02-01-2018 01:46 PM
So, I see ISE supports RSA as of 2.1
So, I have instructions and such, but was wondering if it works on the login to ISE itself.
Basically, I don't need RSA for users into their PC, but for an admin logging into ISE itself.
Solved! Go to Solution.
02-01-2018 02:39 PM
Since Release 1.1.0, Administrative Access to Cisco ISE Using an External Identity Store is available. Note that
External Authentication and Internal Authorization—The administrator’s authentication credentials come from the external identity source, and authorization and administrator role assignment take place using the local Cisco ISE database. This model is used for RSA SecurID authentication. This method requires you to configure the same username in both the external identity store and the local Cisco ISE database.
ISE 2.1.0 added Authenticate Internal User Against External Identity Store Password but CSCvb64350 documented that
If an internal user is configured with an external identity store for authentication, while logging in to the ISE Admin portal, the internal user must select the external identity store as the Identity Source. Authentication will fail if Internal Identity Source is selected.
CSCvg68768 is an enhancement for the above caveat.
02-01-2018 02:39 PM
Since Release 1.1.0, Administrative Access to Cisco ISE Using an External Identity Store is available. Note that
External Authentication and Internal Authorization—The administrator’s authentication credentials come from the external identity source, and authorization and administrator role assignment take place using the local Cisco ISE database. This model is used for RSA SecurID authentication. This method requires you to configure the same username in both the external identity store and the local Cisco ISE database.
ISE 2.1.0 added Authenticate Internal User Against External Identity Store Password but CSCvb64350 documented that
If an internal user is configured with an external identity store for authentication, while logging in to the ISE Admin portal, the internal user must select the external identity store as the Identity Source. Authentication will fail if Internal Identity Source is selected.
CSCvg68768 is an enhancement for the above caveat.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide