10-28-2016 05:30 AM - edited 03-11-2019 12:11 AM
Hi Community,
I'm trying to configure Anyconnect 4.3 vpn access with ASA 9.6 with ISE 2.1 with RSA SecureId.
Desired flow: user establishes Anyconnect session with ASA. ASA uses RADIUS to communicate with ISE. ISE uses RSA SecurieID to check the passcode (authentication) and internal user database to verify user group and push appropriate attributes(authorization).
AuthC:
AuthZ:
The issue is that when I use SecureID at authentication phase, I must use it also in authorization. So my rules to match local for ISE user group does not match in authorization and I can't push policy to the user.
In Cisco ACS there is possible to create Identity Source Sequences to use one one search list for AuthC and other for AuthZ, it works fine:
In ISE there is option only for AuthC:
My final question: How to configure user authentication with SecureID Passcode and use local ISE groups for authorization?
Solved! Go to Solution.
10-31-2016 05:44 AM
I found a solution. You need to set "Password Type" on "RSA SecureID" for particular local user under: Administration > Identity Management > Identities > user like below:
10-31-2016 05:44 AM
I found a solution. You need to set "Password Type" on "RSA SecureID" for particular local user under: Administration > Identity Management > Identities > user like below:
10-31-2016 07:27 PM
Good job on finding a solution to your own problem/question! Also, thank you for taking the time to come back and post it here!
Neno
08-22-2017 09:34 AM
Was there a specific guide you used to setup ISE, ASA, and AnyConnect. I'm working on the same thing you setup, but from scratch. AnyConnect to ASA, ASA via RADIUS to ISE and ISE passing authentication to RSA. Any link or document you have would be appreciated.
Thanks
01-03-2022 08:04 AM
I have same issue, authentication is OK, but authorization failed because the user not found in identity store, any workaround for this?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide