03-21-2018 12:22 AM
Hi All,
We are trying to authenticate a NAS in 2 level, first against LDAP/AD or internal user repository and second level against a token server. User should first login with LDAP/AD password, then NAS should ask for OTP.
How can we achieve this in ISE?
Thanks in Advance
Regards,
Vaibhav
Solved! Go to Solution.
05-31-2018 03:32 AM
No, this scenario is not supported.
03-21-2018 10:01 AM
03-27-2018 05:30 AM
05-30-2018 12:13 PM
I have a very similar requirement - instead of NAS, we are using an ASA for VPN access. (and our token server is Imprivata)
did you ever get this working?
05-31-2018 03:32 AM
No, this scenario is not supported.
05-31-2018 02:59 PM
moved to anyconnect team as well to see if they have further comments since its up to ASA and anyconnect to handle authentication piece
05-31-2018 04:34 PM
In my case, I have it working..
I have an External Identity store for AD, and setup a Radius Token server for my MFA server.
I created a "identity store sequence" and applied this in the Authentication (not the authorization) policy.
works like a champ!
08-28-2018 12:56 PM
How is it using the sequence to perform two levels of authentication as opposed to just passing it from AD?
08-29-2018 08:45 AM
08-29-2018 09:02 AM
That won't work for us, as our use case is not for VPN authentication, but rather for device admin (using Radius, not TACACS). ISE has to be the primary authenticator, but I will keep that in mind if we expand to trying to use MFA for VPN.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide