<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic VPN ASA certificate + DUO authentication using ISE? in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/vpn-asa-certificate-duo-authentication-using-ise/m-p/4746085#M579000</link>
    <description>&lt;P&gt;Hey guys,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm trying to find a way to authenticate users coming from Cisco ASA with certificate and DUO from ISE.&lt;/P&gt;&lt;P&gt;The idea is to follow the steps bellow :&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Users connects to ASA VPN with AnyConnect Client.&lt;/LI&gt;&lt;LI&gt;Device certificate is send to ASA and ASA forward it to ISE.&lt;/LI&gt;&lt;LI&gt;Once certificate is authenticate by ISE a request is send from ISE to DUO proxy to authenticate the users with Duo push.&lt;/LI&gt;&lt;LI&gt;Then User valid is Push and He is authenticated to the VPN.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Is it possible to implement this ?&lt;/P&gt;&lt;P&gt;Also is it possible to do only one Radius request by using EAP-TEAP for the step 2 and 3.&lt;/P&gt;&lt;P&gt;I found this community subject :&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.cisco.com/t5/network-access-control/vpn-certificate-auth-using-ise/td-p/3513185" target="_blank" rel="noopener"&gt;Solved: VPN certificate auth using ISE? - Cisco Community&lt;/A&gt;&lt;/P&gt;&lt;P&gt;But it has been posted 5 years ago so is it outdated ?&lt;/P&gt;&lt;P&gt;Thank for your help !&lt;/P&gt;</description>
    <pubDate>Wed, 28 Dec 2022 13:10:37 GMT</pubDate>
    <dc:creator>Djuxt</dc:creator>
    <dc:date>2022-12-28T13:10:37Z</dc:date>
    <item>
      <title>VPN ASA certificate + DUO authentication using ISE?</title>
      <link>https://community.cisco.com/t5/network-access-control/vpn-asa-certificate-duo-authentication-using-ise/m-p/4746085#M579000</link>
      <description>&lt;P&gt;Hey guys,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm trying to find a way to authenticate users coming from Cisco ASA with certificate and DUO from ISE.&lt;/P&gt;&lt;P&gt;The idea is to follow the steps bellow :&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Users connects to ASA VPN with AnyConnect Client.&lt;/LI&gt;&lt;LI&gt;Device certificate is send to ASA and ASA forward it to ISE.&lt;/LI&gt;&lt;LI&gt;Once certificate is authenticate by ISE a request is send from ISE to DUO proxy to authenticate the users with Duo push.&lt;/LI&gt;&lt;LI&gt;Then User valid is Push and He is authenticated to the VPN.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Is it possible to implement this ?&lt;/P&gt;&lt;P&gt;Also is it possible to do only one Radius request by using EAP-TEAP for the step 2 and 3.&lt;/P&gt;&lt;P&gt;I found this community subject :&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.cisco.com/t5/network-access-control/vpn-certificate-auth-using-ise/td-p/3513185" target="_blank" rel="noopener"&gt;Solved: VPN certificate auth using ISE? - Cisco Community&lt;/A&gt;&lt;/P&gt;&lt;P&gt;But it has been posted 5 years ago so is it outdated ?&lt;/P&gt;&lt;P&gt;Thank for your help !&lt;/P&gt;</description>
      <pubDate>Wed, 28 Dec 2022 13:10:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/vpn-asa-certificate-duo-authentication-using-ise/m-p/4746085#M579000</guid>
      <dc:creator>Djuxt</dc:creator>
      <dc:date>2022-12-28T13:10:37Z</dc:date>
    </item>
    <item>
      <title>Re: VPN ASA certificate + DUO authentication using ISE?</title>
      <link>https://community.cisco.com/t5/network-access-control/vpn-asa-certificate-duo-authentication-using-ise/m-p/4746091#M579001</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1437983"&gt;@Djuxt&lt;/a&gt; certificate authentication is between the anyconnect client and the ASA, not ISE.&lt;/P&gt;
&lt;P&gt;You could send the Duo authentication via ISE which proxies the request to the Duo authentication proxy, once authenticated via Duo ISE can then authorise the user.&lt;/P&gt;
&lt;P&gt;TEAP is used for 802.1X authentication (wired/wireless) not VPN.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Dec 2022 13:22:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/vpn-asa-certificate-duo-authentication-using-ise/m-p/4746091#M579001</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2022-12-28T13:22:36Z</dc:date>
    </item>
  </channel>
</rss>

