cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1641
Views
5
Helpful
3
Replies

Cisco ISE and RSA ID packet flow

AIN UL BADAR
Level 4
Level 4

Hello

I'm in the process of integrating Cisco ISE and RSA Token Server. I'll need to allow Firewall ports in this ISE Distributed Deployment. The question is, does authentications for RSA Tokens come from a PSN or from a PAN towards the RSA Server?

Thank you

1 Accepted Solution

Accepted Solutions

Greg Gibbs
Cisco Employee
Cisco Employee

This depends on what MFA use case(s) you are implementing. If you are only using MFA for user flows like Portals, these are handled by the PSNs. If you are using MFA for login to the Admin GUI (from any of the nodes), then all nodes would need connectivity.

View solution in original post

3 Replies 3

balaji.bandi
Hall of Fame
Hall of Fame

Greg Gibbs
Cisco Employee
Cisco Employee

This depends on what MFA use case(s) you are implementing. If you are only using MFA for user flows like Portals, these are handled by the PSNs. If you are using MFA for login to the Admin GUI (from any of the nodes), then all nodes would need connectivity.

Thank you Greg. It makes sense. My clients are authenticating with regular 802.1x, so it means PSNs initiate/relay the authentication requests back to RSA server.