cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1908
Views
2
Helpful
3
Replies

Radius attribute Class (25) as a condition in AuthZ policy

sahaputh
Level 1
Level 1

Hi,

How can we configure Radius attribute Class (25) as a condition in AuthZ policy?

This is a Anyconnect scenario,where user authentication from ASA (Radius Access-Request) is sent to ISE and ISE send it to an external Radius server (Proxy Service). External Radius server is sending Access-Accept with the corresponding class attribute. How can we use this received class attribute as a condition in authorization policy. I noticed in dictionaries, Radius Class (ID 25) direction is preconfigured with "OUT" and can't change it since it's System defined. Is there's a way to accomplish this?

Thanks!

TK.

1 Accepted Solution

Accepted Solutions

Jason Kunst
Cisco Employee
Cisco Employee

This is not a current option. Working this offline to address the use case to see if its a feature request

View solution in original post

3 Replies 3

Jason Kunst
Cisco Employee
Cisco Employee

This is not a current option. Working this offline to address the use case to see if its a feature request

Jatin Katyal
Cisco Employee
Cisco Employee

Did we make any progress to have Radius Attribute Class (25) as a condition in authorization policy.

~ Jatin

~Jatin

Nope. This is tracked by CSCus80472. I will add a release note enclosure in a moment so expect it externally visible in a day or two.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: