10-19-2023 02:10 PM
Hi all
I have the following scenario FP managed by FMC and Cisco ISE, I am trying to configure the vpn ssl and that the authentication and authorization is provided by the ISE, this perfectly configured vpn using local users in the FMC I get connectivity and when I want to use now the ISE gives me a connectivity error, and from the FMC and FTD I have connectivity to the ISE without any problem, not even in the ISE I get to see the connection attempts.
I read in some forum that I must configure the diagnostic interface to be able to have communication with the ISE and the ip must be in the same network segment as the management interface.
I'm out of ideas and I'm almost sure it's a minor configuration issue that is failing me and I can't see it.
Solved! Go to Solution.
11-02-2023 08:40 AM
I apologize for the delay,PButButPPePePerBut dBut afterBut afterBut after dBut after mBut after manyBut after many years of But after a lot of back and forth with the client we discovered that there was a firewall in the middle that limited the communication, even though we had ping between the ISE and the FTD it did not allow the rest of the ports to communicate.
Thank you all for your comments.
10-20-2023 12:01 AM
@Ruben Lozada if ISE is not seeing any authentication attempts have you defined the FTD as a Network Device (with it's IP address and shared secret)? If you haven't ISE will silently drop the authentication attempts.
You do not need to configure the diagnostics interface, the RADIUS server (ISE) is reached via a data interface.
Example here of FTD Remote Access VPN with ISE authentication
10-20-2023 12:14 AM
Can i see how you config ISE from FMC ?
11-02-2023 08:40 AM
I apologize for the delay,PButButPPePePerBut dBut afterBut afterBut after dBut after mBut after manyBut after many years of But after a lot of back and forth with the client we discovered that there was a firewall in the middle that limited the communication, even though we had ping between the ISE and the FTD it did not allow the rest of the ports to communicate.
Thank you all for your comments.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide