05-07-2019 06:10 AM
Hi All,
Any assistance would be greatly appreciated.
I am sending radius auth logs to a Palo Alto for identity based policies.
It works, but it seems every type of device sends the logs in a different manner for example
I am writing reg expressions and can keep doing this to match the usernames, but this doesnt seem scalable.
Is there any way to tell ISE to just send the username instead of everything?
Solved! Go to Solution.
05-07-2019 06:39 AM
Identity is being sent by the supplicant as Domain\\isetest or domain\domain\isetest.
Please configure at the supplicant end to sent only username as identity. If you have to authenticate users from multiple domains. [domain]\[username] is a preferable identity.
05-07-2019 06:39 AM
Identity is being sent by the supplicant as Domain\\isetest or domain\domain\isetest.
Please configure at the supplicant end to sent only username as identity. If you have to authenticate users from multiple domains. [domain]\[username] is a preferable identity.
05-11-2019 10:31 PM
Aravind Ravichandran is correct on this. Such logs are more for ISE to consume and process further. pxGrid is more for partners to integrate with.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide