<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Awesome thanks! in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-1-3-disable-quot-identity-resolve-quot-step/m-p/2794512#M41765</link>
    <description>&lt;P&gt;Awesome thanks!&lt;/P&gt;</description>
    <pubDate>Thu, 19 Nov 2015 15:21:37 GMT</pubDate>
    <dc:creator>marc.groenen</dc:creator>
    <dc:date>2015-11-19T15:21:37Z</dc:date>
    <item>
      <title>Cisco ISE 1.3 disable "Identity Resolve" step ?</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-1-3-disable-quot-identity-resolve-quot-step/m-p/2794510#M41763</link>
      <description>&lt;P&gt;Currently i am working for a customer with a Cisco ISE 1.3 deployment.&lt;/P&gt;
&lt;P&gt;The Cisco AP's are currently authenticated through MAB, the customer wants to improve this i suggested to implement EAP-FAST instade of MAB for the AP's for a quick and easy fix.&lt;/P&gt;
&lt;P&gt;I have this working in the test and production environment but i was cycling through the authentication process and found something strange.&lt;/P&gt;
&lt;P&gt;I created a rule that if the Network Tunnel protocol is EAP-FAST the credentials are authenticated through Internal Users.&lt;/P&gt;
&lt;P&gt;This works fine,the ISE recognises the flow and authenticatie's through Internal Users.&lt;/P&gt;
&lt;P&gt;15041 Evaluating Identity Policy &lt;BR /&gt; 15048 Queried PIP - Network Access.EapAuthentication &lt;BR /&gt; 15048 Queried PIP - Network Access.EapTunnel &lt;BR /&gt; 15004 Matched rule - EAP-FAST &lt;BR /&gt; 15013 Selected Identity Source - Internal Users &lt;BR /&gt; 24210 Looking up User in Internal Users IDStore - &amp;lt;&amp;lt;Username&amp;gt;&amp;gt;&lt;BR /&gt; 24212 Found User in Internal Users IDStore &lt;BR /&gt; 22037 Authentication Passed&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Further down the path it decides to look the user up in Active Directory.&lt;/P&gt;
&lt;P&gt;Since the user hasnt been created in the active directory it cant find it.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;24432 Looking up user in Active Directory - &amp;lt;&amp;lt;Active Directory &amp;gt;&amp;gt;&amp;nbsp;&lt;BR /&gt; 24325 Resolving identity - &amp;lt;&amp;lt;Username&amp;gt;&amp;gt;&lt;BR /&gt; 24313 Search for matching accounts at join point - &lt;SPAN&gt;&amp;lt;&amp;lt;Active Directory &amp;gt;&amp;gt;&lt;/SPAN&gt; &lt;BR /&gt; 24318 No matching account found in forest - &lt;SPAN&gt;&amp;lt;&amp;lt;Active Directory &amp;gt;&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt; 24322 Identity resolution detected no matching account &lt;BR /&gt; 24352 Identity resolution failed - ERROR_NO_SUCH_USER &lt;BR /&gt; 24412 User not found in Active Directory - &lt;SPAN&gt;&amp;lt;&amp;lt;Active Directory &amp;gt;&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt; 15048 Queried PIP - &lt;SPAN&gt;&amp;lt;&amp;lt;Active Directory &amp;gt;&amp;gt;&lt;/SPAN&gt;.ExternalGroups &lt;BR /&gt; 15048 Queried PIP - Network Access.EapTunnel &lt;BR /&gt; 15004 Matched rule - AP_EAPFAST &lt;BR /&gt; 15016 Selected Authorization Profile - AP_Lan &lt;BR /&gt; 11002 Returned RADIUS Access-Accept &lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;So the authentication and authorisation is succesfull but it try's to resolve the user in the active directory.&lt;/P&gt;
&lt;P&gt;I checked the authentication process for MAB and there i see the same error.&lt;/P&gt;
&lt;P&gt;The MAC adress of the device used for MAB is also only added to the ISE so the authentication goes through Internal Users, authentication and authorisation is succesfull but ISE wants to resolve the user(MAC adress of device) in the Active Directory.&lt;/P&gt;
&lt;P&gt;We also see this step for the EAP-TLS flow and in this case the resolving identity step offcorse is succesfull.&lt;/P&gt;
&lt;P&gt;Is there some way i can disable the resolving of identity through AD when Internal User Group?(or globally?)&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I did some searching and found this(LDAP User Lookup)&lt;/P&gt;
&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/docs/security/ise/1.0/user_guide/ise10_man_id_stores.html#wp1067288" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/ise/1.0/user_guide/ise10_man_id_stores.html#wp1067288&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;When i look at our deployment there is nothing configured under LDAP.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 06:15:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-1-3-disable-quot-identity-resolve-quot-step/m-p/2794510#M41763</guid>
      <dc:creator>marc.groenen</dc:creator>
      <dc:date>2019-03-11T06:15:26Z</dc:date>
    </item>
    <item>
      <title>If you have ANY rules in your</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-1-3-disable-quot-identity-resolve-quot-step/m-p/2794511#M41764</link>
      <description>&lt;P&gt;If you have ANY rules in your authorization rules that use AD groups that are before your MAB or EAP-FAST rules, ISE will do a lookup, to see if it should match that rule. Put your MAB and EAP-FAST rules before any AD membership rules, and it won't do the lookup.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Nov 2015 14:47:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-1-3-disable-quot-identity-resolve-quot-step/m-p/2794511#M41764</guid>
      <dc:creator>jan.nielsen</dc:creator>
      <dc:date>2015-11-19T14:47:03Z</dc:date>
    </item>
    <item>
      <title>Awesome thanks!</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-1-3-disable-quot-identity-resolve-quot-step/m-p/2794512#M41765</link>
      <description>&lt;P&gt;Awesome thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 19 Nov 2015 15:21:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-1-3-disable-quot-identity-resolve-quot-step/m-p/2794512#M41765</guid>
      <dc:creator>marc.groenen</dc:creator>
      <dc:date>2015-11-19T15:21:37Z</dc:date>
    </item>
  </channel>
</rss>

