Thanks Arne for answering. It is exactly where I'm stuck - Okta Radius is hard coded to provide group membership via Filter-Id (11) but ISE doesn't really like it. I have a potential backup plan to differentiate authorisation by AD group membership l...
Hi Craig, This is a few years old post but still something I'm battling right now with ISE 2.7.I'm not sure if I understand.Are your confirming Arne's finding, that attribute received from Radius Token server must be cisco-av-pair=ACS:... Or are you ...
This looks interesting Georg and could work. However, the ultimate goal for Alex is to pass public IP to the downstream Meraki MX, WAN1 interface. In that case how to bridge that ATM interface with Gig0/2/0 (where MX is connected) using BDI? I was t...
Have you established any comms with that person? Anything you could share? I'm not necessarily looking for a complete solution, but some guidance could be a good start.