<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE Admin access using external RADIUS in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-admin-access-using-external-radius/m-p/4034999#M558298</link>
    <description>&lt;P&gt;Hi JD,&lt;/P&gt;
&lt;P&gt;I'm not sure if it's officially documented as 'supported' anywhere, but I just setup a test in my lab using 2 ISE servers and I can successfully authenticate to the ISE GUI via a second external ISE server. My setup is [ISE 2.7] &amp;lt;=&amp;gt; [ISE 2.6].&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My 'ise27' is configured as a RADIUS client in 'ise26' and the necessary Policy Set, AuthC and AuthZ Policies are configured to simply return an ACCESS-ACCEPT result. I'm using an Internal User to test, but it should work with an external ID store as well.&lt;/P&gt;
&lt;P&gt;In 'ise27' I configured 'ise26' as a RADIUS Token server and configured the Admin Access to use 'ise26' for Authentication.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As with the OTP use case, ISE can only use internal authorisation, so you'll have to create shadow (External) user accounts in ISE for any RADIUS users that will need to connect to the ISE GUI.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;Greg&lt;/P&gt;</description>
    <pubDate>Mon, 24 Feb 2020 22:20:32 GMT</pubDate>
    <dc:creator>Greg Gibbs</dc:creator>
    <dc:date>2020-02-24T22:20:32Z</dc:date>
    <item>
      <title>ISE Admin access using external RADIUS</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-admin-access-using-external-radius/m-p/4034817#M558286</link>
      <description>&lt;P&gt;Trying to get clear understanding of utilizing an external RADIUS server for ISE admin access.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As I understand it, "RADIUS Token" external ID store is basically just RADIUS with only a single attribute supported.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a customer that needs to use an external RADIUS server (not OTP/Token) for ISE admin access.&amp;nbsp; The documentation mentions RSA SecureID as supported for Administrative access, but no mention of standard RADIUS auth.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;"&lt;SPAN&gt;External Authentication and Internal Authorization—The administrator’s authentication credentials come from the external identity source, and authorization and administrator role assignment take place using the local Cisco ISE database. This model is used for RSA SecurID authentication. This method requires you to configure the same username in both the external identity store and the local Cisco ISE database."&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Can a standard RADIUS server be used in the same way?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Feb 2020 16:57:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-admin-access-using-external-radius/m-p/4034817#M558286</guid>
      <dc:creator>joplant</dc:creator>
      <dc:date>2020-02-24T16:57:52Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Admin access using external RADIUS</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-admin-access-using-external-radius/m-p/4034999#M558298</link>
      <description>&lt;P&gt;Hi JD,&lt;/P&gt;
&lt;P&gt;I'm not sure if it's officially documented as 'supported' anywhere, but I just setup a test in my lab using 2 ISE servers and I can successfully authenticate to the ISE GUI via a second external ISE server. My setup is [ISE 2.7] &amp;lt;=&amp;gt; [ISE 2.6].&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My 'ise27' is configured as a RADIUS client in 'ise26' and the necessary Policy Set, AuthC and AuthZ Policies are configured to simply return an ACCESS-ACCEPT result. I'm using an Internal User to test, but it should work with an external ID store as well.&lt;/P&gt;
&lt;P&gt;In 'ise27' I configured 'ise26' as a RADIUS Token server and configured the Admin Access to use 'ise26' for Authentication.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As with the OTP use case, ISE can only use internal authorisation, so you'll have to create shadow (External) user accounts in ISE for any RADIUS users that will need to connect to the ISE GUI.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;Greg&lt;/P&gt;</description>
      <pubDate>Mon, 24 Feb 2020 22:20:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-admin-access-using-external-radius/m-p/4034999#M558298</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2020-02-24T22:20:32Z</dc:date>
    </item>
  </channel>
</rss>

