02-07-2022 05:38 AM
Hello together
I have different client types, which all authenticates with MsCHAPv2.
Some groups of clients has the accounts/passwords stored as internal user in the Cisco ISE, other accounts/passwors are stored in the active directory.
Now I want to make a policyset, where all clients with MsChapV2 first search in the internal store of the ISE. If the users there are not found, it should look in the active directory.
Is it possible to do it like this?
Solved! Go to Solution.
02-07-2022 05:56 AM - edited 02-07-2022 05:56 AM
As long as a user is verified against a policy set based on the matched protocol, an identity source sequence with internal store and AD can be used to verify the user in these stores. Provided internal store is the first in the sequence, it will be checked first followed by AD.
02-07-2022 05:56 AM - edited 02-07-2022 05:56 AM
As long as a user is verified against a policy set based on the matched protocol, an identity source sequence with internal store and AD can be used to verify the user in these stores. Provided internal store is the first in the sequence, it will be checked first followed by AD.
02-07-2022 07:47 AM
Perfect, the sequences is what I searched. Thank you very much for your fast answere!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide