cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1929
Views
0
Helpful
5
Replies

Validating AnyConnect Identity Extensions (ACIDex) attributes against external DB

rmueller@cisco.com
Cisco Employee
Cisco Employee

Hi all,

does someone know if it is possible to validate AnyConnect Identity Extensions (like device ID) against an external DB? I know it's possible by using ASA DAP, but customer would like to do it centrally on ISE. Could not find a way (tried to do it with authorization rules).

Thanks in advance.

Roland

1 Accepted Solution

Accepted Solutions

hslai
Cisco Employee
Cisco Employee

ACIDEX attributes are mainly for profiling at present. Please present your use case to our product management team.

View solution in original post

5 Replies 5

Jason Kunst
Cisco Employee
Cisco Employee

Having our experts pcarco chime in as well

hslai
Cisco Employee
Cisco Employee

ACIDEX attributes are mainly for profiling at present. Please present your use case to our product management team.

The use case here is to validate if the device which is connecing via VPN actually a company-owned device. To check that, they would like to validate the device id which AnyConnect is sending to ISE against Database (LDAP/AD probably). The operating system in question here is MacBook. In most cases, you would do that by checking a certificate during authentication, but the customer in question here is not allowed to install certificates on MacBooks as they fear that the certificate can get compromised.

I know that this can be currently done via DAPs and LUA-scripts on ASA, but customer prefers ISE to do this job centrally for all VPN gateways.

Roland

please reach out to ISE-PM mailer for the use case as they handle the requests

Craig Hyps
Level 10
Level 10

This thread may also help on similar query: Machine + User Auth for MAC OSX