cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
457
Views
0
Helpful
1
Replies

Radius Interface for Identity sharing from ISE

jitesar
Cisco Employee
Cisco Employee

When using ASA as identity FW and CDA doesn’t work or is not good enough we are aiming at ISE as the identity source.

 

We have 2 options how to get indentity over Windows WMI: Passive Identity Services (it is practically ISE embedded CDA) or Easy Connect. Both:  „Passive Identity Services“ or „Easy Connect“ can share identity only via PxGrid currently.

So until we will have RADIUS interface for identity sharing in ISE and/or we will have PxGrid interface in ASA we can’t share identity directly from ISE to ASA.

 

ISE does not currently have the CDA RADIUS interface the ASA needs to get identity information & ASA doesn't speak in PxGrid.

 

CDA itself can have problem with installation on newer versions of AD, so ISE should be our identity (or context) information source. But we can't share it from ISE to ASA :-(

 

Sharing this topic as limitation, when using ASA identity FW with ISE with current versions of ISE/ISE-PIC.

1 Accepted Solution

Accepted Solutions

kthiruve
Cisco Employee
Cisco Employee

This is product related question and has been addressed in an internal forum. Closing the question here.

 

-Krishnan

View solution in original post

1 Reply 1

kthiruve
Cisco Employee
Cisco Employee

This is product related question and has been addressed in an internal forum. Closing the question here.

 

-Krishnan