<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic CWA chaining in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cwa-chaining/m-p/3585056#M518976</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello team,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have a customer that requires to check both device certificate (to prevent access of non-corporate laptops) and user identity (username and password). They don't have AD and would like to store the identity in the internal ISE DB. One of the possible solutions discussed was to chain EAP-TLS and CWA but we still have a doubt regarding group information. The attribute we use for that is CWA_ExternalGroups but would it be populated with user group if internal users DB is used for the CWA auth instead of LDAP / AD?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Viktor Kirchev&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 20 Dec 2017 15:11:10 GMT</pubDate>
    <dc:creator>vkirchev</dc:creator>
    <dc:date>2017-12-20T15:11:10Z</dc:date>
    <item>
      <title>CWA chaining</title>
      <link>https://community.cisco.com/t5/network-access-control/cwa-chaining/m-p/3585056#M518976</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello team,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have a customer that requires to check both device certificate (to prevent access of non-corporate laptops) and user identity (username and password). They don't have AD and would like to store the identity in the internal ISE DB. One of the possible solutions discussed was to chain EAP-TLS and CWA but we still have a doubt regarding group information. The attribute we use for that is CWA_ExternalGroups but would it be populated with user group if internal users DB is used for the CWA auth instead of LDAP / AD?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Viktor Kirchev&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Dec 2017 15:11:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cwa-chaining/m-p/3585056#M518976</guid>
      <dc:creator>vkirchev</dc:creator>
      <dc:date>2017-12-20T15:11:10Z</dc:date>
    </item>
    <item>
      <title>Re: CWA chaining</title>
      <link>https://community.cisco.com/t5/network-access-control/cwa-chaining/m-p/3585057#M518977</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The CWA identity is assigned the identity used to perform CWA.&amp;nbsp; It is that value which would be used for group lookup.&amp;nbsp; As the common use case is to perform lookup to one of the defined external ID stores, so not sure if specific testing performed for InternalUser&amp;gt;IdentityGroup, but would suggest trying it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Dec 2017 16:21:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cwa-chaining/m-p/3585057#M518977</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2017-12-20T16:21:17Z</dc:date>
    </item>
  </channel>
</rss>

