are you saying that you cannot see any traffic in that ISE server's Radius LiveLog?&amp;nbsp; If so, then you need to check the basics, like, IP connectivity between NAS and ISE01 (front end) - can you ping from either end?&amp;nbsp; Did you add that NAS as a Client into ISE01?&amp;nbsp; Check that the Radius shared secret is identical in ISE01 config&amp;nbsp;and the NAS.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jun 2018 05:36:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-configuration-of-external-radius/m-p/3400940#M548344</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2018-06-18T05:36:17Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.4 Configuration of external Radius</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-configuration-of-external-radius/m-p/3401125#M548346</link>
      <description>&lt;P&gt;I have a Radius Server running on a Ubiquity USG that controls wireless access. However i can install a radius server on my window sever if needed. I was informed that ISE can act as a radius server, i assume that isn't the case. Ill install a Radius Server on the windows server 2016.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I dont have a NAS to act as the client. I was hoping to use a windows machine or Cisco switch or router to act as the radius client. Do I need to find a NAS to make this happen? If so, then ill go buy one.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there any documentation on how to set this up?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Im very new to ISE so im still trying to figure out how it works. Any help would be much appreciated&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jun 2018 13:19:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-configuration-of-external-radius/m-p/3401125#M548346</guid>
      <dc:creator>mpbaker82</dc:creator>
      <dc:date>2018-06-18T13:19:47Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.4 Configuration of external Radius</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-4-configuration-of-external-radius/m-p/3401226#M548348</link>
      <description>&lt;P&gt;ISE is a Radius Server. Starting on version 1.3 TACACS service was added&amp;nbsp;because ACS is going end of life. You can use a Cisco switch with the proper IOS and practice wired authentication (MAB, 802.11x) on your laptop&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Go to youtube and look for LABMINUTES videos. They have good examples for practices&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jun 2018 15:03:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-4-configuration-of-external-radius/m-p/3401226#M548348</guid>
      <dc:creator>ajc</dc:creator>
      <dc:date>2018-06-18T15:03:22Z</dc:date>
    </item>
  </channel>
</rss>

