<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: RAVPN request control in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ravpn-request-control/m-p/5552001#M1125166</link>
    <description>&lt;P&gt;Thanks Aref.&lt;/P&gt;&lt;P&gt;Initial authentication happen in NPS. I will generate it and feedback here.&lt;/P&gt;</description>
    <pubDate>Mon, 11 May 2026 09:10:10 GMT</pubDate>
    <dc:creator>imanv</dc:creator>
    <dc:date>2026-05-11T09:10:10Z</dc:date>
    <item>
      <title>RAVPN request control</title>
      <link>https://community.cisco.com/t5/network-security/ravpn-request-control/m-p/5551083#M1125151</link>
      <description>&lt;P&gt;I have a remote access VPN with the following scenario.&lt;/P&gt;&lt;P&gt;I have FTD virtual managed by FMC (version 7.7), Cisco ISE radius AAA (version 3.4), external radius server (Microsoft NPS) for multi-factor authentication (MFA). User send the credential to FMC--&amp;gt;ISE--&amp;gt;external radius and after external radius check it with active directory. The external radius server authenticate the remote clients to send the SMS as second factor. After that I configure ISE to continue the Authorization using ISE Authorization profiles.&lt;/P&gt;&lt;P&gt;I found that some remote clients sends many &lt;U&gt;correct credentials&lt;/U&gt; to VPN gateway in short period of time ( less than a minute) and by this method hundreds of SMS sends. I am looking for a way to manage accepting the correct user/passwords for certain period of time to prevent the overwhelming the SMS servers.&lt;/P&gt;&lt;P&gt;Just note that it is not simultaneous connection attempts.&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 06 May 2026 21:48:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ravpn-request-control/m-p/5551083#M1125151</guid>
      <dc:creator>imanv</dc:creator>
      <dc:date>2026-05-06T21:48:34Z</dc:date>
    </item>
    <item>
      <title>Re: RAVPN request control</title>
      <link>https://community.cisco.com/t5/network-security/ravpn-request-control/m-p/5551199#M1125153</link>
      <description>&lt;P&gt;Why you have to use MS NPS if you have ISE? can't ISE handle the whole authentication and authorization process?&lt;/P&gt;</description>
      <pubDate>Thu, 07 May 2026 10:00:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ravpn-request-control/m-p/5551199#M1125153</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2026-05-07T10:00:10Z</dc:date>
    </item>
    <item>
      <title>Re: RAVPN request control</title>
      <link>https://community.cisco.com/t5/network-security/ravpn-request-control/m-p/5551354#M1125161</link>
      <description>&lt;P&gt;Thanks for your reply.&lt;/P&gt;&lt;P&gt;I need it to handle the second factor authentication. The NPS check the credentials with DC and send the result to another application to send the SMS. If the remote client send the OTP code recived by SMS and approved by the application, MS NPS send the result to ISE. Then I configure ISE to continue authorization to ISE authz policies.&lt;/P&gt;</description>
      <pubDate>Thu, 07 May 2026 16:43:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ravpn-request-control/m-p/5551354#M1125161</guid>
      <dc:creator>imanv</dc:creator>
      <dc:date>2026-05-07T16:43:32Z</dc:date>
    </item>
    <item>
      <title>Re: RAVPN request control</title>
      <link>https://community.cisco.com/t5/network-security/ravpn-request-control/m-p/5551550#M1125163</link>
      <description>&lt;P&gt;Could that be something ISE can handle? not really sure if that would fix the reported issue though. How those many authentication requests look like on ISE? I'm just thinking if this issue could be related to some sort of latency on the network used by those remote clients maybe?&lt;/P&gt;</description>
      <pubDate>Fri, 08 May 2026 10:18:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ravpn-request-control/m-p/5551550#M1125163</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2026-05-08T10:18:25Z</dc:date>
    </item>
    <item>
      <title>Re: RAVPN request control</title>
      <link>https://community.cisco.com/t5/network-security/ravpn-request-control/m-p/5552001#M1125166</link>
      <description>&lt;P&gt;Thanks Aref.&lt;/P&gt;&lt;P&gt;Initial authentication happen in NPS. I will generate it and feedback here.&lt;/P&gt;</description>
      <pubDate>Mon, 11 May 2026 09:10:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ravpn-request-control/m-p/5552001#M1125166</guid>
      <dc:creator>imanv</dc:creator>
      <dc:date>2026-05-11T09:10:10Z</dc:date>
    </item>
  </channel>
</rss>

