cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1863
Views
0
Helpful
3
Replies

Device Admin for GUI Based Device using LDAP

Madhuri Dewangan
Cisco Employee
Cisco Employee

Hello Expert,

 

My customer's requirement is , they want to use RADIUS protocol for Device Administration for the GUI Based Devices. 

External Identity Source to be used for the same is LDAP server running in a Microsoft Server. 

We have configured the Authc and Authz Policy for the same. Issue which we are facing here is when a user is logging into the GUI their authentication is failing, but on ISE RADIUS Live logs failed log is not seen. (No logs available for GUI Authentication Request)

We took packet capture for the same where we can seen device is sending "ACCESS-ACCEPT" to ISE node but node is sending back "ACCESS-REJECT".

Please note If we are using MS- Active Directory in AUthentication Rule same is working fine. But here the requirement is to use the LDAP server.

I have attached the pcap for the same.

Any pointer for the resolving this issue is really helpful!!!

 

Thanks and Regards,

1 Accepted Solution

Accepted Solutions

Arne Bier
VIP
VIP

Hi @Madhuri Dewangan 

 

Sounds to me as if your LDAP integration is perhaps not working as expected.  You would need to share some more details about how you integrated the LDAP, and the various tabs of the config that relate to that. I have set it up myself in the past and it's a fiddle job to get the parameters right (AD is plug and play, but with LDAP you have to be very prescriptive and exact).

 

Does the bind from ISE to LDAP success?

 

ldap1.PNG

 

If your Subject Search Base and Group Search Base is setup correctly then you should be able to Retrieve Groups from Directory as a confirmation.

 

 

The wireshark doesn't tell us much - if you still have the pcap file, add an OR filter to include ldap - let's see what's going on there. And the ISE Live Logs must be showing the access-request at least, or else you have some suppression enabled that is blocking it.  Disable it temporarily for testing

Admin -> System -> Settings ->Protocols -> RADIUS   and then uncheck the "Suppress repeated failed auths"

 

 

 

 

View solution in original post

3 Replies 3

Arne Bier
VIP
VIP

Hi @Madhuri Dewangan 

 

Sounds to me as if your LDAP integration is perhaps not working as expected.  You would need to share some more details about how you integrated the LDAP, and the various tabs of the config that relate to that. I have set it up myself in the past and it's a fiddle job to get the parameters right (AD is plug and play, but with LDAP you have to be very prescriptive and exact).

 

Does the bind from ISE to LDAP success?

 

ldap1.PNG

 

If your Subject Search Base and Group Search Base is setup correctly then you should be able to Retrieve Groups from Directory as a confirmation.

 

 

The wireshark doesn't tell us much - if you still have the pcap file, add an OR filter to include ldap - let's see what's going on there. And the ISE Live Logs must be showing the access-request at least, or else you have some suppression enabled that is blocking it.  Disable it temporarily for testing

Admin -> System -> Settings ->Protocols -> RADIUS   and then uncheck the "Suppress repeated failed auths"

 

 

 

 

I would also recommend working through TAC for deep level troubleshooting and support

Hi Jason,

Thanks,

I have managed to resolve this issue by changing the subject name to cn.