<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How users able to login to domain in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/how-users-able-to-login-to-domain/m-p/3850887#M439888</link>
    <description>I am not quite sure I am following.&lt;BR /&gt;&lt;BR /&gt;All policy now control by ISE &amp;amp; ACS. But in the first place, without 802.1x config, how the traffic from all branches can reach AD domain in HQ? Can someone enlighten me?&lt;BR /&gt;&lt;BR /&gt;How are you pushing policy if 8021x is not enabled? From a routing perspective you need to ensure your hosts can reach AD.</description>
    <pubDate>Mon, 06 May 2019 15:36:51 GMT</pubDate>
    <dc:creator>Mike.Cifelli</dc:creator>
    <dc:date>2019-05-06T15:36:51Z</dc:date>
    <item>
      <title>How users able to login to domain</title>
      <link>https://community.cisco.com/t5/network-access-control/how-users-able-to-login-to-domain/m-p/3850696#M439876</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I was wondering how end-users workstation able to reach ACS. Does it has anything to do with ip helper config in the switches?&lt;/P&gt;&lt;P&gt;802.1X is currently not enable. All policy now control by ISE &amp;amp; ACS. But in the first place, without 802.1x config, how the traffic from all branches can reach AD domain in HQ? Can someone enlighten me?&lt;/P&gt;</description>
      <pubDate>Mon, 06 May 2019 10:55:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-users-able-to-login-to-domain/m-p/3850696#M439876</guid>
      <dc:creator>getaway51</dc:creator>
      <dc:date>2019-05-06T10:55:07Z</dc:date>
    </item>
    <item>
      <title>Re: How users able to login to domain</title>
      <link>https://community.cisco.com/t5/network-access-control/how-users-able-to-login-to-domain/m-p/3850765#M439881</link>
      <description>&lt;P&gt;So the IP helper config does not come into play for the 8021x process. The helper will be used to ensure that you can dynamically pull an IP from DHCP. Here is a somewhat brief overview of the 8021x process:&lt;/P&gt;&lt;P&gt;Three main components are used:&lt;BR /&gt;1. Supplicant --&amp;gt;port authentication entity seeking network access (workstation)&lt;BR /&gt;2. Authenticator--&amp;gt;Network Access Device(switch)&lt;BR /&gt;3. Authentication server--&amp;gt;ISE/ACS&lt;/P&gt;&lt;P&gt;EAPoL which is used between your workstation and the switch. Radius is then used between the switch and AAA server. It looks like this:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="eapol.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/36205i9674D220DB63CF84/image-size/medium?v=v2&amp;amp;px=400" role="button" title="eapol.png" alt="eapol.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;With that information note that the NAD will manage the communication to your AAA server and the actual workstations will not talk to the AAA server.&amp;nbsp; I hope this clears up the process for you!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 06 May 2019 13:09:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-users-able-to-login-to-domain/m-p/3850765#M439881</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2019-05-06T13:09:28Z</dc:date>
    </item>
    <item>
      <title>Re: How users able to login to domain</title>
      <link>https://community.cisco.com/t5/network-access-control/how-users-able-to-login-to-domain/m-p/3850842#M439887</link>
      <description>&lt;P&gt;i mean currently no 802.1x. How user able to reach ACS&amp;nbsp; (i.e they login everytime PC boots up)? There is no 802.1X now, i wondering how the process like "login to domain" works?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 06 May 2019 14:55:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-users-able-to-login-to-domain/m-p/3850842#M439887</guid>
      <dc:creator>getaway51</dc:creator>
      <dc:date>2019-05-06T14:55:23Z</dc:date>
    </item>
    <item>
      <title>Re: How users able to login to domain</title>
      <link>https://community.cisco.com/t5/network-access-control/how-users-able-to-login-to-domain/m-p/3850887#M439888</link>
      <description>I am not quite sure I am following.&lt;BR /&gt;&lt;BR /&gt;All policy now control by ISE &amp;amp; ACS. But in the first place, without 802.1x config, how the traffic from all branches can reach AD domain in HQ? Can someone enlighten me?&lt;BR /&gt;&lt;BR /&gt;How are you pushing policy if 8021x is not enabled? From a routing perspective you need to ensure your hosts can reach AD.</description>
      <pubDate>Mon, 06 May 2019 15:36:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-users-able-to-login-to-domain/m-p/3850887#M439888</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2019-05-06T15:36:51Z</dc:date>
    </item>
  </channel>
</rss>

