02-03-2017 04:04 AM
There are couple of questions that I need confirmation for
Q: Can StealthWatch report this easily? How can we stop/alert (the admin) if this happens?
Many thanks,
Abhi
Solved! Go to Solution.
02-03-2017 04:42 AM
Abhishek,
1. This is easily accomplished with ISE 2.2. Navigate to Administration > System > Settings > Max Sessions.
2. This is covered in the Clean Access Manager Installation and Configuration Guide.
3. You can perform both authentications of the Two-Factor Authentication flow within ISE. For example using RSA as the second factor as found Here in the Admin Guide.
02-03-2017 04:42 AM
Abhishek,
1. This is easily accomplished with ISE 2.2. Navigate to Administration > System > Settings > Max Sessions.
2. This is covered in the Clean Access Manager Installation and Configuration Guide.
3. You can perform both authentications of the Two-Factor Authentication flow within ISE. For example using RSA as the second factor as found Here in the Admin Guide.
02-03-2017 06:42 AM
Brilliant, thanks Charles.
02-03-2017 10:35 AM
Hi Abhishek,
Few things to remember,
Point 1 above shows how it can be done. Again this is supported in ISE 2.2. However, I dont think we generate alerts on these.
Point 2 above, CCA is an older solution.I would suggest going the ISE route. In ISE 2.2, we have a way to do posture with no URL-redirect that can be used in 3rd party environments. You need Anyconnect for that. Anyconnect has a headless mode where this can be installed without UI. Anyconnect also supports web agent that could be used for non-admin.
For point 3, apart from RSA secure ID, any solution that supports RFC 2865 compliant token server is supported. EAP-chaining can also be considered for two step verification. You can use Symantec VIP with guest for two factor or SAML 2.0 SSO with form-auth. The compatibility guide lists the external ID servers we support
Cisco Identity Services Engine Network Component Compatibility, Release 2.2 - Cisco
ISE Design & Integration Guides talks about Symantec VIP.
Thanks
Krishnan
02-06-2017 02:42 AM
Thanks Krish! Much appreciated..
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide