cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
5050
Views
6
Helpful
10
Replies

CIsco ISE with HP and Fortigate

nimmi.phasil
Level 1
Level 1

Hi ,

I have configured HP switches 5820X and 5130 for AAA radius authentication with Cisco ISE 2.0.0.306 .

The switch receives successful authorization reply ; but unable to login . What would be the advanced attributes for Radius Authorization profile in 

ISE ?

Also , does ISE support Fotigate firewalls ?

2 Accepted Solutions

Accepted Solutions

Oh, and yes ISE supports any device that uses rfc compliant radius, it's usually only a matter of finding out what av-pairs to send back to that specific device, there is not really any standard for that.

View solution in original post

Did you read the link i attached earlier, is your config on your swith setup like that, with both authentication and accounting configured ? maybe have a read through the comments on the link i sent you, to see what other people have had problems with. I'm pretty sure it's on the switch you need to find your problem. Oh, and actually i don't think you need the quotes

View solution in original post

10 Replies 10

jan.nielsen
Level 7
Level 7

According to the link, HP expects a role to be returned as a Cisco-AVPair, you should try adding that to your authorization profile :

Cisco-avpiar = shell:roles=”network-admin”

https://abouthpnetworking.com/2014/03/16/comware7-radius-based-rbac-user-role-assignment/

Oh, and yes ISE supports any device that uses rfc compliant radius, it's usually only a matter of finding out what av-pairs to send back to that specific device, there is not really any standard for that.

so your using cisco av-pair with HP switches?

Hi Jan,

Tried

 Cisco:cisco-av-pair shell:roles=network-admin

Radius:Service-Type Administrative/Login/NAS Prompt

HP:HP-Privilege-Level 3

The server sends authorization successful messages with all combinations ; switch receives the message.

But login failed message is shown.

Did your put network-admin in quotes?

Tried with quotes

Did you read the link i attached earlier, is your config on your swith setup like that, with both authentication and accounting configured ? maybe have a read through the comments on the link i sent you, to see what other people have had problems with. I'm pretty sure it's on the switch you need to find your problem. Oh, and actually i don't think you need the quotes

Hi Jan,

The issue is resolved when accounting is configured.

Thank You !

Scott Parish
Level 1
Level 1

Nimmi,

Did you ever get ISE and Fortigate working together?

Scott

sajid231088
Level 1
Level 1

Could you please share HP switch configuration.

 

I tried to do it but couldn't het any success.