<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Unable to access Sponsor portal with LDAP as a external identity in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/unable-to-access-sponsor-portal-with-ldap-as-a-external-identity/m-p/4117105#M561648</link>
    <description>&lt;P&gt;One main difference between LDAP and AD or ISE internal user is&amp;nbsp;ISE is not supporting nested LDAP group memberships.&lt;/P&gt;
&lt;P&gt;Please ensure the user is a direct member of the LDAP group, which mapping to an ISE sponsor group.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
    <pubDate>Sat, 11 Jul 2020 23:06:10 GMT</pubDate>
    <dc:creator>hslai</dc:creator>
    <dc:date>2020-07-11T23:06:10Z</dc:date>
    <item>
      <title>Unable to access Sponsor portal with LDAP as a external identity</title>
      <link>https://community.cisco.com/t5/network-access-control/unable-to-access-sponsor-portal-with-ldap-as-a-external-identity/m-p/4117097#M561644</link>
      <description>&lt;P&gt;Hello Team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Need your help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Unable to access Sponsor portal with LDAP credentials.&lt;/P&gt;&lt;P&gt;configuration is correct. sponsor portal is working for AD &amp;amp; internal users but not for LDAP users&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can anyone please help ??&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advanced.&lt;/P&gt;</description>
      <pubDate>Sat, 11 Jul 2020 21:43:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/unable-to-access-sponsor-portal-with-ldap-as-a-external-identity/m-p/4117097#M561644</guid>
      <dc:creator>siddhesh.parab@orange.com1</dc:creator>
      <dc:date>2020-07-11T21:43:02Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to access Sponsor portal with LDAP as a external identity</title>
      <link>https://community.cisco.com/t5/network-access-control/unable-to-access-sponsor-portal-with-ldap-as-a-external-identity/m-p/4117105#M561648</link>
      <description>&lt;P&gt;One main difference between LDAP and AD or ISE internal user is&amp;nbsp;ISE is not supporting nested LDAP group memberships.&lt;/P&gt;
&lt;P&gt;Please ensure the user is a direct member of the LDAP group, which mapping to an ISE sponsor group.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 11 Jul 2020 23:06:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/unable-to-access-sponsor-portal-with-ldap-as-a-external-identity/m-p/4117105#M561648</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2020-07-11T23:06:10Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to access Sponsor portal with LDAP as a external identity</title>
      <link>https://community.cisco.com/t5/network-access-control/unable-to-access-sponsor-portal-with-ldap-as-a-external-identity/m-p/4117157#M561651</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for information.&lt;/P&gt;&lt;P&gt;Could you suggest where i will get those setting in LDAP server ??&lt;/P&gt;</description>
      <pubDate>Sun, 12 Jul 2020 07:03:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/unable-to-access-sponsor-portal-with-ldap-as-a-external-identity/m-p/4117157#M561651</guid>
      <dc:creator>siddhesh.parab@orange.com1</dc:creator>
      <dc:date>2020-07-12T07:03:00Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to access Sponsor portal with LDAP as a external identity</title>
      <link>https://community.cisco.com/t5/network-access-control/unable-to-access-sponsor-portal-with-ldap-as-a-external-identity/m-p/4120910#M561770</link>
      <description>&lt;P&gt;I occasionally dabble in a bit of LDAP and I am always chuffed when things work. It's quite a complex thing to deal with and we are spoilt when dealing with AD (which hides all that LDAP stuff under the hood).&lt;/P&gt;
&lt;P&gt;One tool I can recommend is &lt;A href="https://docs.microsoft.com/en-us/sysinternals/downloads/adexplorer" target="_self"&gt;AD Explorer from Microsoft SysInternals&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Use this tool to bind to your LDAP/AD directory to see where things live and what attributes they have. I had to use this recently to figure out why things were failing when I switched my ISE AuthZ Condition from AD to LDAP and it kept failing.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In my example below I was checking whether a user was a member of the AD Security Group called "ise-readonly". I could do it in two ways. In the first case I assigned the AD user's primary group to be "ise-readonly" which is something you probably can't always rely on. But in the second case, I managed to match the user's group membership by importing that group name from LDAP, and then using it in the AuthZ. The trick with the "memberOf" was that my LDAP setup config was not right to start with, and ISE was failing to read the LDAP Group table from AD.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ldap-lab.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/79343i31D2BBD23407F54B/image-size/large?v=v2&amp;amp;px=999" role="button" title="ldap-lab.PNG" alt="ldap-lab.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="lda-setup.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/79344i363D98ED74B80216/image-size/large?v=v2&amp;amp;px=999" role="button" title="lda-setup.PNG" alt="lda-setup.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ldap-attr.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/79345iD3E089F13B832DCC/image-size/large?v=v2&amp;amp;px=999" role="button" title="ldap-attr.PNG" alt="ldap-attr.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jul 2020 23:07:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/unable-to-access-sponsor-portal-with-ldap-as-a-external-identity/m-p/4120910#M561770</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2020-07-17T23:07:42Z</dc:date>
    </item>
  </channel>
</rss>

