<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Setting up Cisco ISE to work with pFsense in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/setting-up-cisco-ise-to-work-with-pfsense/m-p/4474590#M569958</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/262907"&gt;@martin.fischer&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your post, yes this option worked for me!&amp;nbsp; I am now able to log in with no issues.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I also have webGUI login working with DUO MFA.&amp;nbsp; I can only do PAP as my authentication type.&amp;nbsp; Is that the only option?&amp;nbsp; I tried MS-CHAPv2 but that didn't work. Wondering if there is another setting I need to find.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;</description>
    <pubDate>Mon, 27 Sep 2021 13:12:37 GMT</pubDate>
    <dc:creator>ejerviss</dc:creator>
    <dc:date>2021-09-27T13:12:37Z</dc:date>
    <item>
      <title>Setting up Cisco ISE to work with pFsense</title>
      <link>https://community.cisco.com/t5/network-access-control/setting-up-cisco-ise-to-work-with-pfsense/m-p/4470907#M569853</link>
      <description>&lt;P&gt;We are trying to setup MFA on our pfsense firewalls for the webGUI for management.&amp;nbsp; We would like to use a radius setup with ISE to gain access using MFA.&amp;nbsp; I am able to see my authentications pass in ISE but on pFsense I don't have a user group to associate with.&amp;nbsp; It states I need a local account with group privilege's but I don't have without creating a local user.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does anyone have experience with this?&lt;/P&gt;</description>
      <pubDate>Tue, 21 Sep 2021 17:49:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/setting-up-cisco-ise-to-work-with-pfsense/m-p/4470907#M569853</guid>
      <dc:creator>ejerviss</dc:creator>
      <dc:date>2021-09-21T17:49:55Z</dc:date>
    </item>
    <item>
      <title>Re: Setting up Cisco ISE to work with pFsense</title>
      <link>https://community.cisco.com/t5/network-access-control/setting-up-cisco-ise-to-work-with-pfsense/m-p/4472047#M569889</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1250147"&gt;@ejerviss&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I remember correctly you don't need a local user but you need to reference the local group in the RADIUS response on ISE with the class attribute. E.g. if you want to give the user admin rights and your local group is called &lt;STRONG&gt;admins&lt;/STRONG&gt; then return RADIUS:Class &lt;STRONG&gt;equals&lt;/STRONG&gt; admins&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="Capture.PNG" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/131841i61FD26ECDCEF71C3/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Capture.PNG" alt="Capture.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;</description>
      <pubDate>Thu, 23 Sep 2021 13:29:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/setting-up-cisco-ise-to-work-with-pfsense/m-p/4472047#M569889</guid>
      <dc:creator>martin.fischer</dc:creator>
      <dc:date>2021-09-23T13:29:14Z</dc:date>
    </item>
    <item>
      <title>Re: Setting up Cisco ISE to work with pFsense</title>
      <link>https://community.cisco.com/t5/network-access-control/setting-up-cisco-ise-to-work-with-pfsense/m-p/4474590#M569958</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/262907"&gt;@martin.fischer&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your post, yes this option worked for me!&amp;nbsp; I am now able to log in with no issues.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I also have webGUI login working with DUO MFA.&amp;nbsp; I can only do PAP as my authentication type.&amp;nbsp; Is that the only option?&amp;nbsp; I tried MS-CHAPv2 but that didn't work. Wondering if there is another setting I need to find.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Mon, 27 Sep 2021 13:12:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/setting-up-cisco-ise-to-work-with-pfsense/m-p/4474590#M569958</guid>
      <dc:creator>ejerviss</dc:creator>
      <dc:date>2021-09-27T13:12:37Z</dc:date>
    </item>
  </channel>
</rss>

