02-18-2018 02:25 AM
Hello,
we are using ISE 2.0 which is integrated with AD, we need to integrate with VASCO too required scenario as the follow
user connects through wired network, authenticate from AD by SSO, ISE checks if this OU should be authenticated from VASCO too or not
if yes ISE check with VASCO and anyconnect client on user machine pop up to let the user enter VASCO key
also is there any need to change something on switches please specify
Is this applicable ?!
Solved! Go to Solution.
02-18-2018 08:52 PM
Please review this previous discussion -- Re: Two factor authentication on LAN
If OU is not a typo, it's possible to match on some AD attribute, such as distinguishedName, but that could pose a performance hit on the AD.
Note that CWA Chaining is available in ISE 2.1 onwards so it would not work in ISE 2.0.
02-18-2018 08:52 PM
Please review this previous discussion -- Re: Two factor authentication on LAN
If OU is not a typo, it's possible to match on some AD attribute, such as distinguishedName, but that could pose a performance hit on the AD.
Note that CWA Chaining is available in ISE 2.1 onwards so it would not work in ISE 2.0.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide