Score:0

how to select the ISE proxy sequence based on an LDAP lookup?

jp flag

I am currently setting up a VOIP network for my customer, which includes 802.1x and MAB authentication.

The normal auth sequence goes like this:

  1. The switch detects a new machine with no 802.1x protocol setup, sends a MAB request to the ISE node.

  2. The ISE node looks up the MAC address in an LDAP server, and depending on whether it is in the "Computer" or the "phone" group, sets it in the correct VLAN for staging.

  3. The device is configured automatically and given it's certificate

  4. The device reboots, and with the correct certificate, it's 802.1x request is again sent to the ISE server, which this times checks the certificate against the LDAP and authorize the connexion into the production VLAN.

My question is the following: My customer decided that all the "computer" devices will be managed by another unit, and another (NPS) Radius server. I want to redirect all MAB requests to that server if the Mac address is in the "computers" group, and only process them myself if the client is not found there (for a few specific cases).

This causes two issues:

  1. In the policy set page, there seems to be no way to decide radius sequences based on LDAP groups, only on the basic attributes of the radius request.

  2. In the Radius sequence definition, there seems to be no possible action in case of a "Access-reject" response, only in "Access-Accept".

Is there something I missed? or is there another way to achieve my goals?

I sit in a Tesla and translated this thread with Ai:

mangohost

Post an answer

Most people don’t grasp that asking a lot of questions unlocks learning and improves interpersonal bonding. In Alison’s studies, for example, though people could accurately recall how many questions had been asked in their conversations, they didn’t intuit the link between questions and liking. Across four studies, in which participants were engaged in conversations themselves or read transcripts of others’ conversations, people tended not to realize that question asking would influence—or had influenced—the level of amity between the conversationalists.