<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Thanks Neno, in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-2-0-domain-non-domain-machine-auth-problem/m-p/2861361#M36643</link>
    <description>&lt;P&gt;Thanks Neno,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I have done this for domain users but now facing problem some time domain users getting APIPA ip address initially and after release/renew they get actual IP. Same issue is happening with Guest Wireless users. Is there any KB for windows 7, Service Pack 1 , 32 bit OS.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Kamlesh&lt;/P&gt;</description>
    <pubDate>Wed, 20 Apr 2016 07:10:08 GMT</pubDate>
    <dc:creator>kamlenegi</dc:creator>
    <dc:date>2016-04-20T07:10:08Z</dc:date>
    <item>
      <title>ISE 2.0 Domain &amp; Non Domain Machine Auth Problem</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-0-domain-non-domain-machine-auth-problem/m-p/2861359#M36641</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Can anyone suggest me for ISE 2.0 authorization policy for Domain &amp;amp; Non Domain machine.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Requirement: Domain machine should authenticate from domain user id &amp;amp; password using PEAP. but non domain machine should not authenticate by using domain credential in windows supplicant.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I am trying it using user or computer setting and selecting authorization policy (domain computers &amp;amp; domain users)&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Kamlesh&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 06:40:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-0-domain-non-domain-machine-auth-problem/m-p/2861359#M36641</guid>
      <dc:creator>kamlenegi</dc:creator>
      <dc:date>2019-03-11T06:40:59Z</dc:date>
    </item>
    <item>
      <title>hi Kamlesh-</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-0-domain-non-domain-machine-auth-problem/m-p/2861360#M36642</link>
      <description>&lt;P&gt;hi Kamlesh-&lt;/P&gt;
&lt;P&gt;You can definitely do that. What you will need to do is:&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;For Authentication:&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;- Allow PEAP MSCHAPv2 as the allowed authentication protocol&lt;/P&gt;
&lt;P&gt;- Select Active Directory for the Authentication Store&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;For Authorization:&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;- Create a rule that checks that the endpoint is part of the desired AD group (for instance, domain computers)&lt;/P&gt;
&lt;P&gt;- Deny everything else&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;The Windows Computers should be configured to:&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;- Perform PEAP based authentication&lt;/P&gt;
&lt;P&gt;- Computer type authentication only&lt;/P&gt;
&lt;P&gt;- Set to trust the CA that signed the ISE certificate&lt;/P&gt;
&lt;P&gt;I hope this helps!&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Apr 2016 16:32:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-0-domain-non-domain-machine-auth-problem/m-p/2861360#M36642</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2016-04-19T16:32:45Z</dc:date>
    </item>
    <item>
      <title>Thanks Neno,</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-0-domain-non-domain-machine-auth-problem/m-p/2861361#M36643</link>
      <description>&lt;P&gt;Thanks Neno,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I have done this for domain users but now facing problem some time domain users getting APIPA ip address initially and after release/renew they get actual IP. Same issue is happening with Guest Wireless users. Is there any KB for windows 7, Service Pack 1 , 32 bit OS.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Kamlesh&lt;/P&gt;</description>
      <pubDate>Wed, 20 Apr 2016 07:10:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-0-domain-non-domain-machine-auth-problem/m-p/2861361#M36643</guid>
      <dc:creator>kamlenegi</dc:creator>
      <dc:date>2016-04-20T07:10:08Z</dc:date>
    </item>
    <item>
      <title>Sounds like the DHCP requests</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-0-domain-non-domain-machine-auth-problem/m-p/2861362#M36644</link>
      <description>&lt;P&gt;Sounds like the DHCP requests are timing out and as a result the client is getting the 169.x.x.x address. What values do you have for your timers?&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Apr 2016 17:27:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-0-domain-non-domain-machine-auth-problem/m-p/2861362#M36644</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2016-04-20T17:27:32Z</dc:date>
    </item>
    <item>
      <title>Hi Neno,</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-0-domain-non-domain-machine-auth-problem/m-p/2861363#M36645</link>
      <description>&lt;P&gt;Hi Neno,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Attached snapshot for timer. One more question for regarding license, ISE is consuming license for old connection which is not active but showing authenticated &amp;amp; started. Is there any setting do I need in ISE.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Kamlesh&lt;/P&gt;</description>
      <pubDate>Thu, 21 Apr 2016 11:14:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-0-domain-non-domain-machine-auth-problem/m-p/2861363#M36645</guid>
      <dc:creator>kamlenegi</dc:creator>
      <dc:date>2016-04-21T11:14:36Z</dc:date>
    </item>
    <item>
      <title>So you are doing a VLAN</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-0-domain-non-domain-machine-auth-problem/m-p/2861364#M36646</link>
      <description>&lt;P&gt;So you are doing a VLAN override on the guest clients? The reason I ask is because I have never been able to get that feature to work well. Instead, I have always preferred to use DACLs (Switched Guests) and Named-ACLs (WLCs).&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you must use that feature I would suggest increasing the timers a bit and see if that works.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For your licensing question:&lt;/P&gt;
&lt;P style="margin: 0in; margin-left: .75in; font-family: Calibri; font-size: 11.0pt;"&gt;The Cisco ISE license is counted as follows:&lt;/P&gt;
&lt;UL&gt;
&lt;LI style="margin: 0in; margin-left: .75in; font-family: Calibri; font-size: 11.0pt;"&gt;A Base or Advanced license is consumed based on the feature that is utilized.&lt;/LI&gt;
&lt;LI style="margin: 0in; margin-left: .75in; font-family: Calibri; font-size: 11.0pt;"&gt;An endpoint with multiple network connections can consume more than one license per MAC&lt;/LI&gt;
&lt;/UL&gt;
&lt;P style="margin: 0in; margin-left: .75in; font-family: Calibri; font-size: 11.0pt;"&gt;address. For example, a laptop connected to wired and also to wireless at the same time. Licenses&lt;/P&gt;
&lt;P style="margin: 0in; margin-left: .75in; font-family: Calibri; font-size: 11.0pt;"&gt;for VPN connections are based on the IP address.&lt;/P&gt;
&lt;UL&gt;
&lt;LI style="margin: 0in; margin-left: .75in; font-family: Calibri; font-size: 11.0pt;"&gt;Licenses are counted against concurrent, active sessions. An active session is one for which a&lt;/LI&gt;
&lt;/UL&gt;
&lt;P style="margin: 0in; margin-left: .75in; font-family: Calibri; font-size: 11.0pt;"&gt;RADIUS Accounting Start is received but RADIUS Accounting Stop has not yet been received.&lt;/P&gt;
&lt;P style="margin: 0in; margin-left: .75in; font-family: Calibri; font-size: 11.0pt;"&gt;Note Sessions without RADIUS activity are automatically purged from Active Session list every&lt;/P&gt;
&lt;P style="margin: 0in; margin-left: .75in; font-family: Calibri; font-size: 11.0pt;"&gt;5 days or if the endpoint is deleted from the system.&lt;/P&gt;
&lt;P style="margin: 0in; margin-left: .75in; font-family: Calibri; font-size: 11.0pt;"&gt;To avoid service disruption, Cisco ISE continues to provide services to endpoints that exceed license&lt;/P&gt;
&lt;P style="margin: 0in; margin-left: .75in; font-family: Calibri; font-size: 11.0pt;"&gt;entitlement. Cisco ISE instead relies on RADIUS accounting functions to track concurrent endpoints on&lt;/P&gt;
&lt;P style="margin: 0in; margin-left: .75in; font-family: Calibri; font-size: 11.0pt;"&gt;the network and generate alarms when endpoint counts exceed the licensed amounts:&lt;/P&gt;
&lt;UL&gt;
&lt;LI style="margin: 0in; margin-left: .75in; font-family: Calibri; font-size: 11.0pt;"&gt;80% Info&lt;/LI&gt;
&lt;LI style="margin: 0in; margin-left: .75in; font-family: Calibri; font-size: 11.0pt;"&gt;90% Warning&lt;/LI&gt;
&lt;LI style="margin: 0in; margin-left: .75in; font-family: Calibri; font-size: 11.0pt;"&gt;100% Critical&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;EM&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 24 Apr 2016 01:14:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-0-domain-non-domain-machine-auth-problem/m-p/2861364#M36646</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2016-04-24T01:14:24Z</dc:date>
    </item>
    <item>
      <title>Thanks Neno,</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-0-domain-non-domain-machine-auth-problem/m-p/2861365#M36647</link>
      <description>&lt;P&gt;Thanks Neno,&lt;/P&gt;
&lt;P&gt;I am changing the solution for guest and assigning IP address which is unauth.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;One more question regarding mobile wireless users in flexconnect. It seems that flexconnect environment doesn't support mac filtering. Is there any way ISE support mac authentication for mobile devices. My requirement is three group of mobile users should get different subnet which is possible from WLC making three ssids but should mac authenticate which is not possible in WLC using flexconnect. Three different subnet is required for Proxy filtering.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks for your help.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Apr 2016 09:14:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-0-domain-non-domain-machine-auth-problem/m-p/2861365#M36647</guid>
      <dc:creator>kamlenegi</dc:creator>
      <dc:date>2016-04-25T09:14:40Z</dc:date>
    </item>
    <item>
      <title>You are most welcome!</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-0-domain-non-domain-machine-auth-problem/m-p/2861366#M36648</link>
      <description>&lt;P&gt;You are most welcome!&lt;/P&gt;
&lt;P&gt;Regards,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Neno&lt;/P&gt;</description>
      <pubDate>Mon, 25 Apr 2016 15:39:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-0-domain-non-domain-machine-auth-problem/m-p/2861366#M36648</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2016-04-25T15:39:38Z</dc:date>
    </item>
  </channel>
</rss>

