<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic on ACS5.2 how can we bind the user authentication and machine au in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/on-acs5-2-how-can-we-bind-the-user-authentication-and-machine/m-p/1709717#M319741</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;yes. For the "only computer", you can either use the AD attribute that says if it's a Person or computer account (don't remember which one from top of my mind) or detect if the radius username starts with host/*&amp;nbsp;&amp;nbsp; which is the definition of a computer authentication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For EAP-TLS, I have to say I'm not sure how the flag is set.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 06 Mar 2012 16:08:58 GMT</pubDate>
    <dc:creator>Nicolas Darchis</dc:creator>
    <dc:date>2012-03-06T16:08:58Z</dc:date>
    <item>
      <title>on ACS5.2 how can we bind the user authentication and machine authentication together</title>
      <link>https://community.cisco.com/t5/network-access-control/on-acs5-2-how-can-we-bind-the-user-authentication-and-machine/m-p/1709712#M319379</link>
      <description>&lt;P&gt;For our wireless, we enabled the machine authentication, but we want to bind the machine authentication and user authentication together which means they need to meet both requirements to access the wireless, how can we do this? Right now looks like as soon as the machine is authenticated, it can access the network, no user authentication needed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 01:14:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/on-acs5-2-how-can-we-bind-the-user-authentication-and-machine/m-p/1709712#M319379</guid>
      <dc:creator>txing</dc:creator>
      <dc:date>2019-03-11T01:14:00Z</dc:date>
    </item>
    <item>
      <title>on ACS5.2 how can we bind the user authentication and machine au</title>
      <link>https://community.cisco.com/t5/network-access-control/on-acs5-2-how-can-we-bind-the-user-authentication-and-machine/m-p/1709713#M319432</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You need to provide a dummy vlan with the machine authentication (so that no access is granted) or a vlan with restricted access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then for the user auth, you can set a condition "was machine authenticated" in the service policy on ACS. If you don't have it, click "customize" at the bottom right of your authorization menu. It then only validates the user auth if the same guy was machine authenticated before&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Jul 2011 17:04:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/on-acs5-2-how-can-we-bind-the-user-authentication-and-machine/m-p/1709713#M319432</guid>
      <dc:creator>Nicolas Darchis</dc:creator>
      <dc:date>2011-07-19T17:04:07Z</dc:date>
    </item>
    <item>
      <title>on ACS5.2 how can we bind the user authentication and machine au</title>
      <link>https://community.cisco.com/t5/network-access-control/on-acs5-2-how-can-we-bind-the-user-authentication-and-machine/m-p/1709714#M319545</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your reply, if I configure the ACS 5.2 like you said, will that mean the users can't get all the login scripts and domain policy, network mapping work over the wirless network ? Because the guestvlan can't talk to AD, is this correct?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Jul 2011 17:11:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/on-acs5-2-how-can-we-bind-the-user-authentication-and-machine/m-p/1709714#M319545</guid>
      <dc:creator>txing</dc:creator>
      <dc:date>2011-07-19T17:11:50Z</dc:date>
    </item>
    <item>
      <title>on ACS5.2 how can we bind the user authentication and machine au</title>
      <link>https://community.cisco.com/t5/network-access-control/on-acs5-2-how-can-we-bind-the-user-authentication-and-machine/m-p/1709715#M319585</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It depends. You can give a vlan that has only access to AD, so the PC will be able to get GPOs and scripts but not access to the rest of the network.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Jul 2011 07:24:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/on-acs5-2-how-can-we-bind-the-user-authentication-and-machine/m-p/1709715#M319585</guid>
      <dc:creator>Nicolas Darchis</dc:creator>
      <dc:date>2011-07-20T07:24:57Z</dc:date>
    </item>
    <item>
      <title>on ACS5.2 how can we bind the user authentication and machine au</title>
      <link>https://community.cisco.com/t5/network-access-control/on-acs5-2-how-can-we-bind-the-user-authentication-and-machine/m-p/1709716#M319666</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Nicolas&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;how would a rule set for such a MAR authentication / authorization look like, something like this?:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Authentication&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rule 1: Permit Access for MSCHAPv2 AND all AD Groups (user and machine)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Authorization&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rule 1: Permit Access for MSCHAPv2 AND Was-Machine-Authenticated = FALSE AND only computer AD Group&lt;/P&gt;&lt;P&gt;--&amp;gt; this rule should "perform" the machine authentiction&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rule 2: Permit Access for MSCHAPv2 AND Was-Machine-Authenticated = TRUE AND only user AD Groups&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Would that work for such a scenario or I am missing something?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And what about EAP-TLS, in the ACS 5.x user guide it is stated:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"When the user authenticates with either PEAP or EAP-FAST, against AD external ID store then ACS performs an additional action. It searches the cache for the users Calling-Station-Id. If it is found then Was-Machine-Authenticated attribute is set to true on the session context, otherwise set to false. "&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does this mean, that with EAP-TLS the Was-Machine-Authenticated attribute does not work. We would like to do the same with first machine and then user certificates, but only user certificates on corporate laptops should be allowed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance and best regards&lt;/P&gt;&lt;P&gt;Dominic&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Mar 2012 07:46:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/on-acs5-2-how-can-we-bind-the-user-authentication-and-machine/m-p/1709716#M319666</guid>
      <dc:creator>Dominic Stalder (old profile)</dc:creator>
      <dc:date>2012-03-06T07:46:31Z</dc:date>
    </item>
    <item>
      <title>on ACS5.2 how can we bind the user authentication and machine au</title>
      <link>https://community.cisco.com/t5/network-access-control/on-acs5-2-how-can-we-bind-the-user-authentication-and-machine/m-p/1709717#M319741</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;yes. For the "only computer", you can either use the AD attribute that says if it's a Person or computer account (don't remember which one from top of my mind) or detect if the radius username starts with host/*&amp;nbsp;&amp;nbsp; which is the definition of a computer authentication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For EAP-TLS, I have to say I'm not sure how the flag is set.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Mar 2012 16:08:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/on-acs5-2-how-can-we-bind-the-user-authentication-and-machine/m-p/1709717#M319741</guid>
      <dc:creator>Nicolas Darchis</dc:creator>
      <dc:date>2012-03-06T16:08:58Z</dc:date>
    </item>
    <item>
      <title>Re: on ACS5.2 how can we bind the user authentication and machin</title>
      <link>https://community.cisco.com/t5/network-access-control/on-acs5-2-how-can-we-bind-the-user-authentication-and-machine/m-p/1709718#M319847</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="padding: 0pt; margin: 0pt;"&gt;Just as a help for others, I first tested with PEAP and it worked well - only AD users on AD computers where able to login to the SSID as desired. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding: 0pt; margin: 0pt;"&gt;Attached you find the ACS 5.3 configuration for PEAP with the "Was-Machine-Authenticated" attribute.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding: 0pt; margin: 0pt;"&gt;Access Policy - Identity:&lt;/P&gt;&lt;P style="padding: 0pt; margin: 0pt;"&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/1/0/2/81201-01_Access_Policy_Identity.png" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Access Policy - Authorization:&lt;/P&gt;&lt;P style="padding: 0pt; margin: 0pt;"&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/2/0/2/81202-02_Access_Policy_Authorization.png" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;Dominic&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Mar 2012 13:34:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/on-acs5-2-how-can-we-bind-the-user-authentication-and-machine/m-p/1709718#M319847</guid>
      <dc:creator>Dominic Stalder (old profile)</dc:creator>
      <dc:date>2012-03-12T13:34:45Z</dc:date>
    </item>
  </channel>
</rss>

