cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2111
Views
4
Helpful
3
Replies

Authorization without Authentication

matthen
Cisco Employee
Cisco Employee

Is it possible to use ISE for authorization without authentication?  My use case centers around using ISE to authorize SSLVPN connections in an SSO configuration, without having to supply credentials for authentication.  In this use case we would validate a user certificate on an ASA, and if it's accepted the ASA would pass the username over to ISE for group membership lookup in AD.  Based on the group memberships that are returned from AD, ISE would send back authorization permissions to the ASA.

Thanks,

Matt

1 Accepted Solution

Accepted Solutions

hslai
Cisco Employee
Cisco Employee

Around 06:00 in this labminutes video How to Configure Cisco SSL VPN AnyConnect Client Certificate and Double Authentication (Part 2) shows the key is to continue with authentication failures.

View solution in original post

3 Replies 3

matthen
Cisco Employee
Cisco Employee

Thank you!  This was helpful, but do you know if there is a way to pass back a name from the certificate itself, like UPN or CN, and look that up in AD to get group membership(s) to determine which authorization policy to apply?

hslai
Cisco Employee
Cisco Employee

Around 06:00 in this labminutes video How to Configure Cisco SSL VPN AnyConnect Client Certificate and Double Authentication (Part 2) shows the key is to continue with authentication failures.