09-28-2018 02:42 AM - edited 03-11-2019 01:50 AM
Hello All,
We have a setup in the lab where we are using passive ID with ISE and as a result the username gets mapped to multiple IP addresses.
Please see the attached document for the topology.
Lab components:
ASAv
Virtual ISE 2.3
AD – Server 2016
Workstation – Windows 10
Mail server using kerberos to AD for user.
Lab setup:
ASAv basic config with SXP to ISE.
ISE connected to AD and using Passive ID without agent.
AD basic config with.
Mail server using Kerberos.
I did only a couple of tests before dismantling the lab but this was the scenario as I experienced it.
Scenario:
Is this a known phenomenon?
Regards,
Ivana
Solved! Go to Solution.
09-28-2018 06:33 AM
We use CDA right now instead of Passive ID and it is a known behavior to map a user to different IPs depending on how they access various resources. I am guessing Passive ID works in a similar way.
It looks at the authentications from AD and maps users to the IP that the authentication came from, this is more prominent with our admin staff that RDP to different servers they could have several IPs associated with their user account. Basically any service that authenticates to AD could provide IP mappings to Passive ID for any user. It will hold on to the IP mapping until there is a logout from AD or the timeout expires.
09-28-2018 06:33 AM
We use CDA right now instead of Passive ID and it is a known behavior to map a user to different IPs depending on how they access various resources. I am guessing Passive ID works in a similar way.
It looks at the authentications from AD and maps users to the IP that the authentication came from, this is more prominent with our admin staff that RDP to different servers they could have several IPs associated with their user account. Basically any service that authenticates to AD could provide IP mappings to Passive ID for any user. It will hold on to the IP mapping until there is a logout from AD or the timeout expires.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide