cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements

This community is for technical, feature, configuration and deployment questions.
For production deployment issues, please contact the TAC! We will not comment or assist with your TAC case in these forums.
Please see How to Ask the Community for Help for other best practices.

659
Views
0
Helpful
1
Replies
vaibhgupta157
Beginner

Enable password remote authentication with ISE

Hi All,

I have one requirement to do two level of authentication in NAS device, one for simple login and second one for enable password.

   

      Device--------------------------------------ISE------------------------------------OpenOtp

                            TACACS+                                  RADIUS

In first level, user needs to enter username and password which needs to be authenticated against integrated LDAP/AD or internal user database of ISE. After first level of authentication, user should be put into privilege level 1 in device. User types “enable” command in CLI, which prompts for second level password. This second level enable password should be a token password authenticated with a token server (OpenOtp)


First Level of authentication is working fine. But enable password is not working. I have integrated OpenOtp as RADIUS Token server in ISE. I am referring thread: Cisco ISE Two Factor Authentication / Authorisation with different User Identity Store

Device and ISE configuration and ISE logs are attached. ISE logs shows success for enable authentication but device gives access denied. Device accepts the local enable password. Is there something I am missing in configuration??

Thanks in advance

Regards//

Vaibhav

1 ACCEPTED SOLUTION

Accepted Solutions
hslai
Cisco Employee

I think you would need debugging on the device side and seek support from the device support team. We validate it in the lab on a Cisco switch 3850 or 3650 or CSR 1000v only.

View solution in original post

1 REPLY 1
hslai
Cisco Employee

I think you would need debugging on the device side and seek support from the device support team. We validate it in the lab on a Cisco switch 3850 or 3650 or CSR 1000v only.

View solution in original post

Content for Community-Ad