<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic I use same solution here to in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/802-1x-with-logon-script/m-p/2953707#M37920</link>
    <description>&lt;P&gt;I use same solution here to solve my problem.However, we allow the pc to ad to get the logon script in preauth stage.&lt;/P&gt;</description>
    <pubDate>Wed, 02 Nov 2016 05:32:55 GMT</pubDate>
    <dc:creator>cheungchunyu</dc:creator>
    <dc:date>2016-11-02T05:32:55Z</dc:date>
    <item>
      <title>802.1x with logon script</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-with-logon-script/m-p/2953704#M37917</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Before setting the 802.1x with ISE.The user logon with a script for mapping the network drive.&lt;/P&gt;
&lt;P&gt;We deployed the 802.1x with ip phone and PC successfully, however the logon script is not working now.&lt;/P&gt;
&lt;P&gt;Any required step to make the logon script work?&lt;/P&gt;
&lt;P&gt;ISE:2.1&lt;/P&gt;
&lt;P&gt;switch :3750 with 12.2(55) SE10&lt;/P&gt;
&lt;P&gt;PC:WIN7 (connect to ip phone)&lt;/P&gt;
&lt;P&gt;ip phone:6921(connect to switch f 1/0/4)&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Switch config is show follow:&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;!&lt;BR /&gt;version 12.2&lt;BR /&gt;no service pad&lt;BR /&gt;service tcp-keepalives-in&lt;BR /&gt;service tcp-keepalives-out&lt;BR /&gt;service timestamps debug datetime msec localtime show-timezone&lt;BR /&gt;service timestamps log datetime msec localtime show-timezone&lt;BR /&gt;no service password-encryption&lt;BR /&gt;service linenumber&lt;BR /&gt;service sequence-numbers&lt;BR /&gt;!&lt;BR /&gt;hostname ISESW01&lt;BR /&gt;!&lt;BR /&gt;boot-start-marker&lt;BR /&gt;boot-end-marker&lt;BR /&gt;!&lt;BR /&gt;enable password 7&amp;nbsp;xxxxxxxxxxxxxxxxxxxxxx&lt;BR /&gt;!&lt;BR /&gt;username xxxxxxxxxxx&amp;nbsp;password 7&amp;nbsp;xxxxxxxxxxxxxxxxxxxx&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;&amp;nbsp;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;aaa new-model&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;aaa group server radius ISE&lt;BR /&gt; server 10.202.152.91 auth-port 1645 acct-port 1646&lt;BR /&gt; server 10.202.152.92 auth-port 1645 acct-port 1646&lt;BR /&gt;!&lt;BR /&gt;aaa authentication dot1x default group ISE&lt;BR /&gt;aaa authorization network default group ISE &lt;BR /&gt;aaa authorization auth-proxy default group ISE &lt;BR /&gt;aaa accounting update periodic 5&lt;BR /&gt;aaa accounting dot1x default start-stop group ISE&lt;BR /&gt;aaa accounting system default start-stop group ISE&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;aaa server radius dynamic-author&lt;BR /&gt; client 10.202.152.91&amp;nbsp;&lt;BR /&gt; client 10.202.152.92&amp;nbsp;&lt;BR /&gt;!&lt;BR /&gt;aaa session-id common&lt;BR /&gt;switch 1 provision ws-c3750v2-48ps&lt;BR /&gt;system mtu routing 1500&lt;BR /&gt;vtp mode transparent&lt;BR /&gt;&amp;nbsp;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;ip dhcp excluded-address 10.202.21.1 10.202.21.10&lt;BR /&gt;ip dhcp excluded-address 10.202.121.196&lt;BR /&gt;!&lt;BR /&gt;ip dhcp pool testingdhcp&lt;BR /&gt; network 10.202.19.0 255.255.255.0&lt;BR /&gt; default-router 10.202.19.1 &lt;BR /&gt; dns-server 10.202.152.21 &lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;ip device tracking&lt;BR /&gt;!&lt;BR /&gt;mls qos map policed-dscp 0 10 18 24 46 to 8&lt;BR /&gt;mls qos map cos-dscp 0 8 16 24 32 46 48 56&lt;BR /&gt;mls qos srr-queue input bandwidth 70 30&lt;BR /&gt;mls qos srr-queue input threshold 1 80 90&lt;BR /&gt;mls qos srr-queue input priority-queue 2 bandwidth 30&lt;BR /&gt;mls qos srr-queue input cos-map queue 1 threshold 2 3&lt;BR /&gt;mls qos srr-queue input cos-map queue 1 threshold 3 6 7&lt;BR /&gt;mls qos srr-queue input cos-map queue 2 threshold 1 4&lt;BR /&gt;mls qos srr-queue input dscp-map queue 1 threshold 2 24&lt;BR /&gt;mls qos srr-queue input dscp-map queue 1 threshold 3 48 49 50 51 52 53 54 55&lt;BR /&gt;mls qos srr-queue input dscp-map queue 1 threshold 3 56 57 58 59 60 61 62 63&lt;BR /&gt;mls qos srr-queue input dscp-map queue 2 threshold 3 32 33 40 41 42 43 44 45&lt;BR /&gt; --More-- &amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8; &amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;mls qos srr-queue input dscp-map queue 2 threshold 3 46 47&lt;BR /&gt;mls qos srr-queue output cos-map queue 1 threshold 3 4 5&lt;BR /&gt;mls qos srr-queue output cos-map queue 2 threshold 1 2&lt;BR /&gt;mls qos srr-queue output cos-map queue 2 threshold 2 3&lt;BR /&gt;mls qos srr-queue output cos-map queue 2 threshold 3 6 7&lt;BR /&gt;mls qos srr-queue output cos-map queue 3 threshold 3 0&lt;BR /&gt;mls qos srr-queue output cos-map queue 4 threshold 3 1&lt;BR /&gt;mls qos srr-queue output dscp-map queue 1 threshold 3 32 33 40 41 42 43 44 45&lt;BR /&gt;mls qos srr-queue output dscp-map queue 1 threshold 3 46 47&lt;BR /&gt;mls qos srr-queue output dscp-map queue 2 threshold 1 16 17 18 19 20 21 22 23&lt;BR /&gt;mls qos srr-queue output dscp-map queue 2 threshold 1 26 27 28 29 30 31 34 35&lt;BR /&gt;mls qos srr-queue output dscp-map queue 2 threshold 1 36 37 38 39&lt;BR /&gt;mls qos srr-queue output dscp-map queue 2 threshold 2 24&lt;BR /&gt;mls qos srr-queue output dscp-map queue 2 threshold 3 48 49 50 51 52 53 54 55&lt;BR /&gt;mls qos srr-queue output dscp-map queue 2 threshold 3 56 57 58 59 60 61 62 63&lt;BR /&gt;mls qos srr-queue output dscp-map queue 3 threshold 3 0 1 2 3 4 5 6 7&lt;BR /&gt;mls qos srr-queue output dscp-map queue 4 threshold 1 8 9 11 13 15&lt;BR /&gt;mls qos srr-queue output dscp-map queue 4 threshold 2 10 12 14&lt;BR /&gt;mls qos queue-set output 1 threshold 1 100 100 50 200&lt;BR /&gt;mls qos queue-set output 1 threshold 2 125 125 100 400&lt;BR /&gt;mls qos queue-set output 1 threshold 3 100 100 100 400&lt;BR /&gt;mls qos queue-set output 1 threshold 4 60 150 50 200&lt;BR /&gt;mls qos queue-set output 1 buffers 15 25 40 20&lt;BR /&gt;mls qos&lt;BR /&gt;!&lt;BR /&gt;crypto pki trustpoint TP-self-signed-1210376576&lt;BR /&gt; enrollment selfsigned&lt;BR /&gt; subject-name cn=IOS-Self-Signed-Certificate-1210376576&lt;BR /&gt; revocation-check none&lt;BR /&gt; rsakeypair TP-self-signed-1210376576&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;crypto pki certificate chain TP-self-signed-1210376576&lt;BR /&gt; certificate self-signed 01&lt;BR /&gt;xxxxxxxxxxxxxxxxxxxxxxxxxxxxxx&lt;BR /&gt; quit&lt;BR /&gt;auto qos srnd4&lt;BR /&gt;dot1x system-auth-control&lt;BR /&gt;dot1x critical eapol&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;spanning-tree mode pvst&lt;BR /&gt;spanning-tree extend system-id&lt;BR /&gt;spanning-tree vlan 819 priority 61440&lt;BR /&gt;!&lt;BR /&gt;vlan internal allocation policy ascending&lt;BR /&gt;!&lt;BR /&gt;vlan 121&lt;BR /&gt; name Voice_Vlan&lt;BR /&gt;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8; &amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;!&lt;BR /&gt;vlan 819&lt;BR /&gt; name 19F_VLAN&lt;BR /&gt;!&lt;BR /&gt;vlan 888,899 &lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;class-map match-all AUTOQOS_VOIP_DATA_CLASS&lt;BR /&gt; match ip dscp ef &lt;BR /&gt;class-map match-all AUTOQOS_DEFAULT_CLASS&lt;BR /&gt; match access-group name AUTOQOS-ACL-DEFAULT&lt;BR /&gt;class-map match-all AUTOQOS_VOIP_SIGNAL_CLASS&lt;BR /&gt; match ip dscp cs3 &lt;BR /&gt;class-map match-all AutoQoS-VoIP-RTP-Trust&lt;BR /&gt; match ip dscp ef &lt;BR /&gt;class-map match-all AutoQoS-VoIP-Control-Trust&lt;BR /&gt; match ip dscp cs3 af31 &lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;policy-map AUTOQOS-SRND4-CISCOPHONE-POLICY&lt;BR /&gt; class AUTOQOS_VOIP_DATA_CLASS&lt;BR /&gt; set dscp ef&lt;BR /&gt; police 128000 8000 exceed-action policed-dscp-transmit&lt;BR /&gt;class AUTOQOS_VOIP_SIGNAL_CLASS&lt;BR /&gt; set dscp cs3&lt;BR /&gt; police 32000 8000 exceed-action policed-dscp-transmit&lt;BR /&gt; class AUTOQOS_DEFAULT_CLASS&lt;BR /&gt; set dscp default&lt;BR /&gt; police 10000000 8000 exceed-action policed-dscp-transmit&lt;BR /&gt;policy-map AutoQoS-Police-CiscoPhone&lt;BR /&gt; class AutoQoS-VoIP-RTP-Trust&lt;BR /&gt; set dscp ef&lt;BR /&gt; police 320000 8000 exceed-action policed-dscp-transmit&lt;BR /&gt; class AutoQoS-VoIP-Control-Trust&lt;BR /&gt; set dscp cs3&lt;BR /&gt; police 32000 8000 exceed-action policed-dscp-transmit&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;&lt;BR /&gt;interface FastEthernet1/0/4&lt;BR /&gt; switchport access vlan 819&lt;BR /&gt;switchport mode access&lt;BR /&gt; switchport voice vlan 121&lt;BR /&gt; authentication event fail action next-method&lt;BR /&gt; authentication event server dead action authorize voice&lt;BR /&gt; authentication event no-response action authorize vlan 889&lt;BR /&gt; authentication event server alive action reinitialize &lt;BR /&gt; authentication host-mode multi-domain&lt;BR /&gt; authentication order dot1x mab&lt;BR /&gt; authentication priority dot1x&lt;BR /&gt; authentication port-control auto&lt;BR /&gt; mab&lt;BR /&gt; snmp trap mac-notification change added&lt;BR /&gt; snmp trap mac-notification change removed&lt;BR /&gt; dot1x pae authenticator&lt;BR /&gt; dot1x timeout tx-period 10&lt;BR /&gt; spanning-tree portfast&lt;BR /&gt;!&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;!&lt;BR /&gt;interface Vlan1&lt;BR /&gt; no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Vlan819&lt;BR /&gt; ip address 10.202.19.11 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;ip default-gateway 10.202.19.1&lt;BR /&gt;ip classless&lt;BR /&gt;ip http server&lt;BR /&gt;ip http secure-server&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;ip access-list extended AUTOQOS-ACL-DEFAULT&lt;BR /&gt; permit ip any any&lt;BR /&gt;ip access-list extended Redirect&lt;BR /&gt; deny udp any eq bootpc any eq bootps&lt;BR /&gt; deny udp any any eq bootps&lt;BR /&gt; deny udp any any eq domain&lt;BR /&gt; deny ip any host 10.202.154.192&lt;BR /&gt; permit ip any any&lt;BR /&gt;!&lt;BR /&gt;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8; &amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;&amp;#8;!&lt;BR /&gt;snmp-server community Cisco123 RO&lt;BR /&gt;radius-server attribute 6 on-for-login-auth&lt;BR /&gt;radius-server attribute 8 include-in-access-req&lt;BR /&gt;radius-server attribute 25 access-request include&lt;BR /&gt;radius-server dead-criteria time 30 tries 3&lt;BR /&gt;radius-server host 10.202.152.91 auth-port 1645 acct-port 1646 key 7&amp;nbsp;xxxxxxxxxxxxxxxxxxxxxxxx&lt;BR /&gt;radius-server host 10.202.152.92 auth-port 1645 acct-port 1646 key 7&amp;nbsp;xxxxxxxxxxxxxxxxxxxxxxx&lt;BR /&gt;radius-server vsa send accounting&lt;BR /&gt;radius-server vsa send authentication&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 07:09:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-with-logon-script/m-p/2953704#M37917</guid>
      <dc:creator>cheungchunyu</dc:creator>
      <dc:date>2019-03-11T07:09:43Z</dc:date>
    </item>
    <item>
      <title>I had a similar problem when</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-with-logon-script/m-p/2953705#M37918</link>
      <description>&lt;P&gt;I had a similar problem when the workstations where set to 'computer or user authentication' within PEAP settings. What was happening is that the DACL that was used for when the computer account was authenticated restricted access to just the DCs etc, but did not include the locations required for the login script. It appears that in Windows 7 the user login script runs before the dot1x presents the user credentials to the switch.&lt;/P&gt;
&lt;P&gt;So in our case we&amp;nbsp;modified the DACL that is in place for the computer account to permit access to the locations required for the login script (i.e. the network shares servers), and all is working.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Nov 2016 15:18:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-with-logon-script/m-p/2953705#M37918</guid>
      <dc:creator>djhurley</dc:creator>
      <dc:date>2016-11-01T15:18:14Z</dc:date>
    </item>
    <item>
      <title>Use machine only</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-with-logon-script/m-p/2953706#M37919</link>
      <description>&lt;P&gt;Use machine only authentication in windows, or use Cisco AnyConnect NAM with EAP-Chaining, this solves the issue you are most likely having.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Nov 2016 17:46:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-with-logon-script/m-p/2953706#M37919</guid>
      <dc:creator>jan.nielsen</dc:creator>
      <dc:date>2016-11-01T17:46:03Z</dc:date>
    </item>
    <item>
      <title>I use same solution here to</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-with-logon-script/m-p/2953707#M37920</link>
      <description>&lt;P&gt;I use same solution here to solve my problem.However, we allow the pc to ad to get the logon script in preauth stage.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Nov 2016 05:32:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-with-logon-script/m-p/2953707#M37920</guid>
      <dc:creator>cheungchunyu</dc:creator>
      <dc:date>2016-11-02T05:32:55Z</dc:date>
    </item>
  </channel>
</rss>

