cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
445
Views
5
Helpful
1
Replies

Migrating from ACS to ISE

Andreas88
Level 1
Level 1

Hello, i am finaly migrating from ACS to ISE, but i have a question regarding radius token server.

We want as little downtime as possible, so thats why im asking.

In acs i have set up a remote radius server for identity like this.

Andreas88_0-1666597535139.png

Im under the understanding that i can only use one attribute with a radius token server in ISE, but my question is what should i put under Authorization: To match my old config?

Andreas88_1-1666597622945.png

When doing a debug on a device, i'm seeing the following: Cisco-AVPair = 'ACS:CiscoSecure-Group-Id=200'

So i guess the attribute name should be ACS:CiscoSecure-Group-Id ?

 

 

 

1 Accepted Solution

Accepted Solutions

Arne Bier
VIP
VIP

This question brings back distant memories when I had to do the same thing. ISE still prefixes the "ACS:" part - so all you need to configure into ISE GUI is 'CiscoSecure-Group-Id'

View solution in original post

1 Reply 1

Arne Bier
VIP
VIP

This question brings back distant memories when I had to do the same thing. ISE still prefixes the "ACS:" part - so all you need to configure into ISE GUI is 'CiscoSecure-Group-Id'

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: