cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2217
Views
3
Helpful
2
Replies

ISE Profiling and Posturing support for PAN VPN users

Hello Experts!

I have a requirement where ISE needs to do Profiling and Posturing for VPN endpoints using PAN's GlobalProtect, I want your opinion on how to support Posturing and Profiling for VPN users connecting to the network using PAN's GlobalProtect. I have an assumption on the following info which I got from a Cisco Engineer.

  1. Palo Alto does not support RADIUS CoA (Change of Authorization) [RFC-3576]. As a result, most advanced ISE features (Posture, BYOD, Profiling, etc) on VPN would not be supported when integrating with PAN
  2. PAN does support standard RADIUS attributes. As a result, we can perform basic RADIUS based authentication for RA-VPN clients
  3. PAN does support both RADIUS and TACACS+ for device administration. Thus, ISE can be configured to provide AAA services for PAN based administrators
1 Accepted Solution

Accepted Solutions

Jason Kunst
Cisco Employee
Cisco Employee

You are correct on all 3! The only posture integrated service we have is with Cisco based vpn concentrator (ex: ASA).

I don't think you will gain much visibility with profiling as well. I have asked another SME to be sure

View solution in original post

2 Replies 2

Jason Kunst
Cisco Employee
Cisco Employee

You are correct on all 3! The only posture integrated service we have is with Cisco based vpn concentrator (ex: ASA).

I don't think you will gain much visibility with profiling as well. I have asked another SME to be sure

Currently that is correct.  Without a way to trigger CoA, then user may be deemed posture compliant but no way to reauthorize after initial quarantine without manual intervention by user.