<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Avoid username password prompt everytime a workstation unplugs/plugs in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/avoid-username-password-prompt-everytime-a-workstation-unplugs/m-p/3596152#M496917</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;With username/password you can cache credentials in the supplicant so you do not need to re-type them with every new authentication. I'm not aware of how you can cache a token. You have chosen a very secure authentication method - welcome to the side effect! Suggest you consider certificates which can be automatically presented as Jason suggested.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Letting an endpoint on for a set time (8 hours) is usually only done with Guests where the consequences of a MAC spoof would be fairly inconsequential. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 20 Jun 2018 21:54:24 GMT</pubDate>
    <dc:creator>thomas</dc:creator>
    <dc:date>2018-06-20T21:54:24Z</dc:date>
    <item>
      <title>Avoid username password prompt everytime a workstation unplugs/plugs</title>
      <link>https://community.cisco.com/t5/network-access-control/avoid-username-password-prompt-everytime-a-workstation-unplugs/m-p/3596150#M496915</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have a customer who is using 2FA for wired dot1x.&lt;/P&gt;&lt;P&gt;Their requirement is to not prompt the machine for username/credentials everytime the machine unplugs and plugs for 8 hours.&lt;/P&gt;&lt;P&gt;The user comes int the morning and enters its username and 2FA and then can seamlessly move around for next 8 hours.&lt;/P&gt;&lt;P&gt;Any thoughts on if and how that can be achieved ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Maybe if we can dump authenticated machines hitting various authorization rules into identity groups the first time they authenticate and then purge them at the end of the day.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Jun 2018 15:20:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/avoid-username-password-prompt-everytime-a-workstation-unplugs/m-p/3596150#M496915</guid>
      <dc:creator>umahar</dc:creator>
      <dc:date>2018-06-18T15:20:43Z</dc:date>
    </item>
    <item>
      <title>Re: Avoid username password prompt everytime a workstation unplugs/plugs</title>
      <link>https://community.cisco.com/t5/network-access-control/avoid-username-password-prompt-everytime-a-workstation-unplugs/m-p/3596151#M496916</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What about machine cert plus cached user cert or creds?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Or machine cert plus CWA flow or using CWA with 2FA perhaps? Not sure if possible but endpoint could be registered to a endpoint group for day perhaps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Jun 2018 16:45:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/avoid-username-password-prompt-everytime-a-workstation-unplugs/m-p/3596151#M496916</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-06-19T16:45:48Z</dc:date>
    </item>
    <item>
      <title>Re: Avoid username password prompt everytime a workstation unplugs/plugs</title>
      <link>https://community.cisco.com/t5/network-access-control/avoid-username-password-prompt-everytime-a-workstation-unplugs/m-p/3596152#M496917</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;With username/password you can cache credentials in the supplicant so you do not need to re-type them with every new authentication. I'm not aware of how you can cache a token. You have chosen a very secure authentication method - welcome to the side effect! Suggest you consider certificates which can be automatically presented as Jason suggested.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Letting an endpoint on for a set time (8 hours) is usually only done with Guests where the consequences of a MAC spoof would be fairly inconsequential. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Jun 2018 21:54:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/avoid-username-password-prompt-everytime-a-workstation-unplugs/m-p/3596152#M496917</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2018-06-20T21:54:24Z</dc:date>
    </item>
    <item>
      <title>Re: Avoid username password prompt everytime a workstation unplugs/plugs</title>
      <link>https://community.cisco.com/t5/network-access-control/avoid-username-password-prompt-everytime-a-workstation-unplugs/m-p/3596153#M496918</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Jason and Thomas for your inputs&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jason, I already discussed possibility of using CWA but customer does not want to add another flow. Besides MAC spoofing is a big risk.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thomas I did discuss the same thing with customer that they will have to make a trade off between security and user experience. They have very strict instructions from their management to only use 2FA for NAC. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Jun 2018 14:26:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/avoid-username-password-prompt-everytime-a-workstation-unplugs/m-p/3596153#M496918</guid>
      <dc:creator>umahar</dc:creator>
      <dc:date>2018-06-21T14:26:39Z</dc:date>
    </item>
  </channel>
</rss>

