<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Documentation - Cisco ISE MAR implementation in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/documentation-cisco-ise-mar-implementation/m-p/4012218#M454528</link>
    <description>&lt;P&gt;Hi Giovanni,&lt;/P&gt;
&lt;P&gt;MAR is not a configuration in the supplicant, but rather an attempt by the RADIUS server to cache the machine credential and tie that to the user credential for the same MAC address. The only configuration in the Windows supplicant would be to ensure the 802.1x authentication mode is configured for 'User or computer authentication'&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That said, MAR has various &lt;A href="https://www.cisco.com/c/en/us/support/docs/lan-switching/8021x/116516-problemsolution-technology-00.html" target="_self"&gt;known issues&lt;/A&gt; is not recommended.&lt;/P&gt;
&lt;P&gt;I know of many customers that quickly moved away from using MAR as these known issues were causing multiple user experience complaints.&lt;/P&gt;
&lt;P&gt;The best option currently available would be to use Cisco AnyConnect NAM and &lt;A href="https://community.cisco.com/t5/security-documents/how-to-deploy-eap-chaining-with-anyconnect-nam-and-ise/ta-p/3630969" target="_self"&gt;EAP-Chaining&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;ISE 2.7 does support EAP-TEAP, but Microsoft has not yet released support for TEAP in the Windows supplicant.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;Greg&lt;/P&gt;</description>
    <pubDate>Wed, 15 Jan 2020 22:45:18 GMT</pubDate>
    <dc:creator>Greg Gibbs</dc:creator>
    <dc:date>2020-01-15T22:45:18Z</dc:date>
    <item>
      <title>Documentation - Cisco ISE MAR implementation</title>
      <link>https://community.cisco.com/t5/network-access-control/documentation-cisco-ise-mar-implementation/m-p/4011520#M454527</link>
      <description>&lt;P&gt;Dear All,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;can someone please point me&amp;nbsp; a documentation (slides/video/workd) to describe guidelines to implement MAR (&lt;/P&gt;
&lt;H2 class="message-subject"&gt;&lt;SPAN class="lia-message-unread"&gt;Machine + User Auth&lt;/SPAN&gt;) on windows platform ?&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Giovanni&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jan 2020 21:28:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/documentation-cisco-ise-mar-implementation/m-p/4011520#M454527</guid>
      <dc:creator>Giovanni Di Venuta</dc:creator>
      <dc:date>2020-01-14T21:28:44Z</dc:date>
    </item>
    <item>
      <title>Re: Documentation - Cisco ISE MAR implementation</title>
      <link>https://community.cisco.com/t5/network-access-control/documentation-cisco-ise-mar-implementation/m-p/4012218#M454528</link>
      <description>&lt;P&gt;Hi Giovanni,&lt;/P&gt;
&lt;P&gt;MAR is not a configuration in the supplicant, but rather an attempt by the RADIUS server to cache the machine credential and tie that to the user credential for the same MAC address. The only configuration in the Windows supplicant would be to ensure the 802.1x authentication mode is configured for 'User or computer authentication'&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That said, MAR has various &lt;A href="https://www.cisco.com/c/en/us/support/docs/lan-switching/8021x/116516-problemsolution-technology-00.html" target="_self"&gt;known issues&lt;/A&gt; is not recommended.&lt;/P&gt;
&lt;P&gt;I know of many customers that quickly moved away from using MAR as these known issues were causing multiple user experience complaints.&lt;/P&gt;
&lt;P&gt;The best option currently available would be to use Cisco AnyConnect NAM and &lt;A href="https://community.cisco.com/t5/security-documents/how-to-deploy-eap-chaining-with-anyconnect-nam-and-ise/ta-p/3630969" target="_self"&gt;EAP-Chaining&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;ISE 2.7 does support EAP-TEAP, but Microsoft has not yet released support for TEAP in the Windows supplicant.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;Greg&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jan 2020 22:45:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/documentation-cisco-ise-mar-implementation/m-p/4012218#M454528</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2020-01-15T22:45:18Z</dc:date>
    </item>
    <item>
      <title>Re: Documentation - Cisco ISE MAR implementation</title>
      <link>https://community.cisco.com/t5/network-access-control/documentation-cisco-ise-mar-implementation/m-p/4012781#M454529</link>
      <description>what is the benefit to use AC NAM vs native supplicant ?&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;BR /&gt;Giovanni&lt;BR /&gt;</description>
      <pubDate>Thu, 16 Jan 2020 16:04:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/documentation-cisco-ise-mar-implementation/m-p/4012781#M454529</guid>
      <dc:creator>Giovanni Di Venuta</dc:creator>
      <dc:date>2020-01-16T16:04:58Z</dc:date>
    </item>
    <item>
      <title>Re: Documentation - Cisco ISE MAR implementation</title>
      <link>https://community.cisco.com/t5/network-access-control/documentation-cisco-ise-mar-implementation/m-p/4012993#M454530</link>
      <description>&lt;P&gt;In short, the Windows native supplicant currently only supports EAP types that can send one credential at a time, whereas AC NAM supports EAP-FASTv2 with EAP-Chaining that enables sending both the machine and user credentials in the same message.&lt;/P&gt;
&lt;P&gt;Take a look at this article written by one of the Cisco Technical Marketing Engineers.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.networkworld.com/article/2940463/machine-authentication-and-user-authentication.html" target="_self"&gt;Machine Authentication and User Authentication&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;Greg&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jan 2020 20:43:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/documentation-cisco-ise-mar-implementation/m-p/4012993#M454530</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2020-01-16T20:43:19Z</dc:date>
    </item>
  </channel>
</rss>

