<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Enroll a Mgt port as dot1x supplicant (client) to AD in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/enroll-a-mgt-port-as-dot1x-supplicant-client-to-ad/m-p/3959370#M455609</link>
    <description>&lt;P&gt;Hi everybody&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm building a lab to test the authentication methodes of all connected clients in our company (cameras, fire access points, PC, IP phones, APs., technical devices..etc) to our IP N/W. To do that I've&amp;nbsp;a C3650-24 switch acting as authenticator on which I configured port24 as SPAN for wireshark, I've also&amp;nbsp;a Cisco ISE as test Radius/ Tacacs as authentication server (with AD) and the Infoblox as DHCP/DNS servers. I try to&amp;nbsp;test dot1x compatibility of&amp;nbsp;client devices or for legacy ones fixed IP, the&amp;nbsp;alternative MAB authentication methode.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Before testing real client devices, I've choosen a C3650s as generic test device&amp;nbsp;and its Ethernet&amp;nbsp;Management port on which I can give a static IP or DHCP reservation IP config and to simulate its authentication with dot1x or with its mac add (for MAB), all works fine with MAB except that I cannot install a dot1x certificat on that management port and I don't know if it's really possible to make it configured as a supplicant&amp;nbsp;candidate to&amp;nbsp;enroll for a dot1x certificate over the company's AD and ISE, any idea is very welcome&lt;/P&gt;</description>
    <pubDate>Fri, 15 Nov 2019 15:30:27 GMT</pubDate>
    <dc:creator>Zarra</dc:creator>
    <dc:date>2019-11-15T15:30:27Z</dc:date>
    <item>
      <title>Enroll a Mgt port as dot1x supplicant (client) to AD</title>
      <link>https://community.cisco.com/t5/network-access-control/enroll-a-mgt-port-as-dot1x-supplicant-client-to-ad/m-p/3959370#M455609</link>
      <description>&lt;P&gt;Hi everybody&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm building a lab to test the authentication methodes of all connected clients in our company (cameras, fire access points, PC, IP phones, APs., technical devices..etc) to our IP N/W. To do that I've&amp;nbsp;a C3650-24 switch acting as authenticator on which I configured port24 as SPAN for wireshark, I've also&amp;nbsp;a Cisco ISE as test Radius/ Tacacs as authentication server (with AD) and the Infoblox as DHCP/DNS servers. I try to&amp;nbsp;test dot1x compatibility of&amp;nbsp;client devices or for legacy ones fixed IP, the&amp;nbsp;alternative MAB authentication methode.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Before testing real client devices, I've choosen a C3650s as generic test device&amp;nbsp;and its Ethernet&amp;nbsp;Management port on which I can give a static IP or DHCP reservation IP config and to simulate its authentication with dot1x or with its mac add (for MAB), all works fine with MAB except that I cannot install a dot1x certificat on that management port and I don't know if it's really possible to make it configured as a supplicant&amp;nbsp;candidate to&amp;nbsp;enroll for a dot1x certificate over the company's AD and ISE, any idea is very welcome&lt;/P&gt;</description>
      <pubDate>Fri, 15 Nov 2019 15:30:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/enroll-a-mgt-port-as-dot1x-supplicant-client-to-ad/m-p/3959370#M455609</guid>
      <dc:creator>Zarra</dc:creator>
      <dc:date>2019-11-15T15:30:27Z</dc:date>
    </item>
    <item>
      <title>Re: Enroll a Mgt port as dot1x supplicant (client) to AD</title>
      <link>https://community.cisco.com/t5/network-access-control/enroll-a-mgt-port-as-dot1x-supplicant-client-to-ad/m-p/3959869#M455611</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/934420"&gt;@Zarra&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can try the&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/support/docs/lan-switching/8021x/116681-config-neat-cise-00.html" target="_blank" rel="noopener"&gt;NEAT&lt;/A&gt;&amp;nbsp; configuration (highly complicated). But if you are simply doing a test for 802.1x and MAB, using a switch as a test device is really not the ideal candidate. Trust me.&lt;/P&gt;
&lt;P&gt;Moreover, this is not a 'real-world scenario', even for your own customer.&lt;/P&gt;
&lt;P&gt;You can use any PC, even the one you are using to logging into the switch &lt;span class="lia-unicode-emoji" title=":face_with_tongue:"&gt;😛&lt;/span&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 17 Nov 2019 14:23:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/enroll-a-mgt-port-as-dot1x-supplicant-client-to-ad/m-p/3959869#M455611</guid>
      <dc:creator>Anurag Sharma</dc:creator>
      <dc:date>2019-11-17T14:23:08Z</dc:date>
    </item>
  </channel>
</rss>

