05-09-2018 09:11 AM
I tried to setup Radius in ISE to do the administrator authentication for Palo Alto Firewall. I have the following security challenge from the security team.
Both Radius/TACACS+ use CHAP or PAP/ASCII
By CHAP – we have to enable reversible encryption of password which is hackable .
By PAP/ASCII – the password is in pain text sending between the Radius server and the Palo Alto. It is insecure.
If I wish to use Cisco ISE to do the administrator authentication , what is the recommended authentication method that we can use? Thanks
05-09-2018 12:17 PM
05-10-2018 05:53 PM
ISE can do IPSec -- Configure ISE 2.2 IPSEC to Secure NAD (IOS) Communication - Cisco
Else, ensure the communications between ISE and the NADs are on a separate network.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide