cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1149
Views
0
Helpful
3
Replies

ISE as RADIUS proxy, would CoA work?

mabriand
Cisco Employee
Cisco Employee

Hello,

 

I'm currently investigating ISE and DUO integration with ASA for remote access VPN. One of the options is to have ISE proxy RADIUS requests to the DUO Auth Proxy.

I was wondering if CoA (sent by ISE to ASA) would still be functional in that scenario. I'm ultimately seeking to understand if posture would be possible in that type of setup.

 

Best Regards,

Martin

1 Accepted Solution

Accepted Solutions

paul
Level 10
Level 10

I usually don't use the RADIUS proxy setup.  I prefer the RADIUS token server setup when integrating with 2FA vendors.  In that scenario I know CoA and posturing works just fine.  I would assume it should work with the RADIUS proxy setup. 

 

You can test it easily enough.  Get a device connected on VPN with DUO as RADIUS proxy in ISE.  Go to the live sessions screen and find the session.  Click Reauthentication for CoA actions and see if you see an authentication in the live logs.

View solution in original post

3 Replies 3

paul
Level 10
Level 10

I usually don't use the RADIUS proxy setup.  I prefer the RADIUS token server setup when integrating with 2FA vendors.  In that scenario I know CoA and posturing works just fine.  I would assume it should work with the RADIUS proxy setup. 

 

You can test it easily enough.  Get a device connected on VPN with DUO as RADIUS proxy in ISE.  Go to the live sessions screen and find the session.  Click Reauthentication for CoA actions and see if you see an authentication in the live logs.

mabriand
Cisco Employee
Cisco Employee

Thanks Paul, spot on.

 

Not sure why I drifted from Radius Token server to RADIUS proxy instead.

Indeed with usage of DUO Auth Proxy as a RADIUS token server, there's no concern anymore.

I'm still curious about RADIUS proxy and CoA and will test that whenever I get access to a lab setup with ISE and another RADIUS server.

 

Best Regards,

Martin

kindly please do not forget to share your finding with us.

please do not forget to rate.