<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Login to firewall using external identity server in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/login-to-firewall-using-external-identity-server/m-p/4585567#M573877</link>
    <description>&lt;P&gt;Check out these articles.&amp;nbsp; If you have Device Admin License and want to use TACACS+ to log into the Palo Alto firewall, then Palo Alto has the steps:&lt;/P&gt;
&lt;P class="slds-text-heading_large"&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PMYmCAO&amp;amp;lang=en_US%E2%80%A9" target="_self"&gt;How to configure TACACS authentication against Cisco ISE&lt;/A&gt;&lt;/P&gt;
&lt;P class="slds-text-heading_large"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="slds-text-heading_large"&gt;If you'd rather use RADIUS to login to the firewall, use this entry:&lt;/P&gt;
&lt;P class="article-title"&gt;&lt;A href="https://www.packetswitch.co.uk/configuring-palo-alto-administrator-authentication-with-cisco-ise/" target="_self"&gt;Configuring Palo Alto Administrator Authentication with Cisco ISE (Radius)&lt;/A&gt;&lt;/P&gt;
&lt;P class="slds-text-heading_large"&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 04 Apr 2022 20:49:34 GMT</pubDate>
    <dc:creator>Charlie Moreton</dc:creator>
    <dc:date>2022-04-04T20:49:34Z</dc:date>
    <item>
      <title>Login to firewall using external identity server</title>
      <link>https://community.cisco.com/t5/network-access-control/login-to-firewall-using-external-identity-server/m-p/4585204#M573867</link>
      <description>&lt;P&gt;Good morning,&lt;/P&gt;&lt;P&gt;I am attempting to setup our Palo Alto Firewalls to use certificate authentication by sending our login information to ISE using radius and having ISE lookup the identity in active directory as an external authentication source.&amp;nbsp; I realize I can just setup out Palos to do LDAP with AD and perform authentication and authorization but our network security team would like to keep control of the authorization piece instead of relying on the server team to determine who and what kind of access people have to the firewalls.&amp;nbsp; Is this something that will work?&amp;nbsp; I see the connection to ISE over radius and that I can select an external authentication source for the account used in ISE but so far nothing is working.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Apr 2022 12:56:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/login-to-firewall-using-external-identity-server/m-p/4585204#M573867</guid>
      <dc:creator>Blackhawk1278</dc:creator>
      <dc:date>2022-04-04T12:56:13Z</dc:date>
    </item>
    <item>
      <title>Re: Login to firewall using external identity server</title>
      <link>https://community.cisco.com/t5/network-access-control/login-to-firewall-using-external-identity-server/m-p/4585567#M573877</link>
      <description>&lt;P&gt;Check out these articles.&amp;nbsp; If you have Device Admin License and want to use TACACS+ to log into the Palo Alto firewall, then Palo Alto has the steps:&lt;/P&gt;
&lt;P class="slds-text-heading_large"&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PMYmCAO&amp;amp;lang=en_US%E2%80%A9" target="_self"&gt;How to configure TACACS authentication against Cisco ISE&lt;/A&gt;&lt;/P&gt;
&lt;P class="slds-text-heading_large"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="slds-text-heading_large"&gt;If you'd rather use RADIUS to login to the firewall, use this entry:&lt;/P&gt;
&lt;P class="article-title"&gt;&lt;A href="https://www.packetswitch.co.uk/configuring-palo-alto-administrator-authentication-with-cisco-ise/" target="_self"&gt;Configuring Palo Alto Administrator Authentication with Cisco ISE (Radius)&lt;/A&gt;&lt;/P&gt;
&lt;P class="slds-text-heading_large"&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Apr 2022 20:49:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/login-to-firewall-using-external-identity-server/m-p/4585567#M573877</guid>
      <dc:creator>Charlie Moreton</dc:creator>
      <dc:date>2022-04-04T20:49:34Z</dc:date>
    </item>
    <item>
      <title>Re: Login to firewall using external identity server</title>
      <link>https://community.cisco.com/t5/network-access-control/login-to-firewall-using-external-identity-server/m-p/4585575#M573878</link>
      <description>&lt;P&gt;I don't want to do either of these things.&amp;nbsp; I want to send my credentials to ise using radius and for ise to authenticate those credentials against active directory.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Apr 2022 21:02:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/login-to-firewall-using-external-identity-server/m-p/4585575#M573878</guid>
      <dc:creator>Blackhawk1278</dc:creator>
      <dc:date>2022-04-04T21:02:48Z</dc:date>
    </item>
    <item>
      <title>Re: Login to firewall using external identity server</title>
      <link>https://community.cisco.com/t5/network-access-control/login-to-firewall-using-external-identity-server/m-p/4585600#M573879</link>
      <description>&lt;P&gt;The second link shows how to do this.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Else, use this:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/authentication/configure-radius-authentication.html" target="_self"&gt;Configure RADIUS Authentication&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You'll have to add the firewall as a NAD in a Network Device Group.&amp;nbsp; Then you can use that NDG as a condition for a Policy Set to authenticate to ISE.&amp;nbsp; MS-CHAPv2 is the default protocol that Palo Alto Firewalls use for this.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Apr 2022 22:15:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/login-to-firewall-using-external-identity-server/m-p/4585600#M573879</guid>
      <dc:creator>Charlie Moreton</dc:creator>
      <dc:date>2022-04-04T22:15:22Z</dc:date>
    </item>
  </channel>
</rss>

