Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

Cisco Employee

Calling station ID attribute needs MAC address for Anyconnect VPN client

Hi All,

We are testing Anyconnect VPN users tring to connect using certificate. ASA is validating/ authenticating user based on cert and for authorization it is requesting Radius server(ISE). Currently ASA  is sending Ip address of VPN client in "calling station ID" .We want ASA to send MAC address of Anyconnect VPN client to radius server in 'calling station ID' radius attribute.  Is it possible to achieve this. Any workround ?

Everyone's tags (4)
1 ACCEPTED SOLUTION

Accepted Solutions
Silver

Calling station ID attribute needs MAC address for Anyconnect

Hi Parag,

The Calling Station ID will always contain IP Address in case of Anyconnect VPN.

L3 being the cause unlike Wireless which has L2 Assoc.

Currently no workaround.

Regard

Ed

**Share your knowledge. It’s a way to achieve immortality. --Dalai Lama** Please Rate if helpful. Regards Ed
2 REPLIES
Silver

Calling station ID attribute needs MAC address for Anyconnect

Hi Parag,

The Calling Station ID will always contain IP Address in case of Anyconnect VPN.

L3 being the cause unlike Wireless which has L2 Assoc.

Currently no workaround.

Regard

Ed

**Share your knowledge. It’s a way to achieve immortality. --Dalai Lama** Please Rate if helpful. Regards Ed
Cisco Employee

Calling station ID attribute needs MAC address for Anyconnect

Thanks Edward

868
Views
5
Helpful
2
Replies
CreatePlease login to create content