Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

Porting ACS 4.2 rules to ISE

I'm trying to move AAA services from an ACS 4.2 integrated to AD to an ISE3355 supporting remote access VPN on an ASA/AnyConnect and wireless (PEAP). The ISE3355 is AD integrated.

With respect to Remote Access VPN using AAA on the ACS, I currently map various AD groups to ACS groups, and use the RADIUS IETF Class [025] attribute for the ACS group that associates an ACL name hardcoded in the ASA configuration to enforce the access policy.

Is this a valid approach to porting policies from the ACS to the ISE?

Or alternatively, must I define the ACLs on the ISE instead of using those already defined in the ASA configuration?

I need to do a quick port, so any suggestions are appreciated.

Everyone's tags (1)
2 REPLIES
Cisco Employee

Check the following linkhttp:

Check the following link

http://www.cisco.com/c/en/us/support/docs/security/adaptive-security-appliance-asa-software/117693-configure-ASA-00.html

New Member

Thanks for your response

Thanks for your response Vattullu. My local Cisco account security-focused SE pointed me to this youtube video:

http://www.youtube.com/watch?v=HcMf3q_lmYo

This addressed the issue of authorization issue exactly the way I needed it.

35
Views
0
Helpful
2
Replies