Forum Discussion
Integration with CISCO_ISE_APM
Hi Team,
We utilized F5_APM for SSL_VPN, which is integrated with CISCO_ISE.
Query 1.
1.1 User-Database is managed by ISE, whether its Local or AD and its passed to F5 using Class Attributes, but F5 is failing to fetch any Dynamic ACL's created jn ISE, is there any suggestion , basically we wanted to put some Access-List based restrictions ?
1.2 Whenever we enable Password Change option at next Login' in Cisco ISE, F5 don't understand this and the authentication fail ?
- If point 1 is not possible, as an alternative we created Access-List in F5_APM under Access Module,but is there no option to call any Group(where we can combine the destinations ?)
For example by using Data-Groups and somehow reference that in APM SSL-VPN Policy/Profile/VIP?
Regards PZ
1.1 - this looks to be possible, see: https://support.f5.com/kb/en-us/products/big-ip_apm/manuals/product/apm-implementations-11-5-0/2.html
1.2 - the product* before APM didn't support this, can't find anything about APM. i would raise this with your local sales team or F5 support to double check.
*) https://support.f5.com/csp/article/K8525
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com