10-23-2018 07:10 AM
Our customer uses double authentication for ASA VPN with ACS as primary authentication using AD and ISE as secondary authentication using Safenet and RSA (both in one single identity source).
They now want to move both primary and secondary authentications to ISE as they are getting rid of ACS.
I am reading below link
Was anyone able to find any attribute to distinguish between two radius requests ?
We have two datacenters with 4 PSNs. The idea to send different requests to different PSNs and making check on that also sounds feasible.
If none of the above works we will send AD authentications requests directly to AD from ASA.
Is there any other option anyone can think ? Maybe some kind of chaining
Solved! Go to Solution.
10-23-2018 08:34 PM
I think it simpler to send the AD auth directly from ASA. If the 2 requests are sent to different sets of PSNs, then you may use "Network Access·ISE Host Name" as a condition.
10-23-2018 08:34 PM
I think it simpler to send the AD auth directly from ASA. If the 2 requests are sent to different sets of PSNs, then you may use "Network Access·ISE Host Name" as a condition.
10-24-2018 05:43 AM
Hsing,
This is more of a product request, but one thing that would help in cases like this is if we were able to use the DestPort field in our rule set. If you look at the RADIUS authentication details you can see the destination port of the RADIUS call (1645 or 1812). If there were a Network Access:Destination Port value we could use it for several use cases:
The data is already there. It doesn't seem like it would be that hard to expose that data in the conditions.
10-25-2018 06:50 AM
Many thanks for your input. However, such might not be as simple. If both requests for one RA-VPN session gone into the same PSN, anything sensitive to the state of the session might mess up. If the requests gone into different PSNs, then it's unclear which PSN is the true owner of the session, as the whole deployment shares one session directory.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide