This articles applies to organizations using Cisco ISE. Identity Services Engine (ISE) is a network administration product that enables the creation and enforcement of security and access policies for endpoint devices connected to the company's routers and switches. The purpose is to simplify identity management across diverse devices and applications.
Because an ISE solution relies on the RADIUS protocol we can configure the SonicWall to act as a RADIUS accounting proxy. This provides a convenient integration for existing ISE solutions. For example, if we have two wireless controllers we can send the RADIUS authentication packets directly to the ISE solution and send the RADIUS accounting packets to a SonicWall firewall to proxy to the ISE solution. This will allow the firewall to use user based roles and policies to enforce traffic while providing seamless reporting from the ISE.
The new RADIUS packet flow will look like:
Stated anotherway:
In the following example we will setup RADIUS proxy on a SonicWall firewall using 6.5 firmware:
Please perform the following:
The above example handles Windows wireless (you can NOT send the domain portion when a machine has been joined to the domain). We can then add the following to support non-domain clients while configuring each client. This feature is located under the RADIUS tab:
After performing these steps, the firewall will successfully track user information (to be used for network enforcement) while also providing seamless integration with the ISE solution.