cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
49425
Views
15
Helpful
34
Comments
Richard Lucht
Level 1
Level 1

Using Microsoft Azure MFA for multifactor authentication within Cisco ISE.

Comments
Ricky Sandhu
Level 3
Level 3

@DannyDulin

As part of the Authorization profile, do you use a dACL or another option? 

Sorry for all these questions.  I've had a lot of issues with pushing dACLs as part of the Authorization policy from ISE to the VPN session on the ASA.  Everything works, until it doesn't. We have hundereds of daily users connecting to various VPN gateways (ASA) all over and when I enable Authorization from ISE, it causes few of them to experience an "internal error" on their Cisco Secure Client.  Even the highest echelons of TAC have been unable to help resolve this issue successfully.  

DannyDulin
Level 1
Level 1

I am not using dACL with these afore mentioned AuthZ profiles, but I have used dACL in another scenario with VPN.

I encountered a problem and it turned out to be too many characters in the dACL. SERIOUSLY!

  • The whole dACL can not exceed 4000 characters as it has to fit into one RADIUS packet.
  • up to 64 lines in a single dACL 

DACLs in ISE - Cisco Community

I know this to be accurate because I tested the theory.

BTW...ask as many questions as you need. We're all in this together.

Ricky Sandhu
Level 3
Level 3

@DannyDulin

What's rather strange is that the dACL I am sending is simply permit ip any any and even then the issue occurs.

Are you also using hostscan?  We are using hostscan and as per TAC hostscan and CoA don't work together due to a bug.

**Message from TAC:  Also I would like to point out to this bug that has been found where it is indicated that hostscan and CoA don’t work together which can be our scenario. https://bst.cisco.com/bugsearch/bug/CSCuu55785

**

TAC's solution for us was to stop sending AuthZ profile with a dACL to the ASA, which is what we did but obviously this is pointless.

DannyDulin
Level 1
Level 1

We are not using hostscan. 

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: