cancel
Showing results forĀ 
Search instead forĀ 
Did you mean:Ā 
cancel
554
Views
0
Helpful
6
Replies

ISE with FMC issue

Hello all , 

I have Cisco ISE and the integration between the ISE and the active directory is done.

The user  when he access the SW, routers, Palo Alto and F5 gets authentication from ISE by TACACS , but with FMC not working 

NOTE:

1- Using the radius between the ISE and FMC 

2: When adding a local user at the ISE, I can open the FMC, but any user from active directory can't it 

 

6 Replies 6

balaji.bandi
Hall of Fame
Hall of Fame

We already configured the radius between the FMC and ISE .but the main issue now ""When adding a local user at the ISE, I can open the FMC, but any user from active directory can't open the FMC ""

@Abdelrahman salah not sure what you've configured, so an educated guess.....you need to create the ISE RADIUS Policy Sets to authenticate against AD and authorise the users to an AD group, then return the RADIUS attributes that determines the administration level. FMC external administration, example: https://bluenetsec.com/fmc-external-authentication-with-radius/

After adding ISE, have you enabled ? by default its disabled in FMC

check this video :

https://www.youtube.com/watch?v=GRtsjrNavVs

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Hi balaji

we already Added this Configuration but still not working I think this problem is due to using a username like this: INTERNL\ALEX

kindly check the error 

Test Username : adel@internal.XXXXXX.com
ISE NODE : ISE1.internal.XXXXXXX.com
Scope : Default_Scope
Instance : ISE

Authentication Result : FAILED

Error : Identity not found; some of the domains were not available


Processing Steps:
14:57:49:713: Resolving identity - adel@internal.XXXXX.com
14:57:49:713: Search for matching accounts at join point - internal.XXXXX.com
14:57:49:715: DNS server returned error - internal.XXXXX.com,ERROR_DNS_ERROR_DOMAIN_NOT_FOUND
14:57:49:715: LDAP search in forest failed - internal.XXXXXX.com,ERROR_DOMAIN_IS_OFFLINE
14:57:49:715: Identity resolution detected no matching account
14:57:49:715: Identity resolution failed - ERROR_NO_SUCH_USER_SOME_DOMAINS_NOT_AVAILABLE

Review Cisco Networking for a $25 gift card