12-07-2021 09:29 AM
Hello
I'm in the process of integrating Cisco ISE and RSA Token Server. I'll need to allow Firewall ports in this ISE Distributed Deployment. The question is, does authentications for RSA Tokens come from a PSN or from a PAN towards the RSA Server?
Thank you
Solved! Go to Solution.
12-07-2021 02:11 PM
This depends on what MFA use case(s) you are implementing. If you are only using MFA for user flows like Portals, these are handled by the PSNs. If you are using MFA for login to the Admin GUI (from any of the nodes), then all nodes would need connectivity.
12-07-2021 01:59 PM
check below flows : (Hope this helps you understand)
12-07-2021 02:11 PM
This depends on what MFA use case(s) you are implementing. If you are only using MFA for user flows like Portals, these are handled by the PSNs. If you are using MFA for login to the Admin GUI (from any of the nodes), then all nodes would need connectivity.
12-08-2021 06:17 AM
Thank you Greg. It makes sense. My clients are authenticating with regular 802.1x, so it means PSNs initiate/relay the authentication requests back to RSA server.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide