08-02-2018 12:29 AM
Hello
Lets assume that remote access VPN solution supports to have only machine authentication on vpn connection establishment.
And machine authentication should be done via AD computer object attribute.
Can we have ISE between tunnel head-end and AD server in this scenario supporting this kind of authentication via Radius?
Many Thanks
Ivana
Solved! Go to Solution.
08-05-2018 06:24 PM
If SSL RA VPN, then it's ASA terminate the SSL, but it's possible to perform authorization to ISE and verify the AD attributes. See Solved: Re: Machine Authentication Using ASA VP... - Cisco Community
If IKEv2 IPSec RA VPN, I've seen some setup terminating EAP-TLS at ISE using EAP but I am not certain whether a machine certificate can be used.
08-05-2018 06:24 PM
If SSL RA VPN, then it's ASA terminate the SSL, but it's possible to perform authorization to ISE and verify the AD attributes. See Solved: Re: Machine Authentication Using ASA VP... - Cisco Community
If IKEv2 IPSec RA VPN, I've seen some setup terminating EAP-TLS at ISE using EAP but I am not certain whether a machine certificate can be used.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide