09-06-2017 06:12 AM
Hi All,
May I confirm that currently the supported use-case for 3rd party VPN concentrator are only for AAA services if they are able to support these radius attributes:
For VPN concentrators to integrate with Cisco ISE, the following authentication, authorization, and accounting (AAA) attributes should be included in the RADIUS communication:
Note For VPN devices, the RADIUS Accounting messages must have the Framed-IP-Address attribute set to the client’s VPN-assigned IP address to track the endpoint while on a trusted network.
Profiling and Posture on 3rd party VPN concentrator (e.g. checkpoint or juniper) are not available with ISE 2.2 currently?
Best Regards,
Jimmy
Solved! Go to Solution.
09-11-2017 04:29 PM
You are correct.
Craig said,
We can integrate as a standard AAA server for RADIUS services, but comprehensive support for services like Posture/MDM are currently limited due to lack of CoA support on the 3rd-party VPN gateway.
... Make sure NAD Profile has Juniper dictionary loaded if not using default Juniper NAD profile.
09-11-2017 04:29 PM
You are correct.
Craig said,
We can integrate as a standard AAA server for RADIUS services, but comprehensive support for services like Posture/MDM are currently limited due to lack of CoA support on the 3rd-party VPN gateway.
... Make sure NAD Profile has Juniper dictionary loaded if not using default Juniper NAD profile.
05-08-2018 04:07 AM
Hi,
Is it same status for third party VPN concentrator? We are doing PoC for bank customer. They have Juniper firewall where VPN clients terminate. Customer wants to have authentication and posture verification for VPN clients.
Is it possible with ISE 2.4 and Juniper firewall?
Can't we use inline PSN solution that we used for Cisco ASA previously?
Regards,
D.M.Gore
05-08-2018 04:15 AM
Please see the answer it mentions juniper firewall, not sure of your question seems like already answered?
05-08-2018 07:28 AM
Yes, I do understand third party devices do not support CoA, hence can't have posture support. But can't we use inline ISE PSN node to support device with CoA support?
05-09-2018 06:42 AM
The last ISE release supporting an inline posture node is of ISE 1.4.
09-27-2017 09:30 AM
Understood. Thank you
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: