Hi,
I have the following setup. Cisco ASA 5520, Cisco ISE 1.2 and Active directory.
The goal here is to hand out the static IP address defined in dial-in tab in AD to users connecting via Cisco IPSec VPN client to ASA.
Cisco ISE is connected to ASA and ISE is downloading the user specific data from AD. I am able to log in based on the group membership in AD, I get the IP address, but this IP is from the pool configured on ASA. I can verify that ISE sees the attribute msRASSavedFramedIPAddress in Attribute tab of External identity sources. So the question is: how to modify "something" in order to get the static IP defined in AD?
Thank you