04-17-2018 04:00 PM
Hello,
I am installing ISE 2.3. We have a requirement to utilize the internal user database for READWRITE access and the RSA 2FA for the READONLY to our cisco environment. I was able to do this on my other network with ACS, but a can't figure out how to on ISE. I know it has to do with the device admin policy set, but I just cant figure it out. Any help would be greatly appreciated.
Solved! Go to Solution.
04-18-2018 08:54 AM
So based on your link, I was able to work out what 2.3 was looking for. I had to create an authentication rule tied to a condition using the tacacs:user tied to internal and then the default tied to RSA. I then created the two authorization polices one using a internal condition for the R/W and the network_authentication_passed condition for the RSA for R/O.
Thanks Nidhi for pointing me in the right direction .
04-17-2018 10:09 PM
You might want to look at this thread here - Cisco ISE Two Factor Authentication / Authorisation with different User Identity Store
04-18-2018 06:05 AM
Thank you for the response. That looks similar to how I did it is ACS. Can you help clarify what it would look like in 2.3? I am very confused by its logic and design requirements.
04-18-2018 08:54 AM
So based on your link, I was able to work out what 2.3 was looking for. I had to create an authentication rule tied to a condition using the tacacs:user tied to internal and then the default tied to RSA. I then created the two authorization polices one using a internal condition for the R/W and the network_authentication_passed condition for the RSA for R/O.
Thanks Nidhi for pointing me in the right direction .
04-18-2018 09:07 AM
Would be great if you can share your notes with the community ☺
Thanks!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide