11-20-2019 08:18 AM
I am in the process of trying to setup an LDAP connection to a MFA proxy server. I am able to test bind the connection and can see the connection on the MFA proxy server. The issue is when I try to login to a Nexus switch I have setup in ISE using tacacs+ for device admin. I never see anything from ISE on the MFA server when this request is done.
Here is what I am seeing in ISE:
13005 | Received TACACS+ Authorization Request | |
15049 | Evaluating Policy Group | |
15008 | Evaluating Service Selection Policy | |
15048 | Queried PIP - Network Access.Protocol | |
15048 | Queried PIP - DEVICE.Device Type | |
15041 | Evaluating Identity Policy | |
15013 | Selected Identity Source - MFA_test | |
24031 | Sending request to primary LDAP server - MFA_test | |
24016 | Looking up user in LDAP Server - MFA_test | |
24019 | LDAP connection error was encountered - MFA_test ( Step latency=45001ms) | |
22059 | The advanced option that is configured for process failure is used | |
22062 | The 'Drop' advanced option is configured in case of a failed authentication request |
I am still learning so I am sure there is something I am missing. Are there any other tools on ISe that would assist with investigating this? I am working on setting up sniffer so I don't have that info yet.
11-22-2019 03:02 PM
I don't think this is possible integration point. You can link together like DUO via a RADIUS proxy server like here but not via LDAP that i know of unless your RADIUS proxy can integrate
I also tag my coworker @hslai to see if she can take a look
11-25-2019 02:27 PM
Please note MFA may need longer timeouts because it usually waits for the user to respond (e.g. generating a new one-time password).
A couple of things to check:
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide