<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: auto remediation (certs) with APEX licence and anyconnect agent in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/auto-remediation-certs-with-apex-licence-and-anyconnect-agent/m-p/3557300#M508866</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The people I copied were partners that might have shared their feedback. That’s all we have.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 28 Jun 2018 17:49:38 GMT</pubDate>
    <dc:creator>Jason Kunst</dc:creator>
    <dc:date>2018-06-28T17:49:38Z</dc:date>
    <item>
      <title>auto remediation (certs) with APEX licence and anyconnect agent</title>
      <link>https://community.cisco.com/t5/network-access-control/auto-remediation-certs-with-apex-licence-and-anyconnect-agent/m-p/3557294#M508860</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have been thrown a question prior to ISE deployment in our organization. Soon we will have dot1x on every port of all user and things facing switches and authentication will be via ISE infrastructure.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now among other things corporate desktops and laptops will be authenticated using PKI framework based machine certificates , wherein ISE will forward the query to corporate CA server for verification .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now the requirement is , for the corporate machine which has , lets say , missing or expired or corrupted certificates , by default they wont be authenticated and perhaps provided a internet only VLAN, but since those belong to actual corporate users we like to auto-remidiate the situation without having to remove the dot1x and installing certificates or may be even sending someone to put in certificates manually or taking them to staging areas.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can apex licence in conjugation with any connect client help there ?&amp;nbsp; As i saw there was remediation scenario documentation for things like patches , anti virus etc , but nothing specfic to auto remediation of certificates .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is that possible ? if yes, how ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 24 Jun 2018 06:06:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/auto-remediation-certs-with-apex-licence-and-anyconnect-agent/m-p/3557294#M508860</guid>
      <dc:creator>vark00001</dc:creator>
      <dc:date>2018-06-24T06:06:29Z</dc:date>
    </item>
    <item>
      <title>Re: auto remediation (certs) with APEX licence and anyconnect agent</title>
      <link>https://community.cisco.com/t5/network-access-control/auto-remediation-certs-with-apex-licence-and-anyconnect-agent/m-p/3557295#M508861</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Few things to consider for expired certificate: &lt;/P&gt;&lt;P&gt;- In general corporate PKI (Especially if using MS CA), you can configure the CA server to issue certificates when the expiry date is near. This can be configured from MS CA console and is recommended. As long as the users are connecting the PC often enough before expiry, the machine should always have valid certificate&lt;/P&gt;&lt;P&gt;- Now, if you still want to address expired certificate consider following options:&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;1. If you want to allow expired certificates to authenticate then you can modify the 'Allowed protocols' for EAP-TLS to allow expired certificates. However, instead of providing full access, you can limit access to web portal where the user is instructed to take action to renew certificate.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;2. I&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;t is generally not recommended to allow expired certificates to be authenticated due to security reasons. Better option is to use 'CERTIFICATE:DAYSTOEXPIRY' authorization condition to trigger user action when the certificate is near expiry.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;3. You can simply deny access for expired certificate and redirect user to login via web portal using username and password&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;For above options, you don't need any Apex license as you are only leveraging basic RADIUS authentication.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Hosuk&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Jun 2018 17:21:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/auto-remediation-certs-with-apex-licence-and-anyconnect-agent/m-p/3557295#M508861</guid>
      <dc:creator>howon</dc:creator>
      <dc:date>2018-06-25T17:21:18Z</dc:date>
    </item>
    <item>
      <title>Re: auto remediation (certs) with APEX licence and anyconnect agent</title>
      <link>https://community.cisco.com/t5/network-access-control/auto-remediation-certs-with-apex-licence-and-anyconnect-agent/m-p/3557296#M508862</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Hosuk,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The suggestions here do answer questions for expired certificate , but what can be a good suggestion for machines with no certificates. Imagine we have ordered 10 new machines and those get the image and other software's from a local SCCM server .&lt;/P&gt;&lt;P&gt;Today this is not a problem , since there is no dot1x on ports , so a new&amp;nbsp; machine does a DHCP , get their SCCM server IP , get&amp;nbsp; image and along with that a certificate is issued by scripts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If in future after we establish ISE infrastructure with dot1x on all ports and we are trying to set up these 10 machines , they will not have anything to supply for EAPoL. What will we do in those case, some options are :-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-&amp;gt; remove dot1x temprorily , let them image and get certificates and then apply back DOT1X ( Very manual and prone to ports being left non-dot1x )&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&amp;gt; Stage the machines at designated location with no dot1x and then connect to LAN ( This will add logistics cost )&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&amp;gt; May be authenticate via MAB and then let it get imaged with access to SCCM's only and then do a COA for full access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What to other companies do to handle such situations ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Jun 2018 12:21:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/auto-remediation-certs-with-apex-licence-and-anyconnect-agent/m-p/3557296#M508862</guid>
      <dc:creator>vark00001</dc:creator>
      <dc:date>2018-06-26T12:21:58Z</dc:date>
    </item>
    <item>
      <title>Re: auto remediation (certs) with APEX licence and anyconnect agent</title>
      <link>https://community.cisco.com/t5/network-access-control/auto-remediation-certs-with-apex-licence-and-anyconnect-agent/m-p/3557297#M508863</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: UICTFontTextStyleBody; font-size: 17px;"&gt;Would recommend last 2 options. Likely others from partners will chime in like&amp;nbsp; &lt;A href="https://community.cisco.com/docs/DOC-5661"&gt;berbee&lt;/A&gt; &lt;A href="https://community.cisco.com//u1/376521"&gt;arne.bier&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Jun 2018 12:27:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/auto-remediation-certs-with-apex-licence-and-anyconnect-agent/m-p/3557297#M508863</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-06-26T12:27:02Z</dc:date>
    </item>
    <item>
      <title>Re: auto remediation (certs) with APEX licence and anyconnect agent</title>
      <link>https://community.cisco.com/t5/network-access-control/auto-remediation-certs-with-apex-licence-and-anyconnect-agent/m-p/3557298#M508864</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Jason !!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;would really appreciate real life experiences with this scenario.how are new machines handled generally.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;certainly we are not the only organization with the dilemma.i am sure lot of companies order machines in their office and then &lt;/P&gt;&lt;P&gt;use SCCM for imaging. If the ports are dot1xed , then it will be like a chicken and egg problem.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Jun 2018 16:52:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/auto-remediation-certs-with-apex-licence-and-anyconnect-agent/m-p/3557298#M508864</guid>
      <dc:creator>vark00001</dc:creator>
      <dc:date>2018-06-26T16:52:20Z</dc:date>
    </item>
    <item>
      <title>Re: auto remediation (certs) with APEX licence and anyconnect agent</title>
      <link>https://community.cisco.com/t5/network-access-control/auto-remediation-certs-with-apex-licence-and-anyconnect-agent/m-p/3557299#M508865</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jason ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Did you manage to find any feedback on this ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Jun 2018 03:11:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/auto-remediation-certs-with-apex-licence-and-anyconnect-agent/m-p/3557299#M508865</guid>
      <dc:creator>vark00001</dc:creator>
      <dc:date>2018-06-28T03:11:14Z</dc:date>
    </item>
    <item>
      <title>Re: auto remediation (certs) with APEX licence and anyconnect agent</title>
      <link>https://community.cisco.com/t5/network-access-control/auto-remediation-certs-with-apex-licence-and-anyconnect-agent/m-p/3557300#M508866</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The people I copied were partners that might have shared their feedback. That’s all we have.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Jun 2018 17:49:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/auto-remediation-certs-with-apex-licence-and-anyconnect-agent/m-p/3557300#M508866</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-06-28T17:49:38Z</dc:date>
    </item>
    <item>
      <title>Re: auto remediation (certs) with APEX licence and anyconnect agent</title>
      <link>https://community.cisco.com/t5/network-access-control/auto-remediation-certs-with-apex-licence-and-anyconnect-agent/m-p/3557301#M508867</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jason ,&lt;/P&gt;&lt;P&gt;I actually found interesting line from Aaron woland in his famous&amp;nbsp; book and its version 2 at page 271 , at least for expired certs , there seems to be an inbuilt feature&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;IMG alt="cert.JPG" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/118149_cert.JPG" style="height: 296px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am still trying to brainstorm what to do with brand new machines.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jul 2018 03:14:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/auto-remediation-certs-with-apex-licence-and-anyconnect-agent/m-p/3557301#M508867</guid>
      <dc:creator>vark00001</dc:creator>
      <dc:date>2018-07-05T03:14:06Z</dc:date>
    </item>
    <item>
      <title>Re: auto remediation (certs) with APEX licence and anyconnect agent</title>
      <link>https://community.cisco.com/t5/network-access-control/auto-remediation-certs-with-apex-licence-and-anyconnect-agent/m-p/3557302#M508868</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Not all client OS's would present an expired certificate for EAP-TLS. For example, Windows clients do not.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jul 2018 04:29:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/auto-remediation-certs-with-apex-licence-and-anyconnect-agent/m-p/3557302#M508868</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-07-05T04:29:39Z</dc:date>
    </item>
    <item>
      <title>Re: auto remediation (certs) with APEX licence and anyconnect agent</title>
      <link>https://community.cisco.com/t5/network-access-control/auto-remediation-certs-with-apex-licence-and-anyconnect-agent/m-p/3557303#M508869</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The case with new machines will be that they will not hand out any certificates even though the profiling will figure out based on DHCP , or other profiler's that at least the hardware is of corporate type . like HP model xx-yy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So i am thinking of policy that say "match hardware type -corporate" and if they dont have certificates , give them access to only AD and SCCM servers and let them get a certificate and then do a COA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any thaught on if that can work ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Jul 2018 02:36:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/auto-remediation-certs-with-apex-licence-and-anyconnect-agent/m-p/3557303#M508869</guid>
      <dc:creator>vark00001</dc:creator>
      <dc:date>2018-07-06T02:36:41Z</dc:date>
    </item>
    <item>
      <title>Re: auto remediation (certs) with APEX licence and anyconnect agent</title>
      <link>https://community.cisco.com/t5/network-access-control/auto-remediation-certs-with-apex-licence-and-anyconnect-agent/m-p/3557304#M508870</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello HSLAI ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any comments if this idea can work ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 08 Jul 2018 14:42:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/auto-remediation-certs-with-apex-licence-and-anyconnect-agent/m-p/3557304#M508870</guid>
      <dc:creator>vark00001</dc:creator>
      <dc:date>2018-07-08T14:42:27Z</dc:date>
    </item>
    <item>
      <title>Re: auto remediation (certs) with APEX licence and anyconnect agent</title>
      <link>https://community.cisco.com/t5/network-access-control/auto-remediation-certs-with-apex-licence-and-anyconnect-agent/m-p/3557305#M508871</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sure, if the AD is also serving as DNS and DHCP, as well as the CA services.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 08 Jul 2018 17:48:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/auto-remediation-certs-with-apex-licence-and-anyconnect-agent/m-p/3557305#M508871</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-07-08T17:48:21Z</dc:date>
    </item>
    <item>
      <title>Re: auto remediation (certs) with APEX licence and anyconnect agent</title>
      <link>https://community.cisco.com/t5/network-access-control/auto-remediation-certs-with-apex-licence-and-anyconnect-agent/m-p/3557306#M508872</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Nops , DNS and DHCP are based on completely different product - infoblocks . Though AD has the CA&amp;nbsp; services running.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Jul 2018 03:38:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/auto-remediation-certs-with-apex-licence-and-anyconnect-agent/m-p/3557306#M508872</guid>
      <dc:creator>vark00001</dc:creator>
      <dc:date>2018-07-09T03:38:17Z</dc:date>
    </item>
    <item>
      <title>Re: auto remediation (certs) with APEX licence and anyconnect agent</title>
      <link>https://community.cisco.com/t5/network-access-control/auto-remediation-certs-with-apex-licence-and-anyconnect-agent/m-p/3557307#M508873</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Then, DNS and DHCP need allowed, as well. Or, at least DNS, if the endpoints are using static IP.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Jul 2018 12:33:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/auto-remediation-certs-with-apex-licence-and-anyconnect-agent/m-p/3557307#M508873</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-07-09T12:33:36Z</dc:date>
    </item>
  </channel>
</rss>

