<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Machine and User Authentication with Win Native Supplicant in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/machine-and-user-authentication-with-win-native-supplicant/m-p/3822848#M474643</link>
    <description>&lt;P&gt;I don't think the auto smart port macro will work well in this case.&amp;nbsp; Part of our job as ISE consultants is to advise customers on best practices and help them avoid bad designs.&amp;nbsp; What you just describes is a bad design in my opinion and I wouldn't let one of my customers go down this path.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If the device does correct computer authentication it is has proven that it is a corporate asset.&amp;nbsp; Why place it in a VLAN with limited access?&amp;nbsp; If they want to do some restrictions use a DACL.&lt;/P&gt;</description>
    <pubDate>Wed, 20 Mar 2019 12:13:12 GMT</pubDate>
    <dc:creator>paul</dc:creator>
    <dc:date>2019-03-20T12:13:12Z</dc:date>
    <item>
      <title>Machine and User Authentication with Win Native Supplicant</title>
      <link>https://community.cisco.com/t5/network-access-control/machine-and-user-authentication-with-win-native-supplicant/m-p/3822031#M474640</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;It seems that I will be using native supplicant for my machine and user authentication because of licensing with AnyConnect NAM.&lt;/P&gt;
&lt;P&gt;Anyway, based on the design, once a successful machine authentication the endpoint will be placed into a machine VLAN (like a landing VLAN which have a limited access) then once a successful user authentication, the endpoint will be placed into the user VLAN which has access for everything.&lt;/P&gt;
&lt;P&gt;Here is my concern, I believed that ISE does not send CoA after user authentication meaning, the endpoint is still in the machine VLAN with the same IP. How to overcome this scenario? Or what should be the best approach for this one?&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 19 Mar 2019 13:54:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/machine-and-user-authentication-with-win-native-supplicant/m-p/3822031#M474640</guid>
      <dc:creator>fatalXerror</dc:creator>
      <dc:date>2019-03-19T13:54:07Z</dc:date>
    </item>
    <item>
      <title>Re: Machine and User Authentication with Win Native Supplicant</title>
      <link>https://community.cisco.com/t5/network-access-control/machine-and-user-authentication-with-win-native-supplicant/m-p/3822072#M474641</link>
      <description>&lt;P&gt;Doing a VLAN switch after the initial connection is always tough and something I wouldn't attempt.&amp;nbsp; If you really set on trying it you could do an autosmart port that would bounce the port, but then you are going to disconnect the phone if there is one.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What is the purpose of changing VLANs?&amp;nbsp; The concept of VLANs for security is a bit dated (although still used heavily).&amp;nbsp; You can push DACLs, SGT tags, etc. to grant different levels of access without relying on VLAN changes.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Mar 2019 14:27:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/machine-and-user-authentication-with-win-native-supplicant/m-p/3822072#M474641</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2019-03-19T14:27:00Z</dc:date>
    </item>
    <item>
      <title>Re: Machine and User Authentication with Win Native Supplicant</title>
      <link>https://community.cisco.com/t5/network-access-control/machine-and-user-authentication-with-win-native-supplicant/m-p/3822512#M474642</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/192011"&gt;@paul&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;It is just to simplify the use of ISE for operation purposes, the client wants to have it after a successful machine authentication to put it into a machine vlan with limited access then after a successful user authentication, put it in user vlan with full access.&lt;/P&gt;
&lt;P&gt;Any other ways other than using auto-smart port to address my concern?&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 20 Mar 2019 04:14:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/machine-and-user-authentication-with-win-native-supplicant/m-p/3822512#M474642</guid>
      <dc:creator>fatalXerror</dc:creator>
      <dc:date>2019-03-20T04:14:44Z</dc:date>
    </item>
    <item>
      <title>Re: Machine and User Authentication with Win Native Supplicant</title>
      <link>https://community.cisco.com/t5/network-access-control/machine-and-user-authentication-with-win-native-supplicant/m-p/3822848#M474643</link>
      <description>&lt;P&gt;I don't think the auto smart port macro will work well in this case.&amp;nbsp; Part of our job as ISE consultants is to advise customers on best practices and help them avoid bad designs.&amp;nbsp; What you just describes is a bad design in my opinion and I wouldn't let one of my customers go down this path.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If the device does correct computer authentication it is has proven that it is a corporate asset.&amp;nbsp; Why place it in a VLAN with limited access?&amp;nbsp; If they want to do some restrictions use a DACL.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Mar 2019 12:13:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/machine-and-user-authentication-with-win-native-supplicant/m-p/3822848#M474643</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2019-03-20T12:13:12Z</dc:date>
    </item>
    <item>
      <title>Re: Machine and User Authentication with Win Native Supplicant</title>
      <link>https://community.cisco.com/t5/network-access-control/machine-and-user-authentication-with-win-native-supplicant/m-p/3822865#M474644</link>
      <description>I agree with &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/15810"&gt;@paul&lt;/a&gt;. I think your better option is to explain the benefits to them of using Anyconnect NAM module. One of the major benefits is the ability to use eap-chaining via eap-fast. Using this will allow you to move computers/users into different subnets or apply separate dacls like Paul mentioned. There is a really nice condition you can use in authz policies known as eapchainingresult, which can drive policy based on computer pass + user fail, user pass + computer fail, and user/comp pass. I would push for this. Unfortunately, as far as I know the Windows native supplicant does not support eap-fast or the industry standard eap-teap that would give you the ability to use eap-chaining.</description>
      <pubDate>Wed, 20 Mar 2019 12:37:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/machine-and-user-authentication-with-win-native-supplicant/m-p/3822865#M474644</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2019-03-20T12:37:25Z</dc:date>
    </item>
    <item>
      <title>Re: Machine and User Authentication with Win Native Supplicant</title>
      <link>https://community.cisco.com/t5/network-access-control/machine-and-user-authentication-with-win-native-supplicant/m-p/3822977#M474645</link>
      <description>&lt;P&gt;hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/833210"&gt;@Mike.Cifelli&lt;/a&gt;&amp;nbsp;, I agree with that also and at first I suggested anyconnect NAM but upon checking, the anyconnect 4.x needs now license even if I will just use the NAM module.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Mar 2019 14:47:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/machine-and-user-authentication-with-win-native-supplicant/m-p/3822977#M474645</guid>
      <dc:creator>fatalXerror</dc:creator>
      <dc:date>2019-03-20T14:47:55Z</dc:date>
    </item>
    <item>
      <title>Re: Machine and User Authentication with Win Native Supplicant</title>
      <link>https://community.cisco.com/t5/network-access-control/machine-and-user-authentication-with-win-native-supplicant/m-p/3822986#M474646</link>
      <description>&lt;P&gt;Why does the customer need to go to User authentication?&amp;nbsp; Many customers just want to make sure the device that is connecting is a corporate asset.&amp;nbsp; PEAP Computer authentication tells you that.&amp;nbsp; If you don't have differentiated user access policies or aren't feeding user information to pxGrid connected systems then there is no reason to go to user mode authentication.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Mar 2019 14:55:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/machine-and-user-authentication-with-win-native-supplicant/m-p/3822986#M474646</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2019-03-20T14:55:10Z</dc:date>
    </item>
    <item>
      <title>Re: Machine and User Authentication with Win Native Supplicant</title>
      <link>https://community.cisco.com/t5/network-access-control/machine-and-user-authentication-with-win-native-supplicant/m-p/3822988#M474647</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/192011"&gt;@paul&lt;/a&gt;&amp;nbsp;, they have user differentiated access.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Mar 2019 15:00:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/machine-and-user-authentication-with-win-native-supplicant/m-p/3822988#M474647</guid>
      <dc:creator>fatalXerror</dc:creator>
      <dc:date>2019-03-20T15:00:52Z</dc:date>
    </item>
    <item>
      <title>Re: Machine and User Authentication with Win Native Supplicant</title>
      <link>https://community.cisco.com/t5/network-access-control/machine-and-user-authentication-with-win-native-supplicant/m-p/3823064#M474648</link>
      <description>&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/303946"&gt;@fatalXerror&lt;/a&gt; I think from a security perspective you get an extra layer if you have the ability to quarantine actual users too instead of just computers objects. Obviously there are many ways to skin the cat here. &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/15810"&gt;@paul&lt;/a&gt; makes some good points. If user authentication is a must then they should understand that you will need to spend money on the appropriate licenses to run NAM.</description>
      <pubDate>Wed, 20 Mar 2019 16:15:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/machine-and-user-authentication-with-win-native-supplicant/m-p/3823064#M474648</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2019-03-20T16:15:04Z</dc:date>
    </item>
    <item>
      <title>Re: Machine and User Authentication with Win Native Supplicant</title>
      <link>https://community.cisco.com/t5/network-access-control/machine-and-user-authentication-with-win-native-supplicant/m-p/3830549#M474649</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/833210"&gt;@Mike.Cifelli&lt;/a&gt;, I was able to convinced the admin about the limitation of the MAR and now we will just be using machine authentication to determine organizational asset.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Apr 2019 10:38:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/machine-and-user-authentication-with-win-native-supplicant/m-p/3830549#M474649</guid>
      <dc:creator>fatalXerror</dc:creator>
      <dc:date>2019-04-02T10:38:51Z</dc:date>
    </item>
  </channel>
</rss>

