<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE Deployment Issues in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-deployment-issues/m-p/3748357#M488113</link>
    <description>&lt;P&gt;Thanks guys, I will double check the GPO setup and update the thread.&lt;/P&gt;</description>
    <pubDate>Fri, 16 Nov 2018 19:44:26 GMT</pubDate>
    <dc:creator>NETAD</dc:creator>
    <dc:date>2018-11-16T19:44:26Z</dc:date>
    <item>
      <title>ISE Deployment Issues</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-deployment-issues/m-p/3748251#M488107</link>
      <description>&lt;P&gt;Hello, I'm working on an ISE deployment and I have couple of issues that I'm encountering. Maybe someone have see similar issues before.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1-All of a sudden certain windows machines stop doing dot1x and revert to MAB until a GPO update is forced, or sometimes removing dot1x from the port and putting it back.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2-Remote desktop only work with machine&amp;nbsp;authorization after the user logs in. I've seen that the only way to get user authorization after the remoting in is by using the anyconnect NAM module. Is that accurate or is there a way to get this working right.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;3-ISE is profiling the cisco 3800 APs as Cisco Access Points only and not a specific model. Is that ok?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We're on ISE 2.2 patch 4 with all win10 pcs.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Thanks&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Nov 2018 17:22:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-deployment-issues/m-p/3748251#M488107</guid>
      <dc:creator>NETAD</dc:creator>
      <dc:date>2018-11-16T17:22:54Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Deployment Issues</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-deployment-issues/m-p/3748269#M488108</link>
      <description>&lt;P&gt;For #1 it sounds like there is an issue with your GPO setup.&amp;nbsp; You shouldn't see devices revert back to MAB (unless they are in hibernation or rebooting).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For #3 that is normal because the CDP attributes are wrong in the Cisco profile for the 2802i APs.&amp;nbsp; Look at the CDP attributes retrieved for the AP and compare them to the Cisco profile.&amp;nbsp; You will see the error.&amp;nbsp; You can modify then&amp;nbsp; Cisco profiles if you want to.&amp;nbsp; In most cases, you don't really care about the specific model of AP outside of asset tracking.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Nov 2018 17:44:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-deployment-issues/m-p/3748269#M488108</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2018-11-16T17:44:04Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Deployment Issues</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-deployment-issues/m-p/3748312#M488111</link>
      <description>&lt;P&gt;To help us all out in the future please don't post a list of questions that are unrelated to each other. This doesn't help those answering or in the future it won't help those researching same issues. Its best to search for each issue then post appropriate subject and message when you don't find what you need. A couple of these already have answers as well in the community. Google search works well first and then if you don't find something then search the community directly.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if you have follow up questions it would be nice to split those into a new thread to keep clean and on-point.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/192011"&gt;@paul&lt;/a&gt;&amp;nbsp;did a great job summarizing some of these and i am going to add onto that&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;1-All of a sudden certain windows machines stop doing dot1x and revert to MAB until a GPO update is forced, or sometimes removing dot1x from the port and putting it back.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;PAUL &amp;gt; For #1 it sounds like there is an issue with your GPO setup.&amp;nbsp; You shouldn't see devices revert back to MAB (unless they are in hibernation or rebooting).&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;2-Remote desktop only work with machine&amp;nbsp;authorization after the user logs in. I've seen that the only way to get user authorization after the remoting in is by using the anyconnect NAM module. Is that accurate or is there a way to get this working right.&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;JAK &amp;gt; correct NAM is a stable way to do this. This is not an ISE question but an anyconnect question or general windows&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/vpn-and-anyconnect/remote-desktop-to-dot1x-authenticated-machine-throws-internal/td-p/3471895" target="_blank"&gt;https://community.cisco.com/t5/vpn-and-anyconnect/remote-desktop-to-dot1x-authenticated-machine-throws-internal/td-p/3471895&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/policy-and-access/dot1x-and-remote-desktop-connections/td-p/403708" target="_blank"&gt;https://community.cisco.com/t5/policy-and-access/dot1x-and-remote-desktop-connections/td-p/403708&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;3-ISE is profiling the cisco 3800 APs as Cisco Access Points only and not a specific model. Is that ok?&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;PAUL &amp;gt;&amp;nbsp;For #3 that is normal because the CDP attributes are wrong in the Cisco profile for the 2802i APs.&amp;nbsp; Look at the CDP attributes retrieved for the AP and compare them to the Cisco profile.&amp;nbsp; You will see the error.&amp;nbsp; You can modify then&amp;nbsp; Cisco profiles if you want to.&amp;nbsp; In most cases, you don't really care about the specific model of AP outside of asset tracking.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Nov 2018 18:47:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-deployment-issues/m-p/3748312#M488111</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-11-16T18:47:41Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Deployment Issues</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-deployment-issues/m-p/3748357#M488113</link>
      <description>&lt;P&gt;Thanks guys, I will double check the GPO setup and update the thread.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Nov 2018 19:44:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-deployment-issues/m-p/3748357#M488113</guid>
      <dc:creator>NETAD</dc:creator>
      <dc:date>2018-11-16T19:44:26Z</dc:date>
    </item>
  </channel>
</rss>

