<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ACS 5.3 MAR Timeout with Windows XP in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-5-3-mar-timeout-with-windows-xp/m-p/2013235#M185134</link>
    <description>&lt;P&gt;&lt;SPAN style="font-family: Arial; font-size: 10pt;"&gt;All, here is my current setup:&amp;nbsp; Windows XP machines authenticating wireless using 802.1X to a Cisco ACS 5.3 that redirects the request to Microsoft Active Directory.&amp;nbsp; All the statements that I make below are what I have gathered from reading on forums, some of them might be incorrect.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Arial; font-size: 10pt;"&gt;In the ACS Under “External Identity Stores” and&amp;nbsp; “Active Directory”, there is a check box called “&lt;SPAN style="color: black;"&gt;Enable Machine Access Restrictions” if it is checked and&amp;nbsp; the Aging time is set to 8 hours and a Windows XP machine authenticates using&amp;nbsp; it’s Domain credentials it will gain access to the network but if that computer&amp;nbsp; is not rebooted after the 8 hours is up, Windows XP will not send it machine&amp;nbsp; credentials again, it will only send the user/pass of the user and will loose&amp;nbsp; access to the network.&amp;nbsp; The problem we have is that most of the users do not&amp;nbsp; shutdown their computers when they go home, they hibernate the computers thus&amp;nbsp; when they come back to the school the 8 hours aging time on the ACS has&amp;nbsp; expired.&amp;nbsp; The ACS expects to see the Windows XP machine send it’s domain&amp;nbsp; credentials again but from every forum I have read on, Windows XP will not send&amp;nbsp; it again until it get rebooted (FYI, Windows 7 will send the proper info, thus&amp;nbsp; they work just fine).&amp;nbsp; In the mean time I have changed the aging time to 8760&amp;nbsp; hours but this should only be temporary because it is a security risk to have&amp;nbsp; the aging time set so high.&amp;nbsp; Moving forward what are my options to make this&amp;nbsp; work properly?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: black; font-family: Arial; font-size: 10pt;"&gt; &lt;/SPAN&gt; &lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: black; font-family: Arial; font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: black; font-family: Arial; font-size: 10pt;"&gt;-Is there a way to fix&amp;nbsp; Windows XP?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: black; font-family: Arial; font-size: 10pt;"&gt;-Is there a recommendation on how to bypass this issue but still give us decent&amp;nbsp; security?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: black; font-family: Arial; font-size: 10pt;"&gt;-Is setting the aging time so high, a non security issue?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: black; font-family: Arial; font-size: 10pt;"&gt;-I guess worst case&amp;nbsp; scenario, the customer can try to educate all the students and staff to reboot&amp;nbsp; their machines every morning?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: black; font-family: Arial; font-size: 10pt;"&gt;Thoughts ideas?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: black; font-family: Arial; font-size: 10pt;"&gt;Thanks,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: black; font-family: Arial; font-size: 10pt;"&gt;CM&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: black; font-family: Arial; font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 02:31:36 GMT</pubDate>
    <dc:creator>chris.mccormick</dc:creator>
    <dc:date>2019-03-11T02:31:36Z</dc:date>
    <item>
      <title>ACS 5.3 MAR Timeout with Windows XP</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-3-mar-timeout-with-windows-xp/m-p/2013235#M185134</link>
      <description>&lt;P&gt;&lt;SPAN style="font-family: Arial; font-size: 10pt;"&gt;All, here is my current setup:&amp;nbsp; Windows XP machines authenticating wireless using 802.1X to a Cisco ACS 5.3 that redirects the request to Microsoft Active Directory.&amp;nbsp; All the statements that I make below are what I have gathered from reading on forums, some of them might be incorrect.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Arial; font-size: 10pt;"&gt;In the ACS Under “External Identity Stores” and&amp;nbsp; “Active Directory”, there is a check box called “&lt;SPAN style="color: black;"&gt;Enable Machine Access Restrictions” if it is checked and&amp;nbsp; the Aging time is set to 8 hours and a Windows XP machine authenticates using&amp;nbsp; it’s Domain credentials it will gain access to the network but if that computer&amp;nbsp; is not rebooted after the 8 hours is up, Windows XP will not send it machine&amp;nbsp; credentials again, it will only send the user/pass of the user and will loose&amp;nbsp; access to the network.&amp;nbsp; The problem we have is that most of the users do not&amp;nbsp; shutdown their computers when they go home, they hibernate the computers thus&amp;nbsp; when they come back to the school the 8 hours aging time on the ACS has&amp;nbsp; expired.&amp;nbsp; The ACS expects to see the Windows XP machine send it’s domain&amp;nbsp; credentials again but from every forum I have read on, Windows XP will not send&amp;nbsp; it again until it get rebooted (FYI, Windows 7 will send the proper info, thus&amp;nbsp; they work just fine).&amp;nbsp; In the mean time I have changed the aging time to 8760&amp;nbsp; hours but this should only be temporary because it is a security risk to have&amp;nbsp; the aging time set so high.&amp;nbsp; Moving forward what are my options to make this&amp;nbsp; work properly?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: black; font-family: Arial; font-size: 10pt;"&gt; &lt;/SPAN&gt; &lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: black; font-family: Arial; font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: black; font-family: Arial; font-size: 10pt;"&gt;-Is there a way to fix&amp;nbsp; Windows XP?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: black; font-family: Arial; font-size: 10pt;"&gt;-Is there a recommendation on how to bypass this issue but still give us decent&amp;nbsp; security?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: black; font-family: Arial; font-size: 10pt;"&gt;-Is setting the aging time so high, a non security issue?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: black; font-family: Arial; font-size: 10pt;"&gt;-I guess worst case&amp;nbsp; scenario, the customer can try to educate all the students and staff to reboot&amp;nbsp; their machines every morning?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: black; font-family: Arial; font-size: 10pt;"&gt;Thoughts ideas?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: black; font-family: Arial; font-size: 10pt;"&gt;Thanks,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: black; font-family: Arial; font-size: 10pt;"&gt;CM&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: black; font-family: Arial; font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 02:31:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-3-mar-timeout-with-windows-xp/m-p/2013235#M185134</guid>
      <dc:creator>chris.mccormick</dc:creator>
      <dc:date>2019-03-11T02:31:36Z</dc:date>
    </item>
    <item>
      <title>ACS 5.3 MAR Timeout with Windows XP</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-3-mar-timeout-with-windows-xp/m-p/2013236#M185135</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Chris,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hi your issue seems to be one that is common when enforcing MAR on XP clients. The best solution for you is to use anyconnect NAM as your supplicant. It is free and unlicensed if you have Cisco product tied to you ccoid. Which in this case will be ACS. You can use the NAM profile editor to set the authenticating network for (peap or tls) and choose it to perform computer and machine authentication. From my experience working with NAM is that it will send the computer authenticate and user authentication information over when associating to the SSID.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also there is a new feature in Anyconnect NAM called Eap-chaining, you can set the order on if you prefer computer authentication followed by user authentication, this is however supported by ISE 1.1.1 (MR), however ACS is due for a version update soon and I have a feeling that this may also be a feature added to the ACS line, but I can't confirm for sure.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Sep 2012 22:45:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-3-mar-timeout-with-windows-xp/m-p/2013236#M185135</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-09-10T22:45:29Z</dc:date>
    </item>
    <item>
      <title>ACS 5.3 MAR Timeout with Windows XP</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-3-mar-timeout-with-windows-xp/m-p/2013237#M185137</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you Tarik, I am working with my customer next week to test the anyconnect NAM, once I get the results I will reply back..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CM&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Sep 2012 20:44:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-3-mar-timeout-with-windows-xp/m-p/2013237#M185137</guid>
      <dc:creator>chris.mccormick</dc:creator>
      <dc:date>2012-09-12T20:44:45Z</dc:date>
    </item>
    <item>
      <title>ACS 5.3 MAR Timeout with Windows XP</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-3-mar-timeout-with-windows-xp/m-p/2013238#M185140</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;﻿Chris,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have the exact same problem on my network. I use AnyConnect on my XP computer but still the problem remains.&lt;/P&gt;&lt;P&gt;Did you find a solution to this problem?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Simon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Oct 2012 08:44:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-3-mar-timeout-with-windows-xp/m-p/2013238#M185140</guid>
      <dc:creator>vincentbelliard</dc:creator>
      <dc:date>2012-10-25T08:44:10Z</dc:date>
    </item>
    <item>
      <title>ACS 5.3 MAR Timeout with Windows XP</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-3-mar-timeout-with-windows-xp/m-p/2013239#M185142</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Simon, I was able to get the XP computer working by setting up a profile to authenticte "Machine Auth" only, when I tried to authenticate both machine and user it fails.&amp;nbsp; At this point I am sticking with machine only.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CM&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Oct 2012 14:17:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-3-mar-timeout-with-windows-xp/m-p/2013239#M185142</guid>
      <dc:creator>chris.mccormick</dc:creator>
      <dc:date>2012-10-25T14:17:46Z</dc:date>
    </item>
  </channel>
</rss>

