<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ISE 2.4 Authentication Problem in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-2-4-authentication-problem/m-p/3814908#M484551</link>
    <description>bern81, thank you for the reply. As I said I am new in Cisco ISE.&lt;BR /&gt;Is there any helpful documentation about what you wrote (EAP_TLS Authentication). Because I confused among documentations.</description>
    <pubDate>Wed, 06 Mar 2019 13:10:47 GMT</pubDate>
    <dc:creator>bagiyevramin</dc:creator>
    <dc:date>2019-03-06T13:10:47Z</dc:date>
    <item>
      <title>Cisco ISE 2.4 Authentication Problem</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-2-4-authentication-problem/m-p/3814707#M484543</link>
      <description>&lt;P&gt;Hi, I am new in Cisco ISE.&lt;/P&gt;&lt;P&gt;My Cisco ISE version is 2.4.0.357&lt;/P&gt;&lt;P&gt;In my environment, there are a lot of thin clients which is not in the domain and they will not be in the domain in future. I want these thin clients to join network after passing 802.1X.&lt;/P&gt;&lt;P&gt;How can I achieve this goal with the help of Cisco ISE?&lt;/P&gt;&lt;P&gt;Please help.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Mar 2019 06:23:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-2-4-authentication-problem/m-p/3814707#M484543</guid>
      <dc:creator>bagiyevramin</dc:creator>
      <dc:date>2019-03-06T06:23:11Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 2.4 Authentication Problem</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-2-4-authentication-problem/m-p/3814746#M484546</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You could do EAP-TLS authentication for those clients by creating certificates for them.&lt;/P&gt;
&lt;P&gt;Create a CAP (certificate authentication Profile) in the ISE that will check the CN filed of the certificate or SAN-DNS field&lt;/P&gt;
&lt;P&gt;BUT don't perform any AD lookup in the CAP.&lt;/P&gt;
&lt;P&gt;use this CAP in the authentication policy.&lt;/P&gt;
&lt;P&gt;Then in the authorization policy you can match on certificate fields as conditions to apply policies like VLAN/DACL ....&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ORR less secure method use MAB authentication by adding the MAC addreses to those devices into the ISE database or use an external database like LDAP.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I hope this helps.&lt;/P&gt;
&lt;P&gt;Please rate.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Mar 2019 08:11:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-2-4-authentication-problem/m-p/3814746#M484546</guid>
      <dc:creator>bern81</dc:creator>
      <dc:date>2019-03-06T08:11:49Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 2.4 Authentication Problem</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-2-4-authentication-problem/m-p/3814908#M484551</link>
      <description>bern81, thank you for the reply. As I said I am new in Cisco ISE.&lt;BR /&gt;Is there any helpful documentation about what you wrote (EAP_TLS Authentication). Because I confused among documentations.</description>
      <pubDate>Wed, 06 Mar 2019 13:10:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-2-4-authentication-problem/m-p/3814908#M484551</guid>
      <dc:creator>bagiyevramin</dc:creator>
      <dc:date>2019-03-06T13:10:47Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 2.4 Authentication Problem</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-2-4-authentication-problem/m-p/3815047#M484554</link>
      <description>&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/529249"&gt;@bern81&lt;/a&gt; posted helpful information. IMO, unless you are familiar with PKI and/or if you dont already have an internal PKI setup I would recommend moving forward with the mab solution. Obviously this depends on your requirements, but it will be much easier to manage. If you are interested in 8021x with eap-tls you can find some good video tutorials here:&lt;BR /&gt;&lt;A href="http://www.labminutes.com/video/sec" target="_blank"&gt;http://www.labminutes.com/video/sec&lt;/A&gt;&lt;BR /&gt;HTH!</description>
      <pubDate>Wed, 06 Mar 2019 16:46:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-2-4-authentication-problem/m-p/3815047#M484554</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2019-03-06T16:46:57Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 2.4 Authentication Problem</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-2-4-authentication-problem/m-p/3815424#M484558</link>
      <description>&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/833210"&gt;@Mike.Cifelli&lt;/a&gt; thank you for the reply and link. I'll watch all these videos. Thank you.</description>
      <pubDate>Thu, 07 Mar 2019 07:03:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-2-4-authentication-problem/m-p/3815424#M484558</guid>
      <dc:creator>bagiyevramin</dc:creator>
      <dc:date>2019-03-07T07:03:11Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 2.4 Authentication Problem</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-2-4-authentication-problem/m-p/3815452#M484560</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;I know this is a little bit complicated as Mike mentioned, you need to have a PKI that signs certificates and u need to configure EAP-TLS on the windows devices.&lt;BR /&gt;Check on internet as well about CAP configuration in ISE.</description>
      <pubDate>Thu, 07 Mar 2019 08:32:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-2-4-authentication-problem/m-p/3815452#M484560</guid>
      <dc:creator>bern81</dc:creator>
      <dc:date>2019-03-07T08:32:41Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 2.4 Authentication Problem</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-2-4-authentication-problem/m-p/3816921#M484563</link>
      <description>&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/529249"&gt;@bern81&lt;/a&gt; thank you for the reply, I'll check.</description>
      <pubDate>Sun, 10 Mar 2019 08:19:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-2-4-authentication-problem/m-p/3816921#M484563</guid>
      <dc:creator>bagiyevramin</dc:creator>
      <dc:date>2019-03-10T08:19:13Z</dc:date>
    </item>
  </channel>
</rss>

