<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: EAP-TLS machine authorization using ACS 5.2 in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/eap-tls-machine-authorization-using-acs-5-2/m-p/1643203#M249374</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Hi Anita,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;I'm assuming that you only want to do machine authentication against one specific group on the AD.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;If that is the case then you need to use two customize attributes in the access-policy.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;1.] AD1: External Groups : Domain Computers&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;2.] System Username starts from : host/&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;The above two attributes can be added by going to Access-policy &amp;gt;&amp;gt; authorization &amp;gt;&amp;gt; bottom right corner &amp;gt;&amp;gt; customize &amp;gt;&amp;gt; mode both the attributes on the right side and click submit.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;After that enter the above suggested values.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Before you perform above task, please ensure we have fine connection with AD, I mean when you fetch the directory groups from the AD section it should work.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Please feel free to contact me for further queries.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Rgds, Jatin&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Do rate helpful posts-&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 10 Mar 2011 04:15:46 GMT</pubDate>
    <dc:creator>Jatin Katyal</dc:creator>
    <dc:date>2011-03-10T04:15:46Z</dc:date>
    <item>
      <title>EAP-TLS machine authorization using ACS 5.2</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-tls-machine-authorization-using-acs-5-2/m-p/1643202#M249365</link>
      <description>&lt;P&gt;Dear all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have been struggling with this for a couple of days now and I think there must be something I'm not quite understanding.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are trying to deploy a new Wifi infrastructure using windows wireless clients, Motorola APs (with RFS switches) and using a Cisco ACS 5.2 appliance as our Radius server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In trying to get EAP-TLS to work, I can get clients to connect if no real authorization is used, but when I try to validate if the machine name in the client certificate belongs to a particular AD group, the authorization fails.&amp;nbsp; I don't see how to get the ACS to use the Radius "Username" it receives through the certificate to authorize the machine.&amp;nbsp; The value in the Radius username attribute is the name of the machine.&amp;nbsp; I would like the ACS to check to see if this machine name belongs to a particular group in the Windows AD.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We started with PEAP-MSCHAPv2, but security wanted machine authorization&amp;nbsp; so we thought EAP-TLS was the only way to get this.&amp;nbsp; Now I'm no longer&amp;nbsp; sure.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would love it if someone can guide me in getting the ACS to validate if the machine belongs to a certian Group in the Active Directory using either&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) EAP-TLS&lt;/P&gt;&lt;P&gt;2) PEAP-MSCHAPv2&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 00:53:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-tls-machine-authorization-using-acs-5-2/m-p/1643202#M249365</guid>
      <dc:creator>bhatatrans</dc:creator>
      <dc:date>2019-03-11T00:53:49Z</dc:date>
    </item>
    <item>
      <title>Re: EAP-TLS machine authorization using ACS 5.2</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-tls-machine-authorization-using-acs-5-2/m-p/1643203#M249374</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Hi Anita,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;I'm assuming that you only want to do machine authentication against one specific group on the AD.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;If that is the case then you need to use two customize attributes in the access-policy.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;1.] AD1: External Groups : Domain Computers&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;2.] System Username starts from : host/&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;The above two attributes can be added by going to Access-policy &amp;gt;&amp;gt; authorization &amp;gt;&amp;gt; bottom right corner &amp;gt;&amp;gt; customize &amp;gt;&amp;gt; mode both the attributes on the right side and click submit.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;After that enter the above suggested values.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Before you perform above task, please ensure we have fine connection with AD, I mean when you fetch the directory groups from the AD section it should work.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Please feel free to contact me for further queries.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Rgds, Jatin&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Do rate helpful posts-&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Mar 2011 04:15:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-tls-machine-authorization-using-acs-5-2/m-p/1643203#M249374</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2011-03-10T04:15:46Z</dc:date>
    </item>
    <item>
      <title>Re: EAP-TLS machine authorization using ACS 5.2</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-tls-machine-authorization-using-acs-5-2/m-p/1643204#M249379</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the fast response.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I already had the AD1 external groups configured, but I was trying to figure out how to do 2).&amp;nbsp; Unfortunately, it is still not working.&amp;nbsp; I cannot get the ACS to properly query the AD with the proper information.&amp;nbsp; When I look at the ACS logs, I do not see the AD groups that belong to the particular computer in the Authentication details &amp;gt; Other Details section so I don't think the query is functionning correctly.&amp;nbsp; I will try to further debug this using the CLI.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;By any chance do you know if we can perform both machine AND user authentication using PEAP-MSCHAPv2 with the ACS?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Mar 2011 21:26:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-tls-machine-authorization-using-acs-5-2/m-p/1643204#M249379</guid>
      <dc:creator>bhatatrans</dc:creator>
      <dc:date>2011-03-10T21:26:34Z</dc:date>
    </item>
    <item>
      <title>Re: EAP-TLS machine authorization using ACS 5.2</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-tls-machine-authorization-using-acs-5-2/m-p/1643205#M249382</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #800000; font-size: 10pt;"&gt;Hi Anita,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000; font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000; font-size: 10pt;"&gt;Yes, that can be done very easily.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000; font-size: 10pt;"&gt;&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; You will need to have only one authorization rules created. Where we should have n attribute selected "was machine authenticated" equals to TRUE then assign authorization policy : permit ( whatever we have created)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000; font-size: 10pt;"&gt;This feature will ensure that the user machine has been authenticated before the user is authenticated.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000; font-size: 10pt;"&gt;Apart from that you should have "Machine authentication and MAR" enabled under the AD settings.&lt;BR /&gt;Users and Identity Stores &amp;gt;&amp;nbsp; ... &amp;gt;&amp;nbsp; External Identity Stores &amp;gt;&amp;nbsp; Active Directory &amp;gt;General Tab.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000; font-size: 10pt;"&gt;Once you are done then you've to reboot the host/machine to get this checked. You can check the machine authentication attempt and user authentication attempt under the Monitoring and reports &amp;gt;&amp;gt; favorites &amp;gt;&amp;gt; radius authentication today.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000; font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000; font-size: 10pt;"&gt;Rgds, Jatin&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000; font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000; font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000; font-size: 10pt;"&gt;Do rate helpful posts-&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Mar 2011 00:09:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-tls-machine-authorization-using-acs-5-2/m-p/1643205#M249382</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2011-03-11T00:09:08Z</dc:date>
    </item>
    <item>
      <title>Re: EAP-TLS machine authorization using ACS 5.2</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-tls-machine-authorization-using-acs-5-2/m-p/1643206#M249385</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I ran debug-adclient while trying to authenticate a machine using EAP-TLS and it seems like the ACS does not even try to query the AD for attributes.&amp;nbsp; I don't why this is happening.&amp;nbsp; What I have comfigured in my authentication rule is:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Authentication Method: match x509_PKI (I know this works because it passes with just this checked)&lt;/P&gt;&lt;P&gt;2) AD1: ExternalGroups: contains any and the list of groups&lt;/P&gt;&lt;P&gt;3) Sytem:UserName: starts with host/&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you see why the ACS does not even try to query the AD?&amp;nbsp; I know the ACS can because when MSCHAP is allowed, I see all the queries being done properly with the attributes being returned to the ACS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Secondly, if I do configure machine authentication with MSCHAPv2 when using user authentication as well, does the machine athentication only happen at boot?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Mar 2011 15:39:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-tls-machine-authorization-using-acs-5-2/m-p/1643206#M249385</guid>
      <dc:creator>bhatatrans</dc:creator>
      <dc:date>2011-03-11T15:39:11Z</dc:date>
    </item>
    <item>
      <title>Re: EAP-TLS machine authorization using ACS 5.2</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-tls-machine-authorization-using-acs-5-2/m-p/1643207#M249387</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #800000; font-size: 10pt;"&gt;Yes, In order to initiate machine authentication, you must reboot the machine/computer/lapotop. (Recommended).&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000; font-size: 10pt;"&gt;&lt;BR /&gt;Microsoft PEAP clients may also initiate machine authentication whenever a user logs off. This feature prepares the network connection for the next user login. Microsoft PEAP clients may also initiate machine authentication when a user shuts down or restarts the computer rather than just logging off. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000; font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000; font-size: 10pt;"&gt;Rgds, Jatin&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000; font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000; font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;SPAN style="color: #800000;"&gt;Do rate helpful posts-&lt;/SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Mar 2011 12:56:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-tls-machine-authorization-using-acs-5-2/m-p/1643207#M249387</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2011-03-14T12:56:43Z</dc:date>
    </item>
    <item>
      <title>Re: EAP-TLS machine authorization using ACS 5.2</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-tls-machine-authorization-using-acs-5-2/m-p/1643208#M249389</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for clearing up machine authentication using PEAP.&amp;nbsp; I didn't know we could also authenticate at each login.&amp;nbsp; Is this only for Windows 7 or will it work for Windows XP SP3 clients as well?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have opened up a TAC with Cisco for my TLS authentication issue.&amp;nbsp; I will post what I find out.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for you help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anita&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Mar 2011 13:32:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-tls-machine-authorization-using-acs-5-2/m-p/1643208#M249389</guid>
      <dc:creator>bhatatrans</dc:creator>
      <dc:date>2011-03-14T13:32:43Z</dc:date>
    </item>
    <item>
      <title>Re: EAP-TLS machine authorization using ACS 5.2</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-tls-machine-authorization-using-acs-5-2/m-p/1643209#M249391</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #800000; font-size: 10pt;"&gt;Well, reboot is required for all kind of OS and supplicants to initiate machine authentication.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000; font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000; font-size: 10pt;"&gt;However, in Windows XP SP3, the wired network connection settings are defined as a separate service&lt;BR /&gt;from the wireless network connection service. In this new service, all the wired network connection profile information is stored in XML files. Therefore, the AuthMode and Supplicant Mode registry entries are no longer used in Windows XP SP3. The settings that these registry keys define must now be added directly to the profile.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000; font-size: 10pt;"&gt;The default value for the supplicant mode in Windows XP SP3 for a client that uses a wired network connection is 3. In this setting value, the client sends an Extensible Authentication Protocol over LAN (EAPOL)-Start message for each change in user context. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000; font-size: 10pt;"&gt;The default value for the authentication mode in Windows XP SP3 for a client that uses a wired network connection is 1&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000; font-size: 10pt;"&gt;&lt;BR /&gt;You cannot connect to an 802.1X wired network after you upgrade to Windows XP Service Pack 3&lt;BR /&gt;&lt;A class="jive-link-external-small" href="http://support.microsoft.com/kb/953650"&gt;http://support.microsoft.com/kb/953650&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000; font-size: 10pt;"&gt;Changes to the 802.1X-based wired network connection settings in Windows XP Service Pack 3&lt;BR /&gt;&lt;A class="jive-link-external-small" href="http://support.microsoft.com/kb/949984/"&gt;http://support.microsoft.com/kb/949984/&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000; font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000; font-size: 10pt;"&gt;Rgds, Jatin&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000; font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000; font-size: 10pt;"&gt;Do rate helpful posts-&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Mar 2011 14:24:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-tls-machine-authorization-using-acs-5-2/m-p/1643209#M249391</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2011-03-14T14:24:30Z</dc:date>
    </item>
    <item>
      <title>Re: EAP-TLS machine authorization using ACS 5.2</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-tls-machine-authorization-using-acs-5-2/m-p/1643210#M249393</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think I may have found the issue.&amp;nbsp; It looks like the ACS cannot properly query the AD using Computer names.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In &lt;SPAN class="cuesBreadcrumbStatic"&gt;Users and Identity Stores&lt;/SPAN&gt; &amp;gt;&lt;SPAN class="cuesBreadcrumbStatic"&gt;External Identity Stores&lt;/SPAN&gt; &amp;gt;&lt;SPAN class="cuesBreadcrumbLast"&gt; Active Directory &amp;gt; Directory Attributes, I can search attributes of any user, but all computer names I enter return no values when I click on Select...&amp;nbsp; I verified the account we are using for querying the AD and it has the permissions to read and query the entire Active Directory.&amp;nbsp; Do you know why this may be happening?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anita&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Mar 2011 19:24:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-tls-machine-authorization-using-acs-5-2/m-p/1643210#M249393</guid>
      <dc:creator>bhatatrans</dc:creator>
      <dc:date>2011-03-14T19:24:09Z</dc:date>
    </item>
    <item>
      <title>Re: EAP-TLS machine authorization using ACS 5.2</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-tls-machine-authorization-using-acs-5-2/m-p/1643211#M249394</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello.&lt;/P&gt;&lt;P&gt;Just checking something here:&lt;/P&gt;&lt;P&gt;In your policy, under Identity, do you have AD1 (or some&lt;A class="cuesDrawerItemLink" target="_self"&gt;&lt;SPAN class="cuesSelectedDrawerItem"&gt; Identity Store Sequences&lt;/SPAN&gt;&lt;/A&gt; with AD1 in it) listed as Identity Source?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Mar 2011 12:59:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-tls-machine-authorization-using-acs-5-2/m-p/1643211#M249394</guid>
      <dc:creator>dal</dc:creator>
      <dc:date>2011-03-16T12:59:43Z</dc:date>
    </item>
    <item>
      <title>Re: EAP-TLS machine authorization using ACS 5.2</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-tls-machine-authorization-using-acs-5-2/m-p/1643212#M249396</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, you were absolutely right.&amp;nbsp; I was wondering how to make the connection between Identity and authority.&amp;nbsp; I had chosen&lt;/P&gt;&lt;P&gt;CN Username.&amp;nbsp; Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anita&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Mar 2011 15:45:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-tls-machine-authorization-using-acs-5-2/m-p/1643212#M249396</guid>
      <dc:creator>bhatatrans</dc:creator>
      <dc:date>2011-03-16T15:45:53Z</dc:date>
    </item>
  </channel>
</rss>

