cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2219
Views
10
Helpful
2
Replies

WSA read only access with ISE

harishbau084
Level 1
Level 1

how to enable WSA read only access with ISE, which VSA can be used for it ?

2 Accepted Solutions

Accepted Solutions

@harishbau084 

 

Create different AuthZ rules in ISE, send a different/unique class attribute value per group (RO or admin), then on the WSA map the value sent from ISE to a WSA group, in your scenario "Read-Only Operators".

 

https://www.cisco.com/c/en/us/td/docs/security/wsa/wsa11-0/user_guide/b_WSA_UserGuide/b_WSA_UserGuide_chapter_011000.html#con_1378352

 

 

View solution in original post

2 Replies 2

@harishbau084 

 

Create different AuthZ rules in ISE, send a different/unique class attribute value per group (RO or admin), then on the WSA map the value sent from ISE to a WSA group, in your scenario "Read-Only Operators".

 

https://www.cisco.com/c/en/us/td/docs/security/wsa/wsa11-0/user_guide/b_WSA_UserGuide/b_WSA_UserGuide_chapter_011000.html#con_1378352