cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements

This community is for technical, feature, configuration and deployment questions.
For production deployment issues, please contact the TAC! We will not comment or assist with your TAC case in these forums.
Please see How to Ask the Community for Help for other best practices.

1019
Views
10
Helpful
6
Replies
jewfcb001
Beginner

็How can configure ISE for FIX 2 IP for 1 Users

Hi All ,

I try to configure Cisco ISE Static IP for User VPN(User Custom Attributes) . It's working fine . But  If I need to configure fix 2 IP Address for 1 User .I'm not sure how can do it for this situation and condition on Cisco ISE. 

 

Please advise me .

1 ACCEPTED SOLUTION

Accepted Solutions

Definitely

 

Create two Authorization Profiles, which include the custom IP address attributes (and anything else you need)

 

Authorization Profile VPN_NAS1:

VPNNAS1.PNG

 

 

 

And the other one - VPN_NAS2:

VPNNAS2.PNG

 

And then use them in the Authorization Policy

policy1.PNG

 

 

 

View solution in original post

6 REPLIES 6
Arne Bier
VIP Advisor

@jewfcb001 - how does this work in theory? What is the 2nd IP address used for? Can you give more details about this?

 

As you already found out, you can return custom attributes when internal ISE users are authenticated. The question I have is

  • Does this user always need 2 fixed IP addresses?
  • or ... do you need to assign a different IP address for the same user, but under different conditions? (e.g. user bob needs IP:10.10.10.1 when connecting from location A, and IP: 20.20.20.1 when connecting from location B)
jewfcb001
Beginner

@Arne Bier 

or ... do you need to assign a different IP address for the same user, but under different conditions? (e.g. user bob needs IP:10.10.10.1 when connecting from location A, and IP: 20.20.20.1 when connecting from location B

    Yes , It's my objective. I found user custom attributes and I can configure many attribute for Static  IP address . I think I can use this option for my objective and configure this option on authorization for seperate location.. Please advise me again .

 ise.pngise2.png

Sadly ISE is not flexible in that way. If the user is successfully authenticated, then ISE will make those custom attributes available to you in your Authorization Profile - but you cannot be conditional about it.

 

One way around this would be to create two Authorization Rules with matching Authorization Profiles - and then to return the correct Authorization Profile depending on the Authorization logic that you're using. Is that scalable for you?

 

Example Authorization Profile below (which returns both IPs - of course this is non-sensical - the NAS can only handle (the last) one)

ipaddr.png

jewfcb001
Beginner

@Arne Bier 

 I will use 2 authorize profile and use NAS condition for seperate Static IP. 

 

what do you think? Is it possible ?

Definitely

 

Create two Authorization Profiles, which include the custom IP address attributes (and anything else you need)

 

Authorization Profile VPN_NAS1:

VPNNAS1.PNG

 

 

 

And the other one - VPN_NAS2:

VPNNAS2.PNG

 

And then use them in the Authorization Policy

policy1.PNG

 

 

 

View solution in original post

jewfcb001
Beginner

@Arne Bier 

 

Thank you for the answer . I will try in my lab . I think this solution good for me . 

Content for Community-Ad