cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2465
Views
0
Helpful
2
Replies

Using ISE to block TOR IP’s from connecting to VPN concentrators

tgallawa
Cisco Employee
Cisco Employee

Is it possible to have ISE block TOR IP's from connecting to an ASA RAVPN?

1 Accepted Solution

Accepted Solutions

Marvin Rhoads
Hall of Fame
Hall of Fame

ISE is the wrong solution for that requirement. Ideally have an upstream NGFW/IPS with geoblocking. Or use MFA (like Duo) with geofencing requirements enforced on the MFA client.

View solution in original post

2 Replies 2

Colby LeMaire
VIP Alumni
VIP Alumni

Best option would be to use the firewall itself to block certain IP's from connecting.  Ideally, you would have a "filtering" router at your Internet edge that blocks known bad IP's, RFC 1918 IP's, and your own internal subnet IP's (RFC 2827/BCP 38).  That prevents your firewall from having to process a lot of junk, which uses up resources.

If you cannot block on your edge router or firewall, then you could try to look for the "Framed-IP-Address" attribute in your authentication requests and use a Regex to match against your bad list.  But that is not ideal or efficient.

Marvin Rhoads
Hall of Fame
Hall of Fame

ISE is the wrong solution for that requirement. Ideally have an upstream NGFW/IPS with geoblocking. Or use MFA (like Duo) with geofencing requirements enforced on the MFA client.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: