cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
832
Views
0
Helpful
1
Replies

RSA on ISE login.

Dustin Anderson
VIP Alumni
VIP Alumni

So, I see ISE supports RSA as of 2.1

So, I have instructions and such, but was wondering if it works on the login to ISE itself.

Basically, I don't need RSA for users into their PC, but for an admin logging into ISE itself.

1 Accepted Solution

Accepted Solutions

hslai
Cisco Employee
Cisco Employee

Since Release 1.1.0, Administrative Access to Cisco ISE Using an External Identity Store is available. Note that

External Authentication and Internal Authorization—The administrator’s authentication credentials come from the external identity source, and authorization and administrator role assignment take place using the local Cisco ISE database. This model is used for RSA SecurID authentication. This method requires you to configure the same username in both the external identity store and the local Cisco ISE database.


ISE 2.1.0 added Authenticate Internal User Against External Identity Store Password but CSCvb64350 documented that

If an internal user is configured with an external identity store for authentication, while logging in to the ISE Admin portal, the internal user must select the external identity store as the Identity Source. Authentication will fail if Internal Identity Source is selected.


CSCvg68768 is an enhancement for the above caveat.


View solution in original post

1 Reply 1

hslai
Cisco Employee
Cisco Employee

Since Release 1.1.0, Administrative Access to Cisco ISE Using an External Identity Store is available. Note that

External Authentication and Internal Authorization—The administrator’s authentication credentials come from the external identity source, and authorization and administrator role assignment take place using the local Cisco ISE database. This model is used for RSA SecurID authentication. This method requires you to configure the same username in both the external identity store and the local Cisco ISE database.


ISE 2.1.0 added Authenticate Internal User Against External Identity Store Password but CSCvb64350 documented that

If an internal user is configured with an external identity store for authentication, while logging in to the ISE Admin portal, the internal user must select the external identity store as the Identity Source. Authentication will fail if Internal Identity Source is selected.


CSCvg68768 is an enhancement for the above caveat.