09-27-2023
08:16 AM
- last edited on
09-27-2023
08:35 AM
by
rupeshah
Is it possible to have both network access control on our vlans and a two factor authentication in place (ex. Cisco DUO) at windows logon?
So we want to have users logon to their windows machine and at that point in time they are thrown in an isolated vlan with access only to DUO servers so they can approve Cisco DUO's 2FA challenge on their phone and complete authentication, and then ISE redirects them to whichever vlan they have access to. Is this even possible?
09-27-2023 08:47 AM
this is possible - is this for wired or wireless clients.
10-02-2023 07:58 AM - edited 10-02-2023 08:02 AM
So this question was copied from a post that I posted on Reddit:
(7) Is Cisco ISE NAC and 2FA at Windows Logon possible? : Cisco (reddit.com)
To reply to your question: If possible we wish to apply this to both wired and wireless. To recap - we want to have 2FA at windows logon and then have NAC applied once the user authenticates. We have also moved away from Windows Hello for Business rightly because it stores biometric data locally on the TPM, hence it will never pass the auth details to Cisco ISE. We're trying DUO now, at Windows logon, however, since the user would not have obviously authenticated yet, they would not have any access to the DUO servers on the internet, and they will be prompted with an offline code on every startup. Is there anyway around this? Maybe set the user on an isolated VLAN at logon, with access only to DUO servers..so far we have not managed to find the right solution to what we have in mind.
10-02-2023 08:23 AM - edited 10-02-2023 08:24 AM
When doing this you will just need to put a pre-auth-ACL in place allowing access to the Duo servers. It will need to include the Duo IPs (https://help.duo.com/s/article/1337?language=en_US) in addition to allowing DCHP and DNS.
More info here: https://community.cisco.com/t5/security-knowledge-base/ise-secure-wired-access-prescriptive-deployment-guide/ta-p/3641515#toc-hId-1594628171
Add the Duo servers' public IPs to the ACL in that example and name it according to the usage.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide