<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Enable 802.1x on non domain joined users in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/enable-802-1x-on-non-domain-joined-users/m-p/3894374#M471596</link>
    <description>&lt;P&gt;Hi Mike,&lt;/P&gt;&lt;P&gt;These are not domain connected devices.&lt;/P&gt;</description>
    <pubDate>Sun, 21 Jul 2019 15:15:24 GMT</pubDate>
    <dc:creator>Taro-AB81</dc:creator>
    <dc:date>2019-07-21T15:15:24Z</dc:date>
    <item>
      <title>Enable 802.1x on non domain joined users</title>
      <link>https://community.cisco.com/t5/network-access-control/enable-802-1x-on-non-domain-joined-users/m-p/3888109#M471578</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;I have 1000+ users who need 802.1x to be enabled. (Windows, Ubuntu, Mac Os). We have configured the CISCO ISE and wonder is there's any way we can use a batch file to deploy. We can ask user to download and run the batch file.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have anyone done this before, or how to enable 802.1x on 1000+ users without doing it manually? (Users are not domain connected)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advanced.&lt;/P&gt;&lt;P&gt;#ciscoise #802.1x #nac&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jul 2019 02:28:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/enable-802-1x-on-non-domain-joined-users/m-p/3888109#M471578</guid>
      <dc:creator>Taro-AB81</dc:creator>
      <dc:date>2019-07-11T02:28:28Z</dc:date>
    </item>
    <item>
      <title>Re: Enable 802.1x on non domain joined users</title>
      <link>https://community.cisco.com/t5/network-access-control/enable-802-1x-on-non-domain-joined-users/m-p/3888247#M471584</link>
      <description>You need to have a tool to do this. Its not about enabling it but also&lt;BR /&gt;getting feedback that it was enabled successfully.&lt;BR /&gt;&lt;BR /&gt;I am sure you will find a powershell script to enable dot1x on endusers&lt;BR /&gt;that is the easy part. But making sure that its enabled successfully needs&lt;BR /&gt;a desktop management tool  otherwise you might break the network&lt;BR /&gt;connectivity of the user.&lt;BR /&gt;&lt;BR /&gt;Another option is to use Cisco NAM. With that, you can enable NAM download&lt;BR /&gt;on your VPN gateway (ASA) so that once the user connects to anyconnect VPN,&lt;BR /&gt;NAM will be downloaded along with XML file which has all the authentication&lt;BR /&gt;settings. This is a safer way.&lt;BR /&gt;&lt;BR /&gt;**** remember to rate useful posts&lt;BR /&gt;</description>
      <pubDate>Thu, 11 Jul 2019 07:10:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/enable-802-1x-on-non-domain-joined-users/m-p/3888247#M471584</guid>
      <dc:creator>Mohammed al Baqari</dc:creator>
      <dc:date>2019-07-11T07:10:17Z</dc:date>
    </item>
    <item>
      <title>Re: Enable 802.1x on non domain joined users</title>
      <link>https://community.cisco.com/t5/network-access-control/enable-802-1x-on-non-domain-joined-users/m-p/3888445#M471588</link>
      <description>To better assist you with some potential ideas can you answer the following:&lt;BR /&gt;Are the 1000+ users spread across several external domains or are they a part of one single external domain?&lt;BR /&gt;Do you have a point of contact from the external domain/s?&lt;BR /&gt;Do the external domain/s have internal PKI?&lt;BR /&gt;Have you determined if you plan to use native supplicant or NAM? I think for your scenario you should stay away from NAM since you cannot run it on linux flavors.&lt;BR /&gt;As far as the switch configs, are you planning to deploy static interface configs to support 8021x and/or flexauth? Or do you plan to use templates across the board that you can apply to your user interfaces?</description>
      <pubDate>Thu, 11 Jul 2019 12:34:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/enable-802-1x-on-non-domain-joined-users/m-p/3888445#M471588</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2019-07-11T12:34:32Z</dc:date>
    </item>
    <item>
      <title>Re: Enable 802.1x on non domain joined users</title>
      <link>https://community.cisco.com/t5/network-access-control/enable-802-1x-on-non-domain-joined-users/m-p/3894373#M471593</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Thank you, the issue is im only involved with enabling it on client side. Switches are configured by a separate department. So I wonder is there's a script that can be used for Windows/Ubuntu/Mac OS.&lt;/P&gt;</description>
      <pubDate>Sun, 21 Jul 2019 15:13:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/enable-802-1x-on-non-domain-joined-users/m-p/3894373#M471593</guid>
      <dc:creator>Taro-AB81</dc:creator>
      <dc:date>2019-07-21T15:13:45Z</dc:date>
    </item>
    <item>
      <title>Re: Enable 802.1x on non domain joined users</title>
      <link>https://community.cisco.com/t5/network-access-control/enable-802-1x-on-non-domain-joined-users/m-p/3894374#M471596</link>
      <description>&lt;P&gt;Hi Mike,&lt;/P&gt;&lt;P&gt;These are not domain connected devices.&lt;/P&gt;</description>
      <pubDate>Sun, 21 Jul 2019 15:15:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/enable-802-1x-on-non-domain-joined-users/m-p/3894374#M471596</guid>
      <dc:creator>Taro-AB81</dc:creator>
      <dc:date>2019-07-21T15:15:24Z</dc:date>
    </item>
    <item>
      <title>Re: Enable 802.1x on non domain joined users</title>
      <link>https://community.cisco.com/t5/network-access-control/enable-802-1x-on-non-domain-joined-users/m-p/3894386#M471597</link>
      <description>&lt;P&gt;Many organizations use a MDM to do this. If you consider that, please check with the MDM vendors.&lt;/P&gt;
&lt;P&gt;ISE BYOD can help with MS Windows, Apple iOS, and macOS, but not Ubuntu.&lt;/P&gt;
&lt;P&gt;If you want to do it yourself...&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;For Windows, this one looks interesting — &lt;A href="https://www.asquaredozen.com/2018/07/29/configuring-802-1x-authentication-for-windows-deployment/" target="_blank"&gt;Configuring 802.1x Authentication for Windows Deployment - A Square Dozen&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;For Apple macOS and iOS, create a .mobileconfig file using &lt;A href="https://support.apple.com/apple-configurator" target="_blank"&gt;Apple Configurator&lt;/A&gt; or similar tool and then distribute it.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;For Ubuntu, see &lt;A href="https://unix.stackexchange.com/questions/182847/how-to-automatically-apply-wpa-supplicant-configuration" target="_blank"&gt;ubuntu - How to automatically apply wpa_supplicant configuration? - Unix &amp;amp; Linux Stack Exchange&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 21 Jul 2019 16:04:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/enable-802-1x-on-non-domain-joined-users/m-p/3894386#M471597</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2019-07-21T16:04:48Z</dc:date>
    </item>
  </channel>
</rss>

