<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic user+machine auth question in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/user-machine-auth-question/m-p/3549558#M528586</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My question is related to ACS but your answer will fit for both ISE and ACS. &lt;/P&gt;&lt;P&gt;We configured two rules. First one is for machine auth and second one is for user auth. And we configured windows supplicant as "user and machine authentication". We are not using anyconnect.&lt;/P&gt;&lt;P&gt;I think this configuration is known as MAR.&lt;/P&gt;&lt;P&gt;In ACS logs we see TLS handshake messages. Does it apply EAP-TLS with PEAP here? Or is it just an illusion?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="image001.png" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/109043_image001.png" style="height: auto;" /&gt;&lt;IMG alt="image002.png" class="jive-image image-2" src="https://community.cisco.com/legacyfs/online/fusion/109044_image002.png" style="height: auto;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 10 Jul 2017 20:32:45 GMT</pubDate>
    <dc:creator>ozgguler</dc:creator>
    <dc:date>2017-07-10T20:32:45Z</dc:date>
    <item>
      <title>user+machine auth question</title>
      <link>https://community.cisco.com/t5/network-access-control/user-machine-auth-question/m-p/3549558#M528586</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My question is related to ACS but your answer will fit for both ISE and ACS. &lt;/P&gt;&lt;P&gt;We configured two rules. First one is for machine auth and second one is for user auth. And we configured windows supplicant as "user and machine authentication". We are not using anyconnect.&lt;/P&gt;&lt;P&gt;I think this configuration is known as MAR.&lt;/P&gt;&lt;P&gt;In ACS logs we see TLS handshake messages. Does it apply EAP-TLS with PEAP here? Or is it just an illusion?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="image001.png" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/109043_image001.png" style="height: auto;" /&gt;&lt;IMG alt="image002.png" class="jive-image image-2" src="https://community.cisco.com/legacyfs/online/fusion/109044_image002.png" style="height: auto;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Jul 2017 20:32:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/user-machine-auth-question/m-p/3549558#M528586</guid>
      <dc:creator>ozgguler</dc:creator>
      <dc:date>2017-07-10T20:32:45Z</dc:date>
    </item>
    <item>
      <title>Re: user+machine auth question</title>
      <link>https://community.cisco.com/t5/network-access-control/user-machine-auth-question/m-p/3549559#M528587</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, MAR is used with Windows native supplicant.&lt;/P&gt;&lt;P&gt;During PEAP, the client will get the EAP server certificate and then have the option to validate it. That might be what you are seeing. I can't see that in your screenshot.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Jul 2017 21:02:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/user-machine-auth-question/m-p/3549559#M528587</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2017-07-10T21:02:31Z</dc:date>
    </item>
    <item>
      <title>Re: user+machine auth question</title>
      <link>https://community.cisco.com/t5/network-access-control/user-machine-auth-question/m-p/3549560#M528588</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;But this is not a certificate authentication, right? Is it still needed to do eap chaining for real machine+user auth?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Bonus question: Are they ways to bypass MAR? For example, what happens if i imitate a domain PC's hostname on a non-domain pc?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from my iPhone&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Jul 2017 22:31:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/user-machine-auth-question/m-p/3549560#M528588</guid>
      <dc:creator>ozgguler</dc:creator>
      <dc:date>2017-07-10T22:31:40Z</dc:date>
    </item>
    <item>
      <title>Re: user+machine auth question</title>
      <link>https://community.cisco.com/t5/network-access-control/user-machine-auth-question/m-p/3549561#M528589</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;MAR typically uses password auth. If using certificates, then you need to ensure performing binary compare and use AD id store, else it would not work.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Jul 2017 22:35:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/user-machine-auth-question/m-p/3549561#M528589</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2017-07-10T22:35:46Z</dc:date>
    </item>
    <item>
      <title>Re: user+machine auth question</title>
      <link>https://community.cisco.com/t5/network-access-control/user-machine-auth-question/m-p/3549562#M528590</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please also make sure MAR is enabled in external ID store for AD&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/109052_pastedImage_0.png" style="max-width: 1200px; max-height: 900px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Jul 2017 01:33:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/user-machine-auth-question/m-p/3549562#M528590</guid>
      <dc:creator>kthiruve</dc:creator>
      <dc:date>2017-07-11T01:33:14Z</dc:date>
    </item>
  </channel>
</rss>

