<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Dual authentication without EAP Chaining/EAP FastV2 using ISE &amp; Meraki in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/dual-authentication-without-eap-chaining-eap-fastv2-using-ise/m-p/3567108#M518009</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The network gear doesn’t matter. Either is supports dot1x or it doesn’t. There is no temporary agent that does EAP chaining. Its part of the anyconnect NAM (which is a persistent supplicant). There is also the TEAP standard that we are asking Microsoft and Apple to implement in their supplicants. Please have your customer request this through them.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What about doing Machine &amp;amp; User Auth with Microsoft native supplicant using MAR caching? Keep in mind this doesn't work with Fast USER Switching (known microsoft issue of only authenticating the first user on dot1x and not supplicant)&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine-software/200388-Understanding-Machine-Access-Restriction.html"&gt;https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine-software/200388-Understanding-Machine-Access-Restriction.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/lan-switching/8021x/116516-problemsolution-technology-00.html"&gt;https://www.cisco.com/c/en/us/support/docs/lan-switching/8021x/116516-problemsolution-technology-00.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Some partners &lt;A href="https://community.cisco.com/docs/DOC-5661"&gt;berbee&lt;/A&gt; like do advocate machine auth only i believe and then you can do what is called CWA chaining. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 07 Feb 2018 16:16:33 GMT</pubDate>
    <dc:creator>Jason Kunst</dc:creator>
    <dc:date>2018-02-07T16:16:33Z</dc:date>
    <item>
      <title>Dual authentication without EAP Chaining/EAP FastV2 using ISE &amp; Meraki</title>
      <link>https://community.cisco.com/t5/network-access-control/dual-authentication-without-eap-chaining-eap-fastv2-using-ise/m-p/3567107#M518007</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am looking to deploy a Meraki switch and AP network but the client wants to be able to authenticate both machine and user (equivalent to EAP Chaining).&amp;nbsp;&amp;nbsp; We are looking to deploy ISE 2.2 or 2.3 as the authentication server.&amp;nbsp; The client does not want to deploy any additional software to their machines but would accept a temporary agent if necessary.&amp;nbsp;&amp;nbsp; Are there any suggestions on how this can be achieved in a Meraki environment.....&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Feb 2018 15:57:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dual-authentication-without-eap-chaining-eap-fastv2-using-ise/m-p/3567107#M518007</guid>
      <dc:creator>c.newcombe</dc:creator>
      <dc:date>2018-02-07T15:57:00Z</dc:date>
    </item>
    <item>
      <title>Re: Dual authentication without EAP Chaining/EAP FastV2 using ISE &amp; Meraki</title>
      <link>https://community.cisco.com/t5/network-access-control/dual-authentication-without-eap-chaining-eap-fastv2-using-ise/m-p/3567108#M518009</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The network gear doesn’t matter. Either is supports dot1x or it doesn’t. There is no temporary agent that does EAP chaining. Its part of the anyconnect NAM (which is a persistent supplicant). There is also the TEAP standard that we are asking Microsoft and Apple to implement in their supplicants. Please have your customer request this through them.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What about doing Machine &amp;amp; User Auth with Microsoft native supplicant using MAR caching? Keep in mind this doesn't work with Fast USER Switching (known microsoft issue of only authenticating the first user on dot1x and not supplicant)&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine-software/200388-Understanding-Machine-Access-Restriction.html"&gt;https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine-software/200388-Understanding-Machine-Access-Restriction.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/lan-switching/8021x/116516-problemsolution-technology-00.html"&gt;https://www.cisco.com/c/en/us/support/docs/lan-switching/8021x/116516-problemsolution-technology-00.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Some partners &lt;A href="https://community.cisco.com/docs/DOC-5661"&gt;berbee&lt;/A&gt; like do advocate machine auth only i believe and then you can do what is called CWA chaining. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Feb 2018 16:16:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dual-authentication-without-eap-chaining-eap-fastv2-using-ise/m-p/3567108#M518009</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-02-07T16:16:33Z</dc:date>
    </item>
  </channel>
</rss>

