Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
Hi all,
I have an issue on FMC caused by migration from on-prem MS AD to Azure AD. The problem is with RA VPN access policies using user-based restrictions.
Previously, users authenticated with their on-prem MS AD credentials and gained access to all...
I have two C9800-L-F controllers working in standalone configuration. They are both connected to ISE with their WMI addresses, 192.168.168.40 for the first and 192.168.168.43 for the second.I intend to implement HA SSO (RMI + RP) for these devices, a...
Hi piotr.smietanka,
I opened a TAC case, and after a long analysis by the Cisco engineer, I was pointed to this answer:"You can enforce an access policy on a SAML-authenticated user if you have an associated identity policy with an AD realm matching ...
Hi ahollifield,
Thank you for your answer.In the Remote Access VPN Overview Dashboard in FMC, under active sessions, users are listed with their username, not with the UPN.Can you please clarify which user's UPN should match—that from SAML with the o...
I get an error when I try to add a secondary IP address for a device in ISE. ("Failed to create network device - trustSec.sgaCoaSupportType : CoA cannot be enabled for more than one device.")So I created one NAD with the WMI address and two more with...
Thank you for the prompt answer.Just to be clear, should I have only one NAD in ISE with the WMI address which will serve both controllers?Are the other two NADs with RMI addresses mandatory or optional?Is it possible to have two objects (NADs) with ...