12-28-2022 05:10 AM
Hey guys,
I'm trying to find a way to authenticate users coming from Cisco ASA with certificate and DUO from ISE.
The idea is to follow the steps bellow :
Is it possible to implement this ?
Also is it possible to do only one Radius request by using EAP-TEAP for the step 2 and 3.
I found this community subject :
Solved: VPN certificate auth using ISE? - Cisco Community
But it has been posted 5 years ago so is it outdated ?
Thank for your help !
Solved! Go to Solution.
12-28-2022 05:22 AM
@Djuxt certificate authentication is between the anyconnect client and the ASA, not ISE.
You could send the Duo authentication via ISE which proxies the request to the Duo authentication proxy, once authenticated via Duo ISE can then authorise the user.
TEAP is used for 802.1X authentication (wired/wireless) not VPN.
12-28-2022 05:22 AM
@Djuxt certificate authentication is between the anyconnect client and the ASA, not ISE.
You could send the Duo authentication via ISE which proxies the request to the Duo authentication proxy, once authenticated via Duo ISE can then authorise the user.
TEAP is used for 802.1X authentication (wired/wireless) not VPN.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide