10-26-2021 06:44 AM
Hi guys,
I need to know if is possible use DUO with ISE connected tu Azure AD to give access to our Network equipment using Tacacs+
i already test using duo with duo proxy+ise+ad on-premise, but now i need use ise with azure ad, the idea is not use a duo proxy
Thanks
10-27-2021 08:39 AM
As far as I know, the only way to integrate ISE with Duo is through Radius and hence through the authentication proxy.
This is also stated in the Duo documentation:
To integrate Duo with your Cisco ISE, you will need to install a local Duo proxy service on a machine within your network. This Duo proxy server will receive incoming RADIUS requests from your Cisco ISE, contact your existing local LDAP/AD or RADIUS server to perform primary authentication, and then contact Duo’s cloud service for secondary authentication.
HTH
Antony
02-22-2022 06:01 AM
02-23-2022 05:09 AM
Hi @Jamie7 for AD you could use this guide: Duo MFA Integration with ISE for TACACS+ Device Administration with Microsoft Active Directory Users - Cisco Community
02-23-2022 05:38 AM
Thanks alot @Patricio_Mansilla, Appreciate your response.
02-19-2024 12:10 PM
Hi Guys,
I have the same query. Is it possible in the current version of ISE?
02-20-2024 01:21 PM
This gal suggests taking a look at the Duo feature released in ISE 3.3 P1:
This implements direct connectivity between ISE and Duo without Duo Authentication Proxy server deployment.
02-24-2024 07:49 AM
Hello Kristina,
Thanks a lot for your response. Does the direct integration have any limitations over the DUO Auth Proxy method?. Instead of the on-Premises AD, can we use the Azure AD along with the direct integration method?.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide