<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE SCEP connection to Win2003 server unsuccessful in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-scep-connection-to-win2003-server-unsuccessful/m-p/2039706#M158670</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try using http (you are using https) and see if this works for you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 13 Sep 2012 14:02:18 GMT</pubDate>
    <dc:creator>Tarik Admani</dc:creator>
    <dc:date>2012-09-13T14:02:18Z</dc:date>
    <item>
      <title>ISE SCEP connection to Win2003 server unsuccessful</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-scep-connection-to-win2003-server-unsuccessful/m-p/2039705#M158667</link>
      <description>&lt;P&gt;&lt;SPAN&gt;I'm trying to get SCEP enrollment for BYOD on-boarding to work with a Win2k3 server, so far it keeps failing. On the ISE (1.1.1), when I enter the path to the SCEP server ('&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://" target="_blank"&gt;https://&lt;/A&gt;&lt;SPAN&gt;&amp;lt;W2k3_srv_name&amp;gt;/certsrv/mscep/mscep.dll') the connectivity test fails when hitting the "Test Connectivity" button; the error message is "Connection to SCEP server failed. Remotely Closed [id: 0x00313434]". Strangely, the settings can be saved and ISE won't complain, although the ISE user guide says that the ISE will check the connectivity anyway when saving the settings.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the end, the on-boarding process doesn't work and stops at the stage where the cert enrollment should take place (on various platforms).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;See the Win2k3 event log error attached.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas or experiences?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Toni&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 02:32:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-scep-connection-to-win2003-server-unsuccessful/m-p/2039705#M158667</guid>
      <dc:creator>tgrundbacher</dc:creator>
      <dc:date>2019-03-11T02:32:54Z</dc:date>
    </item>
    <item>
      <title>Re: ISE SCEP connection to Win2003 server unsuccessful</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-scep-connection-to-win2003-server-unsuccessful/m-p/2039706#M158670</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try using http (you are using https) and see if this works for you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Sep 2012 14:02:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-scep-connection-to-win2003-server-unsuccessful/m-p/2039706#M158670</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-09-13T14:02:18Z</dc:date>
    </item>
    <item>
      <title>Re: ISE SCEP connection to Win2003 server unsuccessful</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-scep-connection-to-win2003-server-unsuccessful/m-p/2039707#M158674</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Tarik&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your support - we've also tried with HTTP, yet without success. Meanwhile we've set up a 2008 server with SCEP running on it, with this one it seems to work fine now. I deliberately say *seems to work*, since I still can't get the on-borading process to finish successfully (see attached picture). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It works if you use an internal client on the LAN and request a cert directly from the SCEP server via IE. But for the BYOD devices, no cretificates are being rolled out, and no error or logs neither on ISE, nor on the SCEP server nor on the client indicate what's going wrong. I can't open a TAC case since this is a PoC with an Eval license and the customer will only buy the Advanced license if they like what they see... &lt;SPAN __jive_emoticon_name="sad" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/sad.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Oct 2012 11:54:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-scep-connection-to-win2003-server-unsuccessful/m-p/2039707#M158674</guid>
      <dc:creator>tgrundbacher</dc:creator>
      <dc:date>2012-10-08T11:54:57Z</dc:date>
    </item>
    <item>
      <title>Re: ISE SCEP connection to Win2003 server unsuccessful</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-scep-connection-to-win2003-server-unsuccessful/m-p/2039708#M158679</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Did you tell the SCEP server what template to use for network devices?&amp;nbsp; Also could you post up your policies?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Oct 2012 12:42:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-scep-connection-to-win2003-server-unsuccessful/m-p/2039708#M158679</guid>
      <dc:creator>chris_day</dc:creator>
      <dc:date>2012-10-08T12:42:28Z</dc:date>
    </item>
    <item>
      <title>Re: ISE SCEP connection to Win2003 server unsuccessful</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-scep-connection-to-win2003-server-unsuccessful/m-p/2039709#M158699</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Chris, please find some screenshots of the cert template and the ISE policies in the attachment. Meanwhile we could prove that the ISE doesn't send a single packet towards the SCEP server during the on-borarding process. We can see a packet arriving when we test the SCEP connection from the ISE to the server.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Oct 2012 15:25:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-scep-connection-to-win2003-server-unsuccessful/m-p/2039709#M158699</guid>
      <dc:creator>tgrundbacher</dc:creator>
      <dc:date>2012-10-08T15:25:46Z</dc:date>
    </item>
  </channel>
</rss>

