<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ISE Dynamic VLAN with Microsoft AD in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-dynamic-vlan-with-microsoft-ad/m-p/3429531#M536383</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;DIV&gt;&lt;P&gt;Hi howon, &lt;/P&gt;&lt;P&gt;Thanks for your advice. &lt;/P&gt;&lt;P&gt;If the endpoint do machine authentication to domain controller, how it can be done without an IP address? &lt;/P&gt;&lt;P&gt;Have you try this before?&lt;/P&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 25 Jan 2017 16:54:12 GMT</pubDate>
    <dc:creator>Kevin Raditheo</dc:creator>
    <dc:date>2017-01-25T16:54:12Z</dc:date>
    <item>
      <title>Cisco ISE Dynamic VLAN with Microsoft AD</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-dynamic-vlan-with-microsoft-ad/m-p/3429529#M536380</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;DIV&gt;&lt;P&gt;Hi all, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I want to ask some questions. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Currently I'm using Cisco ISE for dynamic vlan assignment based on group on AD. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem I'm facing is, the user will only get IP address after they put username and password in dot1x supplicant. But sometimes, some user need to contact their domain controller for their windows login and this happens before the endpoint get an IP address. So the endpoint can't contact their DC. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any suggestions for this case? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you very much for your advice.&lt;/P&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Jan 2017 15:13:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-dynamic-vlan-with-microsoft-ad/m-p/3429529#M536380</guid>
      <dc:creator>Kevin Raditheo</dc:creator>
      <dc:date>2017-01-25T15:13:02Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Dynamic VLAN with Microsoft AD</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-dynamic-vlan-with-microsoft-ad/m-p/3429530#M536381</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When user is not logged in, typically the Windows Supplicant is configured to do machine authentication. You will need to create a policy that allows AD 'Domain Computers' Group to have access to the Domain controllers to let the endpoints contact domain controllers.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Jan 2017 16:01:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-dynamic-vlan-with-microsoft-ad/m-p/3429530#M536381</guid>
      <dc:creator>howon</dc:creator>
      <dc:date>2017-01-25T16:01:01Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Dynamic VLAN with Microsoft AD</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-dynamic-vlan-with-microsoft-ad/m-p/3429531#M536383</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;DIV&gt;&lt;P&gt;Hi howon, &lt;/P&gt;&lt;P&gt;Thanks for your advice. &lt;/P&gt;&lt;P&gt;If the endpoint do machine authentication to domain controller, how it can be done without an IP address? &lt;/P&gt;&lt;P&gt;Have you try this before?&lt;/P&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Jan 2017 16:54:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-dynamic-vlan-with-microsoft-ad/m-p/3429531#M536383</guid>
      <dc:creator>Kevin Raditheo</dc:creator>
      <dc:date>2017-01-25T16:54:12Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Dynamic VLAN with Microsoft AD</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-dynamic-vlan-with-microsoft-ad/m-p/3429532#M536384</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just like you authenticate AD user via 802.1x, you can authenticate AD joined machine (computer) to authenticate via 802.1x. It is configurable in the supplicant. Make sure it is set to 'User or Computer authentication' which is the default. Since this is 802.1x authentication it happens at OSI layer 2 without IP. See supplicant setting below on Windows:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Screen Shot 2017-01-25 at 11.05.01 AM.png" class="image-1 jive-image" src="/legacyfs/online/fusion/104082_Screen Shot 2017-01-25 at 11.05.01 AM.png" style="height: 706px; width: 620px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Jan 2017 17:07:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-dynamic-vlan-with-microsoft-ad/m-p/3429532#M536384</guid>
      <dc:creator>howon</dc:creator>
      <dc:date>2017-01-25T17:07:26Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Dynamic VLAN with Microsoft AD</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-dynamic-vlan-with-microsoft-ad/m-p/3429533#M536385</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;DIV&gt;&lt;P&gt;Thank howon, &lt;/P&gt;&lt;P&gt;I think I get it. So the endpoint will authenticate with its machine name through ISE and ISE will query the AD just like user authentication, right? &lt;/P&gt;&lt;P&gt;So I will need a policy with a condition like, if the user is domain computer or something like that. &lt;/P&gt;&lt;P&gt;How about the policy result? Must I put default permit access or can I restrict the traffic with an ACL so it can only contact the DC but not anything else?&lt;/P&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Jan 2017 17:24:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-dynamic-vlan-with-microsoft-ad/m-p/3429533#M536385</guid>
      <dc:creator>Kevin Raditheo</dc:creator>
      <dc:date>2017-01-25T17:24:54Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Dynamic VLAN with Microsoft AD</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-dynamic-vlan-with-microsoft-ad/m-p/3429534#M536386</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, typically you would allow access to AD related IP only + DHCP &amp;amp; DNS.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Jan 2017 17:27:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-dynamic-vlan-with-microsoft-ad/m-p/3429534#M536386</guid>
      <dc:creator>howon</dc:creator>
      <dc:date>2017-01-25T17:27:47Z</dc:date>
    </item>
  </channel>
</rss>

