10-01-2017 07:35 AM
We have ISE 2.3 up to replace CDA for our WSA solution. PassiveID is working and pulling all user<>IP mappings and seeing the groups. We need to apply our created SGTs solely based on the PassiveID / AD groups from the users and are not having any luck. We've seen some documentation for older ISE versions but cannot recreate it in 2.3 with Policy Sets on.
Solved! Go to Solution.
10-03-2017 06:31 AM
CDA and ISE Passive ID cannot assign an SGT today without a RADIUS authorization. External solutions can still leverage AD group info sent in log or pxGrid updates.
10-03-2017 06:31 AM
CDA and ISE Passive ID cannot assign an SGT today without a RADIUS authorization. External solutions can still leverage AD group info sent in log or pxGrid updates.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide