cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1454
Views
5
Helpful
3
Replies

ISE 2.0 strip Windows computer name from RADIUS username

5bswan
Level 1
Level 1

Hi all,

I have a customer using ISE to authenticate BYOD devices against a cisco WLC.  All the user management happens within ISE (no links to active directory, etc).  On occasion when users setup their windows machines the computer name will be sent along with the user name to RADIUS.  So, if they assign jsmith a radius account, windows will actually send over JONSLAPTOP\jsmith as the username.  Is there a way to tell ISE to strip out a computer name from the RADIUS authentication request prior to processing?

Thanks,

Brian

1 Accepted Solution

Accepted Solutions

jrabinow
Level 7
Level 7

Active Directory has an "Identity Rewrite" option that should support what you are looking for

Can see from description of this option below

Changes the format of usernames before they are passed to active directory.

Can see this options under the "Advanced Settings" tab of Active Directory

View solution in original post

3 Replies 3

jrabinow
Level 7
Level 7

Active Directory has an "Identity Rewrite" option that should support what you are looking for

Can see from description of this option below

Changes the format of usernames before they are passed to active directory.

Can see this options under the "Advanced Settings" tab of Active Directory

Can I use that if the usernames are in ISE though? ISE isn't forwarding the requests to Active Directory for authentication. 

nspasov
Cisco Employee
Cisco Employee

Identity Rewrite will indeed do the trick for you!