cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1238
Views
0
Helpful
5
Replies

Issue with authorization for VPN connections

SangLim
Level 1
Level 1

Hello everyone.

 

I'm running ISE 2.1 patch6 and I'm having some weird issue with authorization for VPN connections.

No matter what I do to the authorization profiles in the policy set for VPN connections, the authorization always falls to denyaccess.

When I look at the authentication details, I can see the user authenticates successfully, but when it comes to matching authorization policy, it goes straight to denyaccess.  Weird part is that I don't even have any authorization policy permission set to denyaccess.  Even default policy is set to PermitAccess.

 

In the RADIUS live log, I can see the correct authentication policy, but authorization policy is blank meaning it's not even hitting the default authorization policy.

 

Has anyone run into this issue?

5 Replies 5

Please share the vpn policy sets with detailed radius log.

-Aravind

Please see the attached screenshots.

Hi,

There is some policy in exception policy which is meant to check was machine authenticate equals true.

Please share the exception policy as well.

-Aravind

Here's the exception policy

Nidhi
Cisco Employee
Cisco Employee

Looks like an issue with policies configured. 

please share the details