<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ACS 5.x MAR Feature problem in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-5-x-mar-feature-problem/m-p/2096109#M183887</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Djordje-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;MAR only occurs when the machine first boots up. During boot time the machine sends its credentials to ACS and ACS retains them based on the MAR timer that you have set. Try rebooting the machine and see if that error message goes away. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Thanks you for rating!&lt;/EM&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 24 Dec 2012 23:22:59 GMT</pubDate>
    <dc:creator>nspasov</dc:creator>
    <dc:date>2012-12-24T23:22:59Z</dc:date>
    <item>
      <title>ACS 5.x MAR Feature problem</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-x-mar-feature-problem/m-p/2096108#M183879</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am testing MAR(Machine Access Restriction) feature upon client request. I got it working, when user that joins ACS to Active Directory is member of Domain Admin group.&lt;/P&gt;&lt;P&gt;Now, when In follow ACS config guide and set user rights to&amp;nbsp; "Add workstations to domain user right in corresponding domain"&lt;/P&gt;&lt;P&gt;MAR is not working.&lt;/P&gt;&lt;P&gt; In Radius log I see error:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;24423&amp;nbsp; ACS has not been able to confirm previous successful machine authentication for user in Active Directory&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has anyone tried this, and what level of user rights is needed for MAR to work in your implementation ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;Djordje Zecevic &lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 02:54:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-x-mar-feature-problem/m-p/2096108#M183879</guid>
      <dc:creator>Djordje Zecevic</dc:creator>
      <dc:date>2019-03-11T02:54:53Z</dc:date>
    </item>
    <item>
      <title>ACS 5.x MAR Feature problem</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-x-mar-feature-problem/m-p/2096109#M183887</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Djordje-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;MAR only occurs when the machine first boots up. During boot time the machine sends its credentials to ACS and ACS retains them based on the MAR timer that you have set. Try rebooting the machine and see if that error message goes away. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Thanks you for rating!&lt;/EM&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Dec 2012 23:22:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-x-mar-feature-problem/m-p/2096109#M183887</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2012-12-24T23:22:59Z</dc:date>
    </item>
    <item>
      <title>ACS 5.x MAR Feature problem</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-x-mar-feature-problem/m-p/2096110#M183897</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Neno,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You pointed me in right direction. Results that I describe earlier are MAR cache induced. I have working config:&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/3/2/1/125123-acs.PNG" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;Where first rule is match when computer is booting up(alternatively I could match AD computer group). When computer is boot rules puts him on restricted vlan 131 from where user can be authenticated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After user log on to computer, he is re-authenticated and assigned vlan 132 which is unrestricted.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Alternatively I could add default rule to put users in guest vlan.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Djordje&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Jan 2013 15:19:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-x-mar-feature-problem/m-p/2096110#M183897</guid>
      <dc:creator>Djordje Zecevic</dc:creator>
      <dc:date>2013-01-15T15:19:30Z</dc:date>
    </item>
    <item>
      <title>ACS 5.x MAR Feature problem</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-x-mar-feature-problem/m-p/2096111#M183915</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello &lt;SPAN style="font-size: 10pt;"&gt;Djordje&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am glad I was able to point you in the right direction! &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't know what your requirements are but if the rules that you described worked then great &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt; Also, you can combine both rules where MAR and domain user credentials are checked. If you end up doing this I would recommend that you set the MAR timer to at least 168 hours (one week) that way users don't have to reboot their computers through a working week. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;If your quesion is resolved please mark the thread as "answered"&lt;/EM&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Jan 2013 16:40:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-x-mar-feature-problem/m-p/2096111#M183915</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2013-01-15T16:40:13Z</dc:date>
    </item>
  </channel>
</rss>

