cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1949
Views
0
Helpful
7
Replies

Send NAS-ID while authenticating against RADIUS Token Server

danhamil
Cisco Employee
Cisco Employee

Hi,

For an ISE deployment using an NPS server for MFA, can ISE send the NAS-ID to simplify policies on the NPS side?  i.e. Is it possible in an ISE authentication policy to add/include radius av pairs while authenticating against a RADIUS Token server?

Thanks,

-Dan

1 Accepted Solution

Accepted Solutions

Craig Hyps
Level 10
Level 10

To add/remove/modify RADIUS attributes, you must use RADIUS Proxy.

Craig

View solution in original post

7 Replies 7

Craig Hyps
Level 10
Level 10

To add/remove/modify RADIUS attributes, you must use RADIUS Proxy.

Craig

The customer wants to send the NAS-ID Radius attribute to the RADIUS token server.

How can I send the unique NAS-ID to the external RADIUS token server?  I am not seeing how to configure that in ISE.

Can you let me know where and how that is configured in ISE?

-Dan

Already responded to question.  You cannot manipulate the RADIUS request attributes for RADIUS Token, only for RADIUS Proxy.

How/Where do you modify/view the attributes that are sent to the radius proxy? In ISE 2.3, when you configure proxy service in the authentication policy, you are only allowed to enter authentication conditions.   There is little configuration in the Proxy setup.I can see where there are dictionary attributes defined, but don't see how those are applied when communication with the external radius server.  So the original question, How do I view and or modify what is being sent to the external radius server.  It may be simple and I am missing it.

Administration > Network Resources > RADIUS Server Sequences > (Sequence_Name) > Advanced Attribute Settings

Got it now.  Tab was not showing up in my Chrome browser.  Switched to FF and now it makes sense.  Thanks

Did it work by sending the NAS-ID?

 

I'm having a similar request from a customer who is using MS NSP as an external radius server but haven't got the chance to configure it yet.