<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Duo Security with Cisco ISE in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/duo-security-with-cisco-ise/m-p/4042314#M558648</link>
    <description>Hi&lt;BR /&gt;&lt;BR /&gt;First of all, you've attached a screenshot of your real config of your duo proxy which includes your keys. Remove the screenshot and reattach it by hiding these keys.&lt;BR /&gt;&lt;BR /&gt;Why on ISE are you creating a network access user?&lt;BR /&gt;PAP is available on authentication protocol. Normally ISE receives an authentication request and forward it to your DUO using the protocol. Is this what you want to do?</description>
    <pubDate>Sun, 08 Mar 2020 05:05:05 GMT</pubDate>
    <dc:creator>Francesco Molino</dc:creator>
    <dc:date>2020-03-08T05:05:05Z</dc:date>
    <item>
      <title>Duo Security with Cisco ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/duo-security-with-cisco-ise/m-p/4041288#M558622</link>
      <description>&lt;P&gt;&lt;FONT&gt;&lt;FONT&gt;&lt;FONT&gt;&lt;FONT&gt;&lt;FONT&gt;&lt;FONT&gt;Hola, ¿es posible habilitar PAP con comunicación con Duo Prsoxy y Ciso ISE?&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT&gt;&lt;FONT&gt;&lt;FONT&gt;&lt;FONT&gt;&lt;FONT&gt;&lt;FONT&gt;En la documentación de Duo sobre Fortinet y Palo Alto, es posible activar la opción para especificar el tipo de protocolo que se utilizará para comunicarse con el proxy duo y el NAC, pero en Cisco Ise no encuentro esa opción.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT&gt;&lt;FONT&gt;&lt;FONT&gt;&lt;FONT&gt;&lt;FONT&gt;&lt;FONT&gt;Adjunto mi proxy settings.cfg &lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT&gt;&lt;FONT&gt;&lt;FONT&gt;&lt;FONT&gt;&lt;FONT&gt;&lt;FONT&gt;registros de Cisco Duo&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT&gt;&lt;FONT&gt;&lt;FONT&gt;&lt;FONT&gt;&lt;FONT&gt;&lt;FONT&gt;La configuración que tengo en ISE es: &lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT&gt;&lt;FONT&gt;&lt;FONT&gt;&lt;FONT&gt;&lt;FONT&gt;&lt;FONT&gt;Usuario local creado especificando que es un usuario Duo.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="duo.png" style="width: 763px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/68570i16419157CE819C08/image-size/large?v=v2&amp;amp;px=999" role="button" title="duo.png" alt="duo.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="0893BB99-6575-488F-9CC7-9D97C783D914.jpeg" style="width: 882px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/68768i14A51DECD1EEAFA9/image-size/large?v=v2&amp;amp;px=999" role="button" title="0893BB99-6575-488F-9CC7-9D97C783D914.jpeg" alt="0893BB99-6575-488F-9CC7-9D97C783D914.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="logduo.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/68572i9893ED3F7774561F/image-size/large?v=v2&amp;amp;px=999" role="button" title="logduo.png" alt="logduo.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Mar 2020 12:35:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/duo-security-with-cisco-ise/m-p/4041288#M558622</guid>
      <dc:creator>PQR</dc:creator>
      <dc:date>2020-03-09T12:35:38Z</dc:date>
    </item>
    <item>
      <title>Re: Duo Security with Cisco ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/duo-security-with-cisco-ise/m-p/4042314#M558648</link>
      <description>Hi&lt;BR /&gt;&lt;BR /&gt;First of all, you've attached a screenshot of your real config of your duo proxy which includes your keys. Remove the screenshot and reattach it by hiding these keys.&lt;BR /&gt;&lt;BR /&gt;Why on ISE are you creating a network access user?&lt;BR /&gt;PAP is available on authentication protocol. Normally ISE receives an authentication request and forward it to your DUO using the protocol. Is this what you want to do?</description>
      <pubDate>Sun, 08 Mar 2020 05:05:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/duo-security-with-cisco-ise/m-p/4042314#M558648</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2020-03-08T05:05:05Z</dc:date>
    </item>
    <item>
      <title>Re: Duo Security with Cisco ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/duo-security-with-cisco-ise/m-p/4042740#M558672</link>
      <description>&lt;P&gt;&lt;SPAN&gt;PAP is available on authentication protocol. Normally ISE receives an authentication request and forward it to your DUO using the protocol. Is this what you want to do?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Answer: Yes, I want to do that, but acordly the logs, I need PAP authentication between ISE and Duo proxy and I can’t find the option for set PAP authentication because I set up radios external(duo)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;this is the Web page that i follow:&lt;/P&gt;&lt;P&gt;&lt;A href="https://duo.com/docs/ciscoise-radius" target="_blank" rel="noopener"&gt;https://duo.com/docs/ciscoise-radius&lt;/A&gt;&lt;/P&gt;&lt;P&gt;I need 802.1x authentication&lt;/P&gt;</description>
      <pubDate>Mon, 09 Mar 2020 14:05:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/duo-security-with-cisco-ise/m-p/4042740#M558672</guid>
      <dc:creator>PQR</dc:creator>
      <dc:date>2020-03-09T14:05:16Z</dc:date>
    </item>
    <item>
      <title>Re: Duo Security with Cisco ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/duo-security-with-cisco-ise/m-p/4043150#M558708</link>
      <description>The doc you're looking at is specially for vpn where authentication will be in pap by default.&lt;BR /&gt;&lt;BR /&gt;For 802.1x, you'll need to use saml and so have duo as gateway but not the way you're implementing it.&lt;BR /&gt;As far as i know, duo proxy doesn't support mschapv2.&lt;BR /&gt;</description>
      <pubDate>Tue, 10 Mar 2020 02:24:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/duo-security-with-cisco-ise/m-p/4043150#M558708</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2020-03-10T02:24:15Z</dc:date>
    </item>
    <item>
      <title>Re: Duo Security with Cisco ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/duo-security-with-cisco-ise/m-p/4045731#M558881</link>
      <description>&lt;P&gt;Hi, Do you have a guide configuration with that?&lt;/P&gt;&lt;P&gt;I’ve attached the guide configuration that I follow, but in that guide I don’t see the policy section that I need to configured because when I login in the ssid with DUOAG, i can’t do ping to the DAG portal, only can do ping to ISE IP, but when I Access to the dag portal since the wired network, I have Access. I think is a ise policy config&lt;/P&gt;&lt;P&gt;The ISE, AD,DNS,DUOAG are in the same network&lt;/P&gt;</description>
      <pubDate>Fri, 13 Mar 2020 19:47:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/duo-security-with-cisco-ise/m-p/4045731#M558881</guid>
      <dc:creator>PQR</dc:creator>
      <dc:date>2020-03-13T19:47:46Z</dc:date>
    </item>
    <item>
      <title>Re: Duo Security with Cisco ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/duo-security-with-cisco-ise/m-p/4045748#M558882</link>
      <description>For Duo Gateway, here is the doc: &lt;A href="https://duo.com/docs/dng" target="_blank"&gt;https://duo.com/docs/dng&lt;/A&gt;&lt;BR /&gt;</description>
      <pubDate>Fri, 13 Mar 2020 21:06:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/duo-security-with-cisco-ise/m-p/4045748#M558882</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2020-03-13T21:06:29Z</dc:date>
    </item>
    <item>
      <title>Re: Duo Security with Cisco ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/duo-security-with-cisco-ise/m-p/4045772#M558883</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="duo issue.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/69091i1103CB20D6C51247/image-size/large?v=v2&amp;amp;px=999" role="button" title="duo issue.png" alt="duo issue.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That was the error message that show me after I permit by a push the duo 2fa&lt;/P&gt;</description>
      <pubDate>Fri, 13 Mar 2020 22:54:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/duo-security-with-cisco-ise/m-p/4045772#M558883</guid>
      <dc:creator>PQR</dc:creator>
      <dc:date>2020-03-13T22:54:25Z</dc:date>
    </item>
    <item>
      <title>Re: Duo Security with Cisco ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/duo-security-with-cisco-ise/m-p/4045998#M558900</link>
      <description>Have you followed the link below: &lt;A href="https://community.cisco.com/t5/security-documents/network-access-and-segmentation-with-duo-mfa-and-ise/ta-p/3752831" target="_blank"&gt;https://community.cisco.com/t5/security-documents/network-access-and-segmentation-with-duo-mfa-and-ise/ta-p/3752831&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;When are you getting the error you sent on the guest portal?&lt;BR /&gt;</description>
      <pubDate>Sun, 15 Mar 2020 01:07:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/duo-security-with-cisco-ise/m-p/4045998#M558900</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2020-03-15T01:07:32Z</dc:date>
    </item>
    <item>
      <title>Re: Duo Security with Cisco ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/duo-security-with-cisco-ise/m-p/4481753#M570241</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am facing the same problem with duo proxy.&lt;/P&gt;&lt;P&gt;Can you tell me please, were you able to resolve it without using DAG?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Oct 2021 10:05:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/duo-security-with-cisco-ise/m-p/4481753#M570241</guid>
      <dc:creator>kaiyrkhan1</dc:creator>
      <dc:date>2021-10-07T10:05:51Z</dc:date>
    </item>
  </channel>
</rss>

