cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1360
Views
0
Helpful
11
Replies

ISE as radius for Opengear

shados
Level 1
Level 1

Hello,

I'm trying to configure Opengear to authenticate agaisnt ISE (radius) but no luck. 

https://resources.opengear.com/lighthouse/manuals/23.10/Content/Radius_Configuration.htm

I can't find Framed-Filter-ID within authorization profile or radius configurations.

have someone ever did ad auth for opengear? Please help

11 Replies 11

hi have you looked here ..see the screenshot under authorization policy and condition.

ccieexpert_0-1724466185455.png

 

JPavonM
VIP
VIP

It the IETF RADIUS attribute is not recognised by OpenGear (maybe becuase it is not the same Attribute number), you may need to create a custom dictionary for them.

I've had to do that for Forescout, F5 and others.

HEre you can find some, but not OpenGear, so if the workaround that @ccieexpert told you before doesn't work, you may need to ask their support for the correct RADIUS Att number and use one of the dictionaries as an example.

https://github.com/boundary/wireshark/tree/master/radius

 

Why not use TACACS+ for OpenGear instead?

Is there a guide on how to setup ISE TACACS for Opengear?

that's for TACACS+ not for ISE. Is there a way to adapt those settings for ISE?

What do you mean?  You just create a custom TACACS+ Profile containing the group membership text as outlined in the article.

If you need to use OTP, than I think RADIUs might be the only answer.

shados
Level 1
Level 1

Is there a guide on how to do that?

bmccollam77
Level 1
Level 1

I have OpenGear working with radius in ISE 3.1

You'll need to make sure you configure the proper Authorization Profile.