<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE and AD question when the host machine is in a certain OU. Authorization is changing when user logs in. in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-and-ad-question-when-the-host-machine-is-in-a-certain-ou/m-p/3584765#M529496</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Everyone,&lt;/P&gt;&lt;P&gt;I forgot that in the DOT1X config I could specify Computer and User, or just Computer.&lt;/P&gt;&lt;P&gt;I am going to try this first.&lt;/P&gt;&lt;P&gt;Thanks Jason &amp;amp; Paul&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Ed&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 23 May 2017 20:24:31 GMT</pubDate>
    <dc:creator>ntwkdsnr123</dc:creator>
    <dc:date>2017-05-23T20:24:31Z</dc:date>
    <item>
      <title>ISE and AD question when the host machine is in a certain OU. Authorization is changing when user logs in.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-and-ad-question-when-the-host-machine-is-in-a-certain-ou/m-p/3584760#M529488</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi There,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm trying to set up a public type kiosk that will have restricted access to certain network resources.&amp;nbsp; I have ISE 2.1 running and is currently integrated with Active Directory.&amp;nbsp; The access is going to be determined via a DACL that will get downloaded to the Cisco switch interface that the kiosk is connected to.&amp;nbsp; I am looking for a certain Organizational Unit in AD that the kiosk machine is a member of.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When the kiosk PC is booted up and authenticates via dot1x, the OU is matched and the DACL is applied to the interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;At that point the installer or tech logs into AD with a generic login on the kiosk, ISE goes down through again in our authorization policies and matches the AD user for our domain and then applies another policy, and downloads one of our standard DACLs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a way to only use the defined machine that is in AD instead of the Machine then Domain User?&amp;nbsp; Or a way to stop the process after the interface receives the correct DACL?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Ed&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 May 2017 18:16:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-and-ad-question-when-the-host-machine-is-in-a-certain-ou/m-p/3584760#M529488</guid>
      <dc:creator>ntwkdsnr123</dc:creator>
      <dc:date>2017-05-23T18:16:56Z</dc:date>
    </item>
    <item>
      <title>Re: ISE and AD question when the host machine is in a certain OU. Authorization is changing when user logs in.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-and-ad-question-when-the-host-machine-is-in-a-certain-ou/m-p/3584761#M529490</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What about machine auth only and then do cwa portal&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CWA chaining&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 May 2017 18:25:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-and-ad-question-when-the-host-machine-is-in-a-certain-ou/m-p/3584761#M529490</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2017-05-23T18:25:59Z</dc:date>
    </item>
    <item>
      <title>Re: ISE and AD question when the host machine is in a certain OU. Authorization is changing when user logs in.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-and-ad-question-when-the-host-machine-is-in-a-certain-ou/m-p/3584762#M529492</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As Jason said it sounds like you just want Computer Auth only and don't ever want the supplicant to transition to user auth.&amp;nbsp; The default settings for Windows supplicant when enabled is Computer or User.&amp;nbsp; Just go in a change the supplicant to Computer Only and you should be set.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Computer Auth.JPG" class="image-1 jive-image" src="/legacyfs/online/fusion/107775_Computer Auth.JPG" style="height: auto;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 May 2017 19:16:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-and-ad-question-when-the-host-machine-is-in-a-certain-ou/m-p/3584762#M529492</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2017-05-23T19:16:56Z</dc:date>
    </item>
    <item>
      <title>Re: ISE and AD question when the host machine is in a certain OU. Authorization is changing when user logs in.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-and-ad-question-when-the-host-machine-is-in-a-certain-ou/m-p/3584763#M529494</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;if it possible for him to do the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On ISE:&lt;/P&gt;&lt;P&gt;AuthC: if domain pc, then use AD1&lt;/P&gt;&lt;P&gt;AuthZ: if domain pc, then permit-access with dACL&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;on PC: PEAP, Computer authentication&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 May 2017 19:48:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-and-ad-question-when-the-host-machine-is-in-a-certain-ou/m-p/3584763#M529494</guid>
      <dc:creator>Ping Zhou</dc:creator>
      <dc:date>2017-05-23T19:48:22Z</dc:date>
    </item>
    <item>
      <title>Re: ISE and AD question when the host machine is in a certain OU. Authorization is changing when user logs in.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-and-ad-question-when-the-host-machine-is-in-a-certain-ou/m-p/3584764#M529495</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes but to be clear, because this is often a point of confusion with customers, you have the AuthC part wrong:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;AuthC: Valid AD credentials (computer or user)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;AuthZ: If member of Domain Computers and PEAP then permit access with dACL.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is nothing other than valid AD credential checking happening in the AuthC phase.  All the magic in ISE happens in Authz.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Paul Haferman&lt;/P&gt;&lt;P&gt;Office- 920.996.3011&lt;/P&gt;&lt;P&gt;Cell- 920.284.9250&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 May 2017 19:52:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-and-ad-question-when-the-host-machine-is-in-a-certain-ou/m-p/3584764#M529495</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2017-05-23T19:52:24Z</dc:date>
    </item>
    <item>
      <title>Re: ISE and AD question when the host machine is in a certain OU. Authorization is changing when user logs in.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-and-ad-question-when-the-host-machine-is-in-a-certain-ou/m-p/3584765#M529496</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Everyone,&lt;/P&gt;&lt;P&gt;I forgot that in the DOT1X config I could specify Computer and User, or just Computer.&lt;/P&gt;&lt;P&gt;I am going to try this first.&lt;/P&gt;&lt;P&gt;Thanks Jason &amp;amp; Paul&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Ed&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 May 2017 20:24:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-and-ad-question-when-the-host-machine-is-in-a-certain-ou/m-p/3584765#M529496</guid>
      <dc:creator>ntwkdsnr123</dc:creator>
      <dc:date>2017-05-23T20:24:31Z</dc:date>
    </item>
    <item>
      <title>Re: ISE and AD question when the host machine is in a certain OU. Authorization is changing when user logs in.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-and-ad-question-when-the-host-machine-is-in-a-certain-ou/m-p/3584766#M529497</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you do computer only then you Will loose the ability to track user logins and audit trail&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;so you could chain with CWA &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 May 2017 20:43:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-and-ad-question-when-the-host-machine-is-in-a-certain-ou/m-p/3584766#M529497</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2017-05-23T20:43:07Z</dc:date>
    </item>
    <item>
      <title>Re: ISE and AD question when the host machine is in a certain OU. Authorization is changing when user logs in.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-and-ad-question-when-the-host-machine-is-in-a-certain-ou/m-p/3584767#M529498</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Folks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I set just computer authentication under the 802.1x setting on the Windows machine.&amp;nbsp; Authentication is failing now.&amp;nbsp; In ISE details I see a 5400 Authentication failed event and a 12511 Unexpectedly received TLS alert message from the client.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The resolution suggested has to do with trusting the ISE server certificate.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Am I on the right path here? Or can it be something else?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Ed&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 May 2017 22:37:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-and-ad-question-when-the-host-machine-is-in-a-certain-ou/m-p/3584767#M529498</guid>
      <dc:creator>ntwkdsnr123</dc:creator>
      <dc:date>2017-05-24T22:37:44Z</dc:date>
    </item>
    <item>
      <title>Re: ISE and AD question when the host machine is in a certain OU. Authorization is changing when user logs in.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-and-ad-question-when-the-host-machine-is-in-a-certain-ou/m-p/3584768#M529499</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ed,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Didn’t you say that computer authentication was working before?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this computer joined to the domain?  Did you keep the setting at PEAP?  What happens when you reboot and don’t login?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Paul Haferman&lt;/P&gt;&lt;P&gt;Office- 920.996.3011&lt;/P&gt;&lt;P&gt;Cell- 920.284.9250&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 May 2017 23:17:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-and-ad-question-when-the-host-machine-is-in-a-certain-ou/m-p/3584768#M529499</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2017-05-24T23:17:59Z</dc:date>
    </item>
    <item>
      <title>Re: ISE and AD question when the host machine is in a certain OU. Authorization is changing when user logs in.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-and-ad-question-when-the-host-machine-is-in-a-certain-ou/m-p/3584769#M529500</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When testing, can you try unchecking "validate server certificate " on your PEAP setting on the windows PC? So you can tell if it's Radius server cert issue?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 May 2017 00:56:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-and-ad-question-when-the-host-machine-is-in-a-certain-ou/m-p/3584769#M529500</guid>
      <dc:creator>Ping Zhou</dc:creator>
      <dc:date>2017-05-25T00:56:54Z</dc:date>
    </item>
  </channel>
</rss>

