cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
644
Views
0
Helpful
2
Replies

Use ISE as an external radius server in another ISE

juan.saavedra
Level 1
Level 1

Hello,

This is the scenario: three companies are part of a corporate, we want to authenticate this users by 802.1x, there have 3 Active Directory and 3 Cisco ISE.

Is not posible to join in a forest or "connect" Active Directoy.

This:

userA@companyA.com --> WLC Company B --> ISE Company B --> radius_connection --> ISE Company A --> AD@companyA.com

Is this possible?

THANK YOU!

1 Accepted Solution

Accepted Solutions

jan.nielsen
Level 7
Level 7

Yes, it's called radius proxy. You can create seperate authentication rules, that match the domain name in your username, and send the request on to the proper ISE server.

In ISE it's the authentication policy, and the radius server sequence you need to work with

View solution in original post

2 Replies 2

jan.nielsen
Level 7
Level 7

Yes, it's called radius proxy. You can create seperate authentication rules, that match the domain name in your username, and send the request on to the proper ISE server.

In ISE it's the authentication policy, and the radius server sequence you need to work with

juan.saavedra
Level 1
Level 1

Thank you, Jan.

I tried, it work well.