10-19-2018 07:08 AM
I don't think DUO Proxy matters in this case, but how does radius token Primary and failover server work. I can never get the authentication to access the secondary server. Timeout on primary is 60 seconds. Do I need to lower this?
Policy says "if process fails [DROP]" I assume this means it would query the secondary server in the radius token. Doesnt seem to ever get there.
Solved! Go to Solution.
11-29-2018 05:36 AM
Well after much aggravation and working with DUO they have suggested that we redesign this.
Rather then ASA - ISE - DUO Proxy
They suggested ASA - DUO - ISE
We had a lot of timing issues with the original design and many lockouts.
Some issues now is with dACLs and my Anyconnect clients. From what I can gather, due to the fact I inherited this setup, when the ASA sends radius requests to ISE in addition to the radius ports its sents CoA on port 1700 to ISE. Now with DUO servers in the middle and the ASA sending radius requests to DUO and not ISE, dACLs seem to now work.
How is this setup built with something like RSA? There has to be similarities.
11-29-2018 06:20 AM
11-29-2018 06:24 AM
11-29-2018 06:59 AM
11-29-2018 08:46 AM
Ok so create two separate AAA server groups, one with DUO proxy's using the radius port 1812, and the other using ISE servers using also the radius port but with CoA port 1700 on it?
So Anyconnect client connects and is prompted for username and password, user types DomainA/username and then the ASA calls to DUO and then DUO does an AD lookup to the DC using the [ad_client] section. So that is then a go or a no, if a go then the ASA calls to ISE and looks at what?
How would you build your authentication section in ISE policy set?
I think the challenge is still two forest domains. Right now ISE makes the choice to which DC is queried based on radius name consisting of DomainA or DomainB.
12-04-2018 12:47 PM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide