<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Prime Infrastructure AAA with ISE in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/prime-infrastructure-aaa-with-ise/m-p/2594037#M75737</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have configured Authc and Authz policies as follows:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;Authc:&lt;/U&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;If Radius-NAS-Port-Type EQUALS Virtual the Default Network Access and use AD&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;Authz:&lt;/U&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;If Radius-NAS-Port-Type EQUALS Virtual&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; AND AD Specific User Group&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; then Authz Profile Permissions (Cisco av-pair = NCS:role0=Root and NCS:virtual-domain0=ROOT-DOMAIN)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am able to authenticate successfully and the Authorisation permission is applied and I can see this from the Authentication logs, but after that it seems ISE goes back to the Default Authentication policy of Deny Access.&lt;/P&gt;&lt;P&gt;Please could any one explain why this failure as the Prime Admin guide doesn't have the proper configuration steps.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 05:14:29 GMT</pubDate>
    <dc:creator>grabonlee</dc:creator>
    <dc:date>2019-03-11T05:14:29Z</dc:date>
    <item>
      <title>Prime Infrastructure AAA with ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/prime-infrastructure-aaa-with-ise/m-p/2594037#M75737</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have configured Authc and Authz policies as follows:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;Authc:&lt;/U&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;If Radius-NAS-Port-Type EQUALS Virtual the Default Network Access and use AD&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;Authz:&lt;/U&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;If Radius-NAS-Port-Type EQUALS Virtual&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; AND AD Specific User Group&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; then Authz Profile Permissions (Cisco av-pair = NCS:role0=Root and NCS:virtual-domain0=ROOT-DOMAIN)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am able to authenticate successfully and the Authorisation permission is applied and I can see this from the Authentication logs, but after that it seems ISE goes back to the Default Authentication policy of Deny Access.&lt;/P&gt;&lt;P&gt;Please could any one explain why this failure as the Prime Admin guide doesn't have the proper configuration steps.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 05:14:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/prime-infrastructure-aaa-with-ise/m-p/2594037#M75737</guid>
      <dc:creator>grabonlee</dc:creator>
      <dc:date>2019-03-11T05:14:29Z</dc:date>
    </item>
    <item>
      <title>Are you saying that you are</title>
      <link>https://community.cisco.com/t5/network-access-control/prime-infrastructure-aaa-with-ise/m-p/2594038#M75738</link>
      <description>&lt;P&gt;Are you saying that you are initially able to login as an administrator to Prime but then any subsequent authentications fail?&lt;/P&gt;</description>
      <pubDate>Thu, 04 Dec 2014 17:12:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/prime-infrastructure-aaa-with-ise/m-p/2594038#M75738</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2014-12-04T17:12:05Z</dc:date>
    </item>
    <item>
      <title>No. What I am saying is that</title>
      <link>https://community.cisco.com/t5/network-access-control/prime-infrastructure-aaa-with-ise/m-p/2594039#M75740</link>
      <description>&lt;P&gt;No. What I am saying is that I successfully authenticate and the authorisation policy+profile above is applied. But this fails despite the fact it's just a Cisco-av-pair as shown above.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can see from Operations &amp;gt; Authentication that Authentication is successful and Auth profile applied.&lt;/P&gt;&lt;P&gt;After this, I see fail and when I check the details, the message is Authentication &amp;gt; Default policy, subject not found in ID store.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Dec 2014 19:09:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/prime-infrastructure-aaa-with-ise/m-p/2594039#M75740</guid>
      <dc:creator>grabonlee</dc:creator>
      <dc:date>2014-12-04T19:09:11Z</dc:date>
    </item>
    <item>
      <title>I am not sure I fully</title>
      <link>https://community.cisco.com/t5/network-access-control/prime-infrastructure-aaa-with-ise/m-p/2594040#M75742</link>
      <description>&lt;P&gt;I am not sure I fully understand exact flow and the problem. Can you post screenshots of the following:&lt;/P&gt;&lt;P&gt;1. Prime radius and AAA configurations&lt;/P&gt;&lt;P&gt;2. ISE Policy Configuration&amp;nbsp;&lt;/P&gt;&lt;P&gt;3. Authentication screen of the failed/pass authentication&lt;/P&gt;</description>
      <pubDate>Fri, 05 Dec 2014 01:51:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/prime-infrastructure-aaa-with-ise/m-p/2594040#M75742</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2014-12-05T01:51:35Z</dc:date>
    </item>
    <item>
      <title>Please see attached</title>
      <link>https://community.cisco.com/t5/network-access-control/prime-infrastructure-aaa-with-ise/m-p/2594041#M75743</link>
      <description>&lt;P&gt;Please see attached&lt;/P&gt;</description>
      <pubDate>Fri, 05 Dec 2014 11:50:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/prime-infrastructure-aaa-with-ise/m-p/2594041#M75743</guid>
      <dc:creator>grabonlee</dc:creator>
      <dc:date>2014-12-05T11:50:26Z</dc:date>
    </item>
    <item>
      <title>Hi,Does anybody have a</title>
      <link>https://community.cisco.com/t5/network-access-control/prime-infrastructure-aaa-with-ise/m-p/2594042#M75744</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Does anybody have a solution to this issue? I am having the same problem - it's as though a second request is sent to ISE which only matches up to the Default policy which, in my case, is deny access.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 02 Mar 2015 01:06:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/prime-infrastructure-aaa-with-ise/m-p/2594042#M75744</guid>
      <dc:creator>ALAN MURRAY</dc:creator>
      <dc:date>2015-03-02T01:06:16Z</dc:date>
    </item>
    <item>
      <title>For my authorization profile</title>
      <link>https://community.cisco.com/t5/network-access-control/prime-infrastructure-aaa-with-ise/m-p/2594043#M75745</link>
      <description>&lt;P&gt;For my authorization profile result in ISE for PI, I use the following:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Access Type = ACCESS_ACCEPT&lt;BR /&gt;cisco-av-pair = NCS:virtual-domain0=ROOT-DOMAIN&lt;BR /&gt;cisco-av-pair = NCS:role0=Root&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now you would obviously need to change this if you have multiple virtual domains in PI. It looks similar to what you are using.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My successful login is shown below (however&amp;nbsp;I don't see the Virtual port type):&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;TABLE border="0" class="content_table"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="31%"&gt;Source Timestamp&lt;/TD&gt;&lt;TD width="69%"&gt;2015-03-03 10:23:56.123&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="31%"&gt;Received Timestamp&lt;/TD&gt;&lt;TD width="69%"&gt;2015-03-03 10:23:56.123&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="31%"&gt;Policy Server&lt;/TD&gt;&lt;TD width="69%"&gt;MYISESERVER&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="31%"&gt;Event&lt;/TD&gt;&lt;TD style="color: green;" width="69%"&gt;5200 Authentication succeeded&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="31%"&gt;Failure Reason&lt;/TD&gt;&lt;TD style="color: red;" width="69%"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="31%"&gt;Resolution&lt;/TD&gt;&lt;TD width="69%"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="31%"&gt;Root cause&lt;/TD&gt;&lt;TD width="69%"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="31%"&gt;Username&lt;/TD&gt;&lt;TD width="69%"&gt;mycoolusername&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="31%"&gt;User Type&lt;/TD&gt;&lt;TD width="69%"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="31%"&gt;Endpoint Id&lt;/TD&gt;&lt;TD width="69%"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="31%"&gt;Endpoint Profile&lt;/TD&gt;&lt;TD width="69%"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="31%"&gt;IP Address&lt;/TD&gt;&lt;TD width="69%"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="31%"&gt;Identity Store&lt;/TD&gt;&lt;TD width="69%"&gt;MYADIDENTITYSTORE&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="31%"&gt;Identity Group&lt;/TD&gt;&lt;TD width="69%"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="31%"&gt;Audit Session Id&lt;/TD&gt;&lt;TD width="69%"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="31%"&gt;Authentication Method&lt;/TD&gt;&lt;TD width="69%"&gt;PAP_ASCII&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="31%"&gt;Authentication Protocol&lt;/TD&gt;&lt;TD width="69%"&gt;PAP_ASCII&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="31%"&gt;Service Type&lt;/TD&gt;&lt;TD width="69%"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="31%"&gt;Network Device&lt;/TD&gt;&lt;TD width="69%"&gt;PISERVERNAME&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="31%"&gt;Device Type&lt;/TD&gt;&lt;TD width="69%"&gt;Network Management&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="31%"&gt;Location&lt;/TD&gt;&lt;TD width="69%"&gt;Corporate Office&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="31%"&gt;NAS IP Address&lt;/TD&gt;&lt;TD width="69%"&gt;PI-IP-ADDRESS&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="31%"&gt;NAS Port Id&lt;/TD&gt;&lt;TD width="69%"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="31%"&gt;NAS Port Type&lt;/TD&gt;&lt;TD width="69%"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="31%"&gt;Authorization Profile&lt;/TD&gt;&lt;TD width="69%"&gt;Cisco-Prime-Infrastructure&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="31%"&gt;Posture Status&lt;/TD&gt;&lt;TD width="69%"&gt;NotApplicable&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="31%"&gt;Security Group&lt;/TD&gt;&lt;TD width="69%"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="31%"&gt;Response Time&lt;/TD&gt;&lt;TD width="69%"&gt;19&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Try&amp;nbsp;taking out the port type=virtual in your authorization profile config.&amp;nbsp;I only see the port type=virtual in the authentication.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Mar 2015 18:29:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/prime-infrastructure-aaa-with-ise/m-p/2594043#M75745</guid>
      <dc:creator>Seth Bjorn</dc:creator>
      <dc:date>2015-03-03T18:29:34Z</dc:date>
    </item>
    <item>
      <title>Thanks, Seth. I'll try that.</title>
      <link>https://community.cisco.com/t5/network-access-control/prime-infrastructure-aaa-with-ise/m-p/2594044#M75746</link>
      <description>&lt;P&gt;Thanks, Seth. I'll try that.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Mar 2015 22:53:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/prime-infrastructure-aaa-with-ise/m-p/2594044#M75746</guid>
      <dc:creator>ALAN MURRAY</dc:creator>
      <dc:date>2015-03-03T22:53:25Z</dc:date>
    </item>
    <item>
      <title>Taking out the port-type</title>
      <link>https://community.cisco.com/t5/network-access-control/prime-infrastructure-aaa-with-ise/m-p/2594045#M75747</link>
      <description>&lt;P&gt;Taking out the port-type=virtual in the authorization profile sorted things out for Alan and I. Thanks for taking the time to answer, Seth.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(We're still using role0=Admin, though, as appropriate for the permissions setup we're using)&lt;/P&gt;</description>
      <pubDate>Tue, 03 Mar 2015 23:31:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/prime-infrastructure-aaa-with-ise/m-p/2594045#M75747</guid>
      <dc:creator>Alex White-Robinson</dc:creator>
      <dc:date>2015-03-03T23:31:19Z</dc:date>
    </item>
    <item>
      <title>I should've updated long ago.</title>
      <link>https://community.cisco.com/t5/network-access-control/prime-infrastructure-aaa-with-ise/m-p/2594046#M75748</link>
      <description>&lt;P&gt;I should've updated long ago. Removed the NAS-Port-Type=Virtual and replaced with NDG&amp;nbsp; created for Prime i.e Device:DeviceType=Prime.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For Authentication, the I left the Radius=Virtual in the Policy&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Apr 2015 10:08:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/prime-infrastructure-aaa-with-ise/m-p/2594046#M75748</guid>
      <dc:creator>grabonlee</dc:creator>
      <dc:date>2015-04-02T10:08:55Z</dc:date>
    </item>
    <item>
      <title>Hello,</title>
      <link>https://community.cisco.com/t5/network-access-control/prime-infrastructure-aaa-with-ise/m-p/2594047#M75749</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;i am expecting the same problem.&lt;/P&gt;
&lt;P&gt;Where i will remove port type=virtual?&lt;/P&gt;
&lt;P&gt;In my authorization profile i have :&lt;/P&gt;
&lt;P&gt;Access Type = ACCESS_ACCEPT&lt;BR /&gt;cisco-av-pair = NCS:role0=Root&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Marco&lt;/P&gt;</description>
      <pubDate>Fri, 19 Feb 2016 09:28:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/prime-infrastructure-aaa-with-ise/m-p/2594047#M75749</guid>
      <dc:creator>Marco Aresu</dc:creator>
      <dc:date>2016-02-19T09:28:20Z</dc:date>
    </item>
  </channel>
</rss>

