cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
659
Views
1
Helpful
4
Replies

ISE EAP-TLS identities send over PxGrid as user

Ezequ!el
Level 1
Level 1

Hi!

We are using ISE to authenticate computers connecting to our LAN using EAP-TLS and share those authenticated identities over PxGrid with 3rd party products.

The problem we are hitting is PxGrid shares those identities as user identities and not as machine identities. Is there any way to influence that?

This is working fine on MAB authenticated computers, as their identities are shared by the PxGrid as machine identity.

Thanks in advance.

4 Replies 4

ammahend
VIP
VIP

can you share a live log detail for your EAP-TLS successful authentication

 

-hope this helps-

Uli1412
Level 1
Level 1

Hi,

I am Ezequiel's colleague. All of our clients have these problems.

I hope you mean the following:

Authentication Details

Source Timestamp2023-12-22 02:26:03.652
Received Timestamp2023-12-22 02:26:03.652
Policy Servercisco-ise
Event5200 Authentication succeeded
Usernamepc.local.domain
Endpoint Id99:62:26:BF:99:D3
Calling Station Id45-32-99-AD-99-D3
Endpoint ProfileHP-Device
IPv4 Address10.98.98.98
IPv6 Addressxxxx
Identity GroupProfiled
Audit Session Id5EA772359700991A8F32A868
Authentication Methoddot1x
Authentication ProtocolEAP-TLS
Service TypeFramed
Network Deviceswitch123.local.domain
Device TypeAll Device Types#SDA
LocationAll Locations#GER
NAS IPv4 Address10.99.99.99
NAS Port IdGigabitEthernet1/0/1
NAS Port TypeEthernet
Authorization ProfileResult_SGT123
Security GroupSGT123
Response Time11 milliseconds

Many thanks and best regards

Uli

hslai
Cisco Employee
Cisco Employee

@Ezequ!el and @Uli1412 The session info sent from ISE via pxGrid does indicate whether the auth sessions resulted from computer/machine auth. Until Firepower able to consume such correctly, please separate the ISE deployments if possible.

Uli1412
Level 1
Level 1

Hello @hslai 

Thanks for your answer!

What do you mean by "seperate the ISE deployments"?