<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Wired Dot1x and forcing machine auth on windows in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/wired-dot1x-and-forcing-machine-auth-on-windows/m-p/336051#M432809</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Right, you need AuthMode = 2.&lt;/P&gt;&lt;P&gt;If onlky allowing domain memebers onto the network is the primary goal, then you may also want to consider:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;* The Machine Access Restriction feature on ACS (what you referred to before as a cache, but does help for mitigation of this threat).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;* Denying dial-in permisssions on user accounts (but this may break other things you may be using for remote access).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Example: If someone brought in there PC from home with virtually any supplicant on it, they're on the network as long as their NT credentials check out (whether machine-auth fails or not, b/c remember they can configure their own supplicant).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 27 Jan 2005 14:11:40 GMT</pubDate>
    <dc:creator>jafrazie</dc:creator>
    <dc:date>2005-01-27T14:11:40Z</dc:date>
    <item>
      <title>Wired Dot1x and forcing machine auth on windows</title>
      <link>https://community.cisco.com/t5/network-access-control/wired-dot1x-and-forcing-machine-auth-on-windows/m-p/336049#M432807</link>
      <description>&lt;P&gt;I've got wired dot1x authentication working ok. the ACS server backs off to a windows domain so machine level authentication works fine. However I can't see a way of forcing windows to only ever do machine authentication. Has anyone else looked at this? I could enable the option on the ACS server to require a previous machine auth before it accepts a user auth but it can only cache this for a limited amount of time. The only way to get a machine auth is for there not to be a user logged on at the time. If we accept user auth then any user can bring their own machine onto the network but we this is what we want to stop and only allow bank standard (i.e. domain members) machines on the network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;cheers&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 20:59:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wired-dot1x-and-forcing-machine-auth-on-windows/m-p/336049#M432807</guid>
      <dc:creator>mweavind</dc:creator>
      <dc:date>2019-03-10T20:59:13Z</dc:date>
    </item>
    <item>
      <title>Re: Wired Dot1x and forcing machine auth on windows</title>
      <link>https://community.cisco.com/t5/network-access-control/wired-dot1x-and-forcing-machine-auth-on-windows/m-p/336050#M432808</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.microsoft.com/technet/prodtechnol/winxppro/maintain/wificomp.mspx#EEAA" target="_blank"&gt;http://www.microsoft.com/technet/prodtechnol/winxppro/maintain/wificomp.mspx#EEAA&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Search for AuthMode - Registry Settings&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Jan 2005 07:19:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wired-dot1x-and-forcing-machine-auth-on-windows/m-p/336050#M432808</guid>
      <dc:creator>Florian Sontheim</dc:creator>
      <dc:date>2005-01-27T07:19:12Z</dc:date>
    </item>
    <item>
      <title>Re: Wired Dot1x and forcing machine auth on windows</title>
      <link>https://community.cisco.com/t5/network-access-control/wired-dot1x-and-forcing-machine-auth-on-windows/m-p/336051#M432809</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Right, you need AuthMode = 2.&lt;/P&gt;&lt;P&gt;If onlky allowing domain memebers onto the network is the primary goal, then you may also want to consider:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;* The Machine Access Restriction feature on ACS (what you referred to before as a cache, but does help for mitigation of this threat).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;* Denying dial-in permisssions on user accounts (but this may break other things you may be using for remote access).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Example: If someone brought in there PC from home with virtually any supplicant on it, they're on the network as long as their NT credentials check out (whether machine-auth fails or not, b/c remember they can configure their own supplicant).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Jan 2005 14:11:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wired-dot1x-and-forcing-machine-auth-on-windows/m-p/336051#M432809</guid>
      <dc:creator>jafrazie</dc:creator>
      <dc:date>2005-01-27T14:11:40Z</dc:date>
    </item>
  </channel>
</rss>

