cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3746
Views
3
Helpful
7
Replies

Duo Integration with ISE for TACACS+ Device Administration with AD Users

Hi guys,

I need to know if is possible use DUO with ISE connected tu Azure AD to give access to our Network equipment using Tacacs+

i already test using duo with duo proxy+ise+ad on-premise, but now i need use ise with azure ad, the idea is not use a duo proxy

Thanks

7 Replies 7

Antony GALLEZ
Level 1
Level 1

Hi @Patricio_Mansilla,

As far as I know, the only way to integrate ISE with Duo is through Radius and hence through the authentication proxy.

This is also stated in the Duo documentation:

To integrate Duo with your Cisco ISE, you will need to install a local Duo proxy service on a machine within your network. This Duo proxy server will receive incoming RADIUS requests from your Cisco ISE, contact your existing local LDAP/AD or RADIUS server to perform primary authentication, and then contact Duo’s cloud service for secondary authentication.

HTH
Antony

Jamie7
Level 1
Level 1

Hi @Patricio_Mansilla

Can you please share how you use DUO for ISE Device Admin with AD

Thanks,

Jamie7
Level 1
Level 1

Thanks alot @Patricio_Mansilla, Appreciate your response.

Hi Guys,

I have the same query. Is it possible in the current version of ISE?

DuoKristina
Cisco Employee
Cisco Employee

This gal suggests taking a look at the Duo feature released in ISE 3.3 P1:

https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine-33/221232-configure-ise-3-3-native-multi-factor-au.html

https://www.cisco.com/c/en/us/td/docs/security/ise/3-3/release_notes/b_ise_33_RN.html#concept_btq_mhd_lzb

This implements direct connectivity between ISE and Duo without Duo Authentication Proxy server deployment.

Duo, not DUO.

Hello Kristina,

Thanks a lot for your response. Does the direct integration have any limitations over the DUO Auth Proxy method?. Instead of the on-Premises AD, can we use the Azure AD along with the direct integration method?.

Quick Links