11-14-2019 10:14 PM - edited 11-14-2019 10:24 PM
We have users with account's in different domains. We ask "meberOf" for vpn authorisation from one specific domain. Not all users login in at the domain where this memberOf are located . If the account out from the domain we doing "authorisation" is expired ISE will not give me the meberOf caused by "expired account"
Is there any chance to "tell" ISE to ignore "expired account" for memberOf requests ?
Solved! Go to Solution.
11-20-2019 08:05 AM
If the AD connection is defined as an Active Directory join point in ISE, why not using "Groups", instead of "memberOf"? If as an LDAP object, then why not as an Active Directory object?
The attribute "memberOf" does not include the primary group membership and also does not show membership from nested groups. Using "Groups" with the AD join points have no such limit.
I do not think it related to expired accounts.
11-19-2019 11:35 AM
I am pretty sure its not possible but will ask @hslai see what she thinks
11-20-2019 08:05 AM
If the AD connection is defined as an Active Directory join point in ISE, why not using "Groups", instead of "memberOf"? If as an LDAP object, then why not as an Active Directory object?
The attribute "memberOf" does not include the primary group membership and also does not show membership from nested groups. Using "Groups" with the AD join points have no such limit.
I do not think it related to expired accounts.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide