02-09-2022 01:11 PM
Hello,
Because OKTA returns only one radius attribute, I need to configure a Cisco VPN Anyconnect by:
- Authentication with an OKTA Radius server: allow to validate user credentials
- Authorization with an ISE server: allows to return several radius attributes (class, IP pool, ...)
Can you help me please?
Thank you
02-09-2022 01:20 PM
@cisco.13 you could send aaa to ISE. ISE can proxy authentication requests to okta. Once authentication is passed ise will authorise the session.
02-09-2022 01:42 PM
@Rob Ingram thank you for your reply,
can you share the procedure or screenshots of the ISE configuration please?
Thank you
02-22-2022 07:37 AM
Hello,
I succeeded to authenticate with okta and add the authorizations on ISE
question, how can I authorize only a specific group from okta?
Thank you
02-22-2022 12:51 PM
Hello,
I succeeded to authenticate with okta and add the authorizations on ISE
question, how can I authorize only a specific group from okta?
Thank you
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide