This document describes configuring RADIUS External Authentication between Cisco Secure Email Gateway and Cisco Identity Services Engine.
Cisco recommends that you have knowledge of these topics:
The information in this document is based on these software and hardware versions:
The information in this document was created from the devices in a specific lab environment. All of the devices used in this document started with a cleared (default) configuration. If your network is live, ensure that you understand the potential impact of any command.
Versions outside those listed in the Components Used section were not tested.
RADIUS Class Attribute
The Class attribute is an arbitrary value that the RADIUS server returns in the Access-Accept response and includes in accounting packets. It is configured in Cisco ISE on a per-group basis.
When a user matches an ISE group that has Attribute 25 tied to it, ISE returns the Class value on Access-Accept. The Secure Email Gateway then reads that value and applies the local role defined in its mapping table.
Note: In the ISE Authorization Profile, the ASA VPN common task is used as the container that populates RADIUS Attribute 25 (Class). The value entered there is what the appliance reads for role mapping.

Cisco Identity Services Engine accepts authentication requests from the appliance and matches them against a user identity and group.
Log in to the ISE server. Navigate to Administration > Identity Management > Groups > User Identity Group and create an identity group.

Create new users, or assign existing users, to the identity group created in Step 1. Navigate to Administration > Identity Management > Identities and create or assign users to the group.

RADIUS authentication can succeed without an authorization profile; however, no roles are assigned. To assign roles, navigate to Policy > Policy Elements > Results > Authorization > Authorization Profiles.

This step lets ISE identify log in attempts and map them to the correct authorization profile. On a successful match, ISE returns Access-Accept along with the Class value defined in the profile.
Navigate to Policy > Policy Sets and select Add (+ symbol).

Assign a name and select the plus symbol to add the required conditions. This lab environment uses a Radius NAS-IP-Address condition. Save the new policy.

To match the authorization requests correctly, add the conditions. Select the symbol > and add conditions. This lab environment uses InternalUser-IdentityGroup and matches each authorization profile.

Log in to the appliance. Navigate to System Administration > Users > External Authentication and select Enable External Authentication.

Enter these values:
Select Map externally authenticated users to multiple local roles (recommended).

Note: The Authentication Protocol selected here (for example, PAP) must match the allowed protocols in the ISE Policy Set. A mismatch causes authentication to fail.
Submit and commit the changes.
Use this section to confirm your configuration works properly.

This section provides the information you can use to troubleshoot your configuration.
Symptom: Login fails on the appliance with the message "Invalid username or password".
Likely cause: A mismatch in the authorization policy, the returned Class value, or the authentication protocol.
Resolution:

| Revision | Publish Date | Comments |
|---|---|---|
2.0 |
21-Jul-2026
|
Updated Machine Translation, SEO, Alt Text, Style Requirements, and Formatting. |
1.0 |
26-May-2021
|
Initial Release |