07-09-2018 02:27 AM
Hi Experts,
In the ACS vs ISE feature table, there is a feature called radius token attribute support, what is this specific feature? Is there any details on it?
Thanks,
Wendy
Solved! Go to Solution.
07-09-2018 08:42 AM
No specific reference provided, but assume it is option for RADIUS Token server to return a single authorization attribute to ISE for mapping to ISE Authorization Policy. From Admin UI...
"The RADIUS Token server may be configured to return a value in a Cisco av-pair with the format:attribute_name. If this is received from the Token Server, it may be placed into a dictionary value for subsequent authorization policy. To enable this feature, enter a name for the RADIUS Token Dictionary attribute below.
A common case is a "CiscoSecure-Group-Id" in the Cisco av-pair, using the name CiscoSecure-Group-Id."
07-09-2018 08:42 AM
No specific reference provided, but assume it is option for RADIUS Token server to return a single authorization attribute to ISE for mapping to ISE Authorization Policy. From Admin UI...
"The RADIUS Token server may be configured to return a value in a Cisco av-pair with the format:attribute_name. If this is received from the Token Server, it may be placed into a dictionary value for subsequent authorization policy. To enable this feature, enter a name for the RADIUS Token Dictionary attribute below.
A common case is a "CiscoSecure-Group-Id" in the Cisco av-pair, using the name CiscoSecure-Group-Id."
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide