<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Authentication Open on switch Vs EAP chaining with user and machine certificate in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/authentication-open-on-switch-vs-eap-chaining-with-user-and/m-p/3594889#M517317</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I usually don't do EAP chaining, but you should be able to setup a secondary wired profile that just does EAP-TLS Computer authentication.&amp;nbsp; If I am doing certificate authentication, I don't do EAP chaining and setup 3 NAM wired profiles:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Priority #1- User or Computer EAP-TLS&lt;/P&gt;&lt;P&gt;Priority #2- Computer EAP-TLS&lt;/P&gt;&lt;P&gt;Priority #3- no authentication&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Priority #2 is there to handle the issue you are seeing, i.e. first time user logon to a machine and the user certificate hasn't autoenrolled yet.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 13 Apr 2018 15:55:56 GMT</pubDate>
    <dc:creator>paul</dc:creator>
    <dc:date>2018-04-13T15:55:56Z</dc:date>
    <item>
      <title>Authentication Open on switch Vs EAP chaining with user and machine certificate</title>
      <link>https://community.cisco.com/t5/network-access-control/authentication-open-on-switch-vs-eap-chaining-with-user-and/m-p/3594888#M517314</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am deploying ISE 2.2 patch 6in production at one my customers and having a query regarding monitor mode and eap chaining.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Components used:&lt;/P&gt;&lt;P&gt;ISE 2.2 P6&lt;/P&gt;&lt;P&gt;AnyConnect NAM 4.5.x&lt;/P&gt;&lt;P&gt;Dot1x Authentication - user and machine certificate authentication&lt;/P&gt;&lt;P&gt;Switch Deployment - Monitor mode&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;EAP Chaining (certificate authentication) is working fine with following scenarios:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG style="text-decoration: underline;"&gt;user and machine both succeeded&lt;/STRONG&gt;: observed the expected behavior as per the policies configured in ISE.&lt;/LI&gt;&lt;LI&gt;&lt;STRONG style="text-decoration: underline;"&gt;user succeeded and machine failed&lt;/STRONG&gt;: Machine certificate is not present on endpoint, only user certificate is present. However in this scenario the endpoint is getting access as per ISE policies.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But EAP chaining (certificate authentication) is not working with following scenario:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;user failed and machine succeeded&lt;/STRONG&gt;&lt;/SPAN&gt;: In this scenario user certificate is not present in this endpoint. AnyConnect NAM is popping up a dialogue for selecting a user certificate, we are not able to select anything as there is no user certificate present on endpoint and hence we are not getting network access, even if switch port is in authentication open mode&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please let me know if this is the expected behavior of AnyConnect NAM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;P&gt;Sadashiv&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Apr 2018 10:49:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authentication-open-on-switch-vs-eap-chaining-with-user-and/m-p/3594888#M517314</guid>
      <dc:creator>sadashivpalde</dc:creator>
      <dc:date>2018-04-13T10:49:56Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication Open on switch Vs EAP chaining with user and machine certificate</title>
      <link>https://community.cisco.com/t5/network-access-control/authentication-open-on-switch-vs-eap-chaining-with-user-and/m-p/3594889#M517317</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I usually don't do EAP chaining, but you should be able to setup a secondary wired profile that just does EAP-TLS Computer authentication.&amp;nbsp; If I am doing certificate authentication, I don't do EAP chaining and setup 3 NAM wired profiles:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Priority #1- User or Computer EAP-TLS&lt;/P&gt;&lt;P&gt;Priority #2- Computer EAP-TLS&lt;/P&gt;&lt;P&gt;Priority #3- no authentication&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Priority #2 is there to handle the issue you are seeing, i.e. first time user logon to a machine and the user certificate hasn't autoenrolled yet.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Apr 2018 15:55:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authentication-open-on-switch-vs-eap-chaining-with-user-and/m-p/3594889#M517317</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2018-04-13T15:55:56Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication Open on switch Vs EAP chaining with user and machine certificate</title>
      <link>https://community.cisco.com/t5/network-access-control/authentication-open-on-switch-vs-eap-chaining-with-user-and/m-p/3594890#M517320</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Paul,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your reply and workaround.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, this workaround would not be feasible in our case. My original query is related to behavior of NAM if user certificate is not present on endpoint and switch is configured in authentication open mode.&lt;/P&gt;&lt;P&gt;From the test results, it looks like endpoint / user doesn't get network access if user certificate is not present.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this the expected behavior if we are using NAM??&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Apr 2018 05:40:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authentication-open-on-switch-vs-eap-chaining-with-user-and/m-p/3594890#M517320</guid>
      <dc:creator>sadashivpalde</dc:creator>
      <dc:date>2018-04-18T05:40:55Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication Open on switch Vs EAP chaining with user and machine certificate</title>
      <link>https://community.cisco.com/t5/network-access-control/authentication-open-on-switch-vs-eap-chaining-with-user-and/m-p/3594891#M517323</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Sadashiv,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is expected behavior for NAM.&amp;nbsp; If NAM cannot find a credential, username/password, or certificate we will prompt the user for this credential.&amp;nbsp; When no credential is provide we will not respond to the request from ISE and the connection will timeout.&amp;nbsp; In you case ISE is probably reporting Endpoint abandoned EAP session....&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You may be able to use the port exception policy in NAM to help get around this.&amp;nbsp;&amp;nbsp; I am not sure in this case if ISE is sending an authentication failure.&amp;nbsp; If it is you could allow access in NM after a failed auth, or you can also allow before any authentication is performed.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps,&lt;/P&gt;&lt;P&gt;Steve S.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Apr 2018 15:04:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authentication-open-on-switch-vs-eap-chaining-with-user-and/m-p/3594891#M517323</guid>
      <dc:creator>stsargen</dc:creator>
      <dc:date>2018-04-18T15:04:36Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication Open on switch Vs EAP chaining with user and machine certificate</title>
      <link>https://community.cisco.com/t5/network-access-control/authentication-open-on-switch-vs-eap-chaining-with-user-and/m-p/3594892#M517325</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Steven,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your inputs and we also has the same observartion.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So one more query comes in my mind is, if user certificate is present and machine certificate is not present i.e, User Succeeded and Machine failed then the endpoint gets the network access in our scenario.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does this mean that NAM checks user credentials before the machine credentials?? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance!!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Apr 2018 06:05:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authentication-open-on-switch-vs-eap-chaining-with-user-and/m-p/3594892#M517325</guid>
      <dc:creator>sadashivpalde</dc:creator>
      <dc:date>2018-04-19T06:05:55Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication Open on switch Vs EAP chaining with user and machine certificate</title>
      <link>https://community.cisco.com/t5/network-access-control/authentication-open-on-switch-vs-eap-chaining-with-user-and/m-p/3594893#M517326</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Sadashiv,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NAM will provide credentials in the order that they are requested by ISE.&amp;nbsp; Is ISE actually hitting a user pass machine failed policy, or user only policy.&amp;nbsp; This would explain why you have access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Steve S.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Apr 2018 13:49:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authentication-open-on-switch-vs-eap-chaining-with-user-and/m-p/3594893#M517326</guid>
      <dc:creator>stsargen</dc:creator>
      <dc:date>2018-04-19T13:49:56Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication Open on switch Vs EAP chaining with user and machine certificate</title>
      <link>https://community.cisco.com/t5/network-access-control/authentication-open-on-switch-vs-eap-chaining-with-user-and/m-p/3594894#M517328</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I assume you followed the instructions in &lt;A href="https://community.cisco.com/docs/DOC-68163"&gt;How To: Deploy EAP Chaining with AnyConnect NAM and ISE&lt;/A&gt; ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Apr 2018 21:04:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authentication-open-on-switch-vs-eap-chaining-with-user-and/m-p/3594894#M517328</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2018-04-19T21:04:42Z</dc:date>
    </item>
  </channel>
</rss>

