10-03-2018 11:59 AM
Hello everyone.
I'm running ISE 2.1 patch6 and I'm having some weird issue with authorization for VPN connections.
No matter what I do to the authorization profiles in the policy set for VPN connections, the authorization always falls to denyaccess.
When I look at the authentication details, I can see the user authenticates successfully, but when it comes to matching authorization policy, it goes straight to denyaccess. Weird part is that I don't even have any authorization policy permission set to denyaccess. Even default policy is set to PermitAccess.
In the RADIUS live log, I can see the correct authentication policy, but authorization policy is blank meaning it's not even hitting the default authorization policy.
Has anyone run into this issue?
10-03-2018 08:08 PM
Please share the vpn policy sets with detailed radius log.
10-04-2018 11:06 AM
10-04-2018 06:55 PM
Hi,
There is some policy in exception policy which is meant to check was machine authenticate equals true.
Please share the exception policy as well.
10-05-2018 10:26 AM
10-03-2018 10:06 PM
Looks like an issue with policies configured.
please share the details
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide