<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ISE 3.2.0.542 External Identity Store Cert Auth via Proxy in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-3-2-0-542-external-identity-store-cert-auth-via-proxy/m-p/5072495#M588830</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/255804"&gt;@KatoNakatomi&lt;/a&gt;&amp;nbsp;- where is the OCSP server located? Normally the web proxy is used to allow ISE to access web resources outside of the company intranet. But if the client certs are issued by the company PKI, then should be no need to go via a proxy. But interesting to note, that there is no mention of OCSP in the ISE web proxy setup.&amp;nbsp; Probably something you could test in the lab (run a tcpdump on the ISE node).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 18 Apr 2024 02:18:30 GMT</pubDate>
    <dc:creator>Arne Bier</dc:creator>
    <dc:date>2024-04-18T02:18:30Z</dc:date>
    <item>
      <title>Cisco ISE 3.2.0.542 External Identity Store Cert Auth via Proxy</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-3-2-0-542-external-identity-store-cert-auth-via-proxy/m-p/5071886#M588811</link>
      <description>&lt;P&gt;We have implemented 802.1x with machine certificate authentication.&lt;/P&gt;&lt;P&gt;The certificate validation is via OCSP and the question is does Cisco ISE support connection to OSCP via a Web Proxy? The assumption is that the connection would be using the system proxy settings&lt;/P&gt;&lt;P&gt;However, OCSP is no listed in the notes as one affected by the Proxy Setting&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Notes:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;The following functionalities are impacted by the proxy settings&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Partner Mobile Management&lt;/LI&gt;&lt;LI&gt;Endpoint Profiler Feed Service Update&lt;/LI&gt;&lt;LI&gt;Endpoint Posture Update&lt;/LI&gt;&lt;LI&gt;Endpoint Posture Agent Resources Download&lt;/LI&gt;&lt;LI&gt;CRL (Certificate Revocation List) Download&lt;/LI&gt;&lt;LI&gt;SMS Message Transmission&lt;/LI&gt;&lt;LI&gt;Social Login&lt;/LI&gt;&lt;LI&gt;Rest Auth Service - Azure AD&lt;/LI&gt;&lt;LI&gt;pxGrid Cloud&lt;/LI&gt;&lt;LI&gt;TrustSec Integration for Meraki&lt;/LI&gt;&lt;LI&gt;pxGrid Direct&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Apr 2024 12:55:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-3-2-0-542-external-identity-store-cert-auth-via-proxy/m-p/5071886#M588811</guid>
      <dc:creator>KatoNakatomi</dc:creator>
      <dc:date>2024-04-17T12:55:05Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 3.2.0.542 External Identity Store Cert Auth via Proxy</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-3-2-0-542-external-identity-store-cert-auth-via-proxy/m-p/5071926#M588813</link>
      <description>&lt;P&gt;OCSP does not require any download and it is not using the traditional CRL method, so I don't believe there will be any problem with OCSP. The list you provided refers explicitly to the CRL method, not OCSP.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Apr 2024 13:14:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-3-2-0-542-external-identity-store-cert-auth-via-proxy/m-p/5071926#M588813</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2024-04-17T13:14:37Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 3.2.0.542 External Identity Store Cert Auth via Proxy</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-3-2-0-542-external-identity-store-cert-auth-via-proxy/m-p/5071964#M588814</link>
      <description>&lt;P&gt;The challenge is we need the ISE connection to the OCSP server go through a Web Proxy? Is this supported?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Apr 2024 13:38:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-3-2-0-542-external-identity-store-cert-auth-via-proxy/m-p/5071964#M588814</guid>
      <dc:creator>KatoNakatomi</dc:creator>
      <dc:date>2024-04-17T13:38:21Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 3.2.0.542 External Identity Store Cert Auth via Proxy</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-3-2-0-542-external-identity-store-cert-auth-via-proxy/m-p/5071987#M588815</link>
      <description>&lt;P&gt;I can't see why not.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Apr 2024 13:45:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-3-2-0-542-external-identity-store-cert-auth-via-proxy/m-p/5071987#M588815</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2024-04-17T13:45:13Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 3.2.0.542 External Identity Store Cert Auth via Proxy</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-3-2-0-542-external-identity-store-cert-auth-via-proxy/m-p/5072495#M588830</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/255804"&gt;@KatoNakatomi&lt;/a&gt;&amp;nbsp;- where is the OCSP server located? Normally the web proxy is used to allow ISE to access web resources outside of the company intranet. But if the client certs are issued by the company PKI, then should be no need to go via a proxy. But interesting to note, that there is no mention of OCSP in the ISE web proxy setup.&amp;nbsp; Probably something you could test in the lab (run a tcpdump on the ISE node).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Apr 2024 02:18:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-3-2-0-542-external-identity-store-cert-auth-via-proxy/m-p/5072495#M588830</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2024-04-18T02:18:30Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 3.2.0.542 External Identity Store Cert Auth via Proxy</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-3-2-0-542-external-identity-store-cert-auth-via-proxy/m-p/5072613#M588834</link>
      <description>&lt;P&gt;The OCSP server is an externally hosted outside the organisation, thus requiring the web traffic to traverse a web proxy. We will try the tcpdump on ISE nodes or have the team check the DNS servers if there is any record of the ISE node trying to resolve the external OCSP domain.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Apr 2024 07:04:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-3-2-0-542-external-identity-store-cert-auth-via-proxy/m-p/5072613#M588834</guid>
      <dc:creator>KatoNakatomi</dc:creator>
      <dc:date>2024-04-18T07:04:24Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 3.2.0.542 External Identity Store Cert Auth via Proxy</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-3-2-0-542-external-identity-store-cert-auth-via-proxy/m-p/5075838#M588917</link>
      <description>&lt;P&gt;Cisco TAC has advised OCSP connections through a web proxy is not supported by Cisco ISE.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2024 07:50:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-3-2-0-542-external-identity-store-cert-auth-via-proxy/m-p/5075838#M588917</guid>
      <dc:creator>KatoNakatomi</dc:creator>
      <dc:date>2024-04-23T07:50:53Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 3.2.0.542 External Identity Store Cert Auth via Proxy</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-3-2-0-542-external-identity-store-cert-auth-via-proxy/m-p/5075955#M588921</link>
      <description>&lt;P&gt;Thanks for sharing this info. Did they provide any documentation link that you can share for that?&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2024 09:13:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-3-2-0-542-external-identity-store-cert-auth-via-proxy/m-p/5075955#M588921</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2024-04-23T09:13:28Z</dc:date>
    </item>
  </channel>
</rss>

