Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
Hi,
is there a way to change ASA NAS-IP address (RADIUS attribute 4) when ASA talks to ISE (in general to any RADIUS server). I know there is a way for routers or switches. I need this functionality on ASA as my ASA (actually few of them) are nated (...
I think reauthentication for MAB is very useful in few scenarios. Let assume we have printers allowed via MAB and we assigned to them dACL. With reauthentication set for 16 hours, when we change ACL on ISE then we have 100% guarantee new ACL will be...
@MHM Cisco World wrote:
ciscoasa(config)# aaa-server mygroup (inside) host 192.168.10.10 thekey timeout 20
this Interface IP is use for both source and NAS-IP as I know.
Yes, that is correct. Additionally you will need a route through "inside" int...
Hi Greg,
I believe ISE guys are more experienced with messing up with NAS-IP as potentially they are using this attribute in Rules.
@Greg Gibbs wrote:
This is more of a question about the ASA then it is about ISE, so it's probably a question better ...
Hi MHM,
In general that is correct what you are saying and I thought about that but I'm not able to change SRC IP address of RADIUS packet. It needs to be exactly as is and I'm not allowed to change it (routing, NAT, VPN, and so on....).
I'm looking ...