<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: EAP-chaining with internal ID stores in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/eap-chaining-with-internal-id-stores/m-p/3692264#M508058</link>
    <description>&lt;P&gt;This is not a supported setup as EAP-Chaining is for Windows environment ATM. Remember that machine authentication requires domain joined machine to function properly, which is not possible with ISE internal database. You&amp;nbsp;may be able to fake machine authentication using machine certificate to bypass domain join requirement and make it work, but still not an orthodox setup.&lt;/P&gt;
&lt;P&gt;Can you provide why you are looking for such setup?&lt;/P&gt;</description>
    <pubDate>Tue, 21 Aug 2018 15:19:35 GMT</pubDate>
    <dc:creator>howon</dc:creator>
    <dc:date>2018-08-21T15:19:35Z</dc:date>
    <item>
      <title>EAP-chaining with internal ID stores</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-chaining-with-internal-id-stores/m-p/3692107#M508057</link>
      <description>&lt;P&gt;Hello Friends!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Today I tryed to implement EAP-chaining, but without certificate and AD integration.&lt;/P&gt;
&lt;P&gt;I didn`t find any information about it. All existig info regards of AD integration, and machine cert validation.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is it possible to do machine authentication using Internal Devices same way that we do User auth with Internal User store?&lt;/P&gt;
&lt;P&gt;As result a have this&lt;/P&gt;
&lt;TABLE class="content_table" border="0"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="33%"&gt;SelectedAuthenticationIdentityStores&lt;/TD&gt;
&lt;TD width="67%"&gt;Internal Users&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="33%"&gt;SelectedAuthenticationIdentityStores&lt;/TD&gt;
&lt;TD width="67%"&gt;&lt;STRONG&gt;Internal Endpoints&lt;/STRONG&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="33%"&gt;SelectedAuthenticationIdentityStores&lt;/TD&gt;
&lt;TD width="67%"&gt;All_AD_Join_Points&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="33%"&gt;SelectedAuthenticationIdentityStores&lt;/TD&gt;
&lt;TD width="67%"&gt;Guest Users&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;TABLE class="content_table" border="0"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="33%"&gt;EapChainingResult&lt;/TD&gt;
&lt;TD width="67%"&gt;User succeeded and &lt;STRONG&gt;machine failed&lt;/STRONG&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;TABLE class="content_table_steps" border="0" cellpadding="3"&gt;
&lt;TBODY&gt;
&lt;TR class=""&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;12219&lt;/TD&gt;
&lt;TD&gt;Selected identity type 'Machine'&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR class=""&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;12125&lt;/TD&gt;
&lt;TD&gt;EAP-FAST inner method started&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR class=""&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;11521&lt;/TD&gt;
&lt;TD&gt;Prepared EAP-Request/Identity for inner EAP method&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR class=""&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;12105&lt;/TD&gt;
&lt;TD&gt;Prepared EAP-Request with another EAP-FAST challenge&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR class="content_table_steps_highlight"&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;11006&lt;/TD&gt;
&lt;TD&gt;Returned RADIUS Access-Challenge&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR class=""&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;11001&lt;/TD&gt;
&lt;TD&gt;Received RADIUS Access-Request&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR class=""&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;11018&lt;/TD&gt;
&lt;TD&gt;RADIUS is re-using an existing session&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR class=""&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;12104&lt;/TD&gt;
&lt;TD&gt;Extracted EAP-Response containing EAP-FAST challenge-response&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR class=""&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;12213&lt;/TD&gt;
&lt;TD&gt;Identity type provided by client is not equal to requested type&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR class=""&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;12216&lt;/TD&gt;
&lt;TD&gt;Identity type provided by client was already used for authentication&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR class=""&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;12967&lt;/TD&gt;
&lt;TD&gt;Sent EAP Intermediate Result TLV indicating failure&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR class=""&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;12105&lt;/TD&gt;
&lt;TD&gt;Prepared EAP-Request with another EAP-FAST challenge&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR class=""&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;11006&lt;/TD&gt;
&lt;TD&gt;Returned RADIUS Access-Challenge&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR class=""&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;11001&lt;/TD&gt;
&lt;TD&gt;Received RADIUS Access-Request&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR class=""&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;11018&lt;/TD&gt;
&lt;TD&gt;RADIUS is re-using an existing session&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR class=""&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;12104&lt;/TD&gt;
&lt;TD&gt;Extracted EAP-Response containing EAP-FAST challenge-response&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR class=""&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;24715&lt;/TD&gt;
&lt;TD&gt;ISE has not confirmed locally previous successful machine authentication for user in Active Directory&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;A don`t understand what I`m doing wrong.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks in advance,&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Tue, 21 Aug 2018 11:48:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-chaining-with-internal-id-stores/m-p/3692107#M508057</guid>
      <dc:creator>tommy182</dc:creator>
      <dc:date>2018-08-21T11:48:59Z</dc:date>
    </item>
    <item>
      <title>Re: EAP-chaining with internal ID stores</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-chaining-with-internal-id-stores/m-p/3692264#M508058</link>
      <description>&lt;P&gt;This is not a supported setup as EAP-Chaining is for Windows environment ATM. Remember that machine authentication requires domain joined machine to function properly, which is not possible with ISE internal database. You&amp;nbsp;may be able to fake machine authentication using machine certificate to bypass domain join requirement and make it work, but still not an orthodox setup.&lt;/P&gt;
&lt;P&gt;Can you provide why you are looking for such setup?&lt;/P&gt;</description>
      <pubDate>Tue, 21 Aug 2018 15:19:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-chaining-with-internal-id-stores/m-p/3692264#M508058</guid>
      <dc:creator>howon</dc:creator>
      <dc:date>2018-08-21T15:19:35Z</dc:date>
    </item>
    <item>
      <title>Re: EAP-chaining with internal ID stores</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-chaining-with-internal-id-stores/m-p/3692285#M508059</link>
      <description>&lt;P&gt;Thanks for your reference.&lt;/P&gt;
&lt;P&gt;Actually there is no real reason to do this, I was only doing this because of temporary disabled CA role in our DC.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Again, thanks, It looks like I didn`t complete realize how chaining works(and generated this strange topic:)).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Tue, 21 Aug 2018 15:41:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-chaining-with-internal-id-stores/m-p/3692285#M508059</guid>
      <dc:creator>tommy182</dc:creator>
      <dc:date>2018-08-21T15:41:51Z</dc:date>
    </item>
  </channel>
</rss>

