cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1919
Views
2
Helpful
3
Replies

Radius attribute Class (25) as a condition in AuthZ policy

sahaputh
Level 1
Level 1

Hi,

How can we configure Radius attribute Class (25) as a condition in AuthZ policy?

This is a Anyconnect scenario,where user authentication from ASA (Radius Access-Request) is sent to ISE and ISE send it to an external Radius server (Proxy Service). External Radius server is sending Access-Accept with the corresponding class attribute. How can we use this received class attribute as a condition in authorization policy. I noticed in dictionaries, Radius Class (ID 25) direction is preconfigured with "OUT" and can't change it since it's System defined. Is there's a way to accomplish this?

Thanks!

TK.

1 Accepted Solution

Accepted Solutions

Jason Kunst
Cisco Employee
Cisco Employee

This is not a current option. Working this offline to address the use case to see if its a feature request

View solution in original post

3 Replies 3

Jason Kunst
Cisco Employee
Cisco Employee

This is not a current option. Working this offline to address the use case to see if its a feature request

Jatin Katyal
Cisco Employee
Cisco Employee

Did we make any progress to have Radius Attribute Class (25) as a condition in authorization policy.

~ Jatin

~Jatin

Nope. This is tracked by CSCus80472. I will add a release note enclosure in a moment so expect it externally visible in a day or two.