<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Limitations of Windows Supplicant with 802.1x in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/limitations-of-windows-supplicant-with-802-1x/m-p/3541934#M536735</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The question is have is surrounding EAP Chaining and the use of the Any Connect NAM module vs the Windows Supplicant.&amp;nbsp;&amp;nbsp; The introduction of the Any Connect NAM could prove to be challenge in this environment, however customer would like to authenticate both the machine and user through Microsoft Active Directory.&amp;nbsp; I have learned that without EAP chaining the machine has a tendency not to re-authenticate when the machine sleeps and then requires a reboot.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Since the customer engineers are currently comfortable with the Windows Supplicant I am looking for a creative way to authenticate both the user and the machine without deploying the Any Connect NAM. Using EAP-PEAP has some limitations within the Windows Supplicant (authenticate user OR computer).&amp;nbsp; I have been labing policies leveraging Profiling to glean unique information about the devices to identify them as corp assets. I.e. Host name in the DHCP probe.&amp;nbsp; While this is not as secure as the certificate issued by AD when the machine joined the domain this does offer a form of machine authentication that doesn't rely on the Supplicant to send both machine and user credentials.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My question is: How are others solving the limitations of the supplicants that do not support EAP-FAST for 802.1x wired and wireless deployments?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 08 Dec 2016 16:57:23 GMT</pubDate>
    <dc:creator>chatataridge</dc:creator>
    <dc:date>2016-12-08T16:57:23Z</dc:date>
    <item>
      <title>Limitations of Windows Supplicant with 802.1x</title>
      <link>https://community.cisco.com/t5/network-access-control/limitations-of-windows-supplicant-with-802-1x/m-p/3541934#M536735</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The question is have is surrounding EAP Chaining and the use of the Any Connect NAM module vs the Windows Supplicant.&amp;nbsp;&amp;nbsp; The introduction of the Any Connect NAM could prove to be challenge in this environment, however customer would like to authenticate both the machine and user through Microsoft Active Directory.&amp;nbsp; I have learned that without EAP chaining the machine has a tendency not to re-authenticate when the machine sleeps and then requires a reboot.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Since the customer engineers are currently comfortable with the Windows Supplicant I am looking for a creative way to authenticate both the user and the machine without deploying the Any Connect NAM. Using EAP-PEAP has some limitations within the Windows Supplicant (authenticate user OR computer).&amp;nbsp; I have been labing policies leveraging Profiling to glean unique information about the devices to identify them as corp assets. I.e. Host name in the DHCP probe.&amp;nbsp; While this is not as secure as the certificate issued by AD when the machine joined the domain this does offer a form of machine authentication that doesn't rely on the Supplicant to send both machine and user credentials.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My question is: How are others solving the limitations of the supplicants that do not support EAP-FAST for 802.1x wired and wireless deployments?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Dec 2016 16:57:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/limitations-of-windows-supplicant-with-802-1x/m-p/3541934#M536735</guid>
      <dc:creator>chatataridge</dc:creator>
      <dc:date>2016-12-08T16:57:23Z</dc:date>
    </item>
    <item>
      <title>Re: Limitations of Windows Supplicant with 802.1x</title>
      <link>https://community.cisco.com/t5/network-access-control/limitations-of-windows-supplicant-with-802-1x/m-p/3541935#M536737</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The problem is that windows supplicant will only send the user credentials when you are in the user space. So if for some reason you went to sleep and your authentication expired then when it came alive it would not be able to send machine+user auth.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Another option is to use machine certs only and then redirect to a CWA portal for them to do the user authentication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For future you can push Microsoft to support TEAP&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Dec 2016 18:53:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/limitations-of-windows-supplicant-with-802-1x/m-p/3541935#M536737</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2016-12-08T18:53:12Z</dc:date>
    </item>
    <item>
      <title>Re: Limitations of Windows Supplicant with 802.1x</title>
      <link>https://community.cisco.com/t5/network-access-control/limitations-of-windows-supplicant-with-802-1x/m-p/3541936#M536739</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In addition to what Jason noted, with profiling, ISE 2.1 added AD probe where existence in AD can be used to identify corporate assets. The profiling attribute is in profiling policy; ACTIVEDIRECTORY_PROBE -&amp;gt; AD-Host-Exists. Once you create policy with this to put matching endpoints to endpoint group, you can use that during authorization policy.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Dec 2016 19:29:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/limitations-of-windows-supplicant-with-802-1x/m-p/3541936#M536739</guid>
      <dc:creator>howon</dc:creator>
      <dc:date>2016-12-08T19:29:46Z</dc:date>
    </item>
    <item>
      <title>Re: Limitations of Windows Supplicant with 802.1x</title>
      <link>https://community.cisco.com/t5/network-access-control/limitations-of-windows-supplicant-with-802-1x/m-p/3541937#M536740</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;howon&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you, I had not found this new profile policy attribute. I have a few more questions: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Will the AD probe work with wireless and wired clients?&amp;nbsp; &lt;/P&gt;&lt;P&gt;What is the AD probe using to match the client to AD membership? &lt;/P&gt;&lt;P&gt;What Profiling services are needed? DHCP, HTTP, RADIUS, NMAP, DNS and SNMPQUERRY&lt;/P&gt;&lt;P&gt;Is there an aging timmer for profiled endpoint groups?&lt;/P&gt;&lt;P&gt;Would the expression read:&amp;nbsp; &lt;SPAN style="color: #3d3d3d; font-family: arial; font-size: 12px;"&gt;AD-Host-Exists equals&amp;nbsp; "TRUE"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Len&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Dec 2016 20:37:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/limitations-of-windows-supplicant-with-802-1x/m-p/3541937#M536740</guid>
      <dc:creator>chatataridge</dc:creator>
      <dc:date>2016-12-08T20:37:21Z</dc:date>
    </item>
    <item>
      <title>Re: Limitations of Windows Supplicant with 802.1x</title>
      <link>https://community.cisco.com/t5/network-access-control/limitations-of-windows-supplicant-with-802-1x/m-p/3541938#M536741</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jason&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes it would be great if Microsoft and Apple would deploy a supplicant that offers both machine and user credentials.&amp;nbsp; I have suggested the CWA redirect, however they customer is looking for a solution that dosnt require end user interaction. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Len&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Dec 2016 20:40:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/limitations-of-windows-supplicant-with-802-1x/m-p/3541938#M536741</guid>
      <dc:creator>chatataridge</dc:creator>
      <dc:date>2016-12-08T20:40:45Z</dc:date>
    </item>
    <item>
      <title>Re: Limitations of Windows Supplicant with 802.1x</title>
      <link>https://community.cisco.com/t5/network-access-control/limitations-of-windows-supplicant-with-802-1x/m-p/3714377#M536745</link>
      <description>&lt;P&gt;Hi Expert,&lt;/P&gt;
&lt;P&gt;I am also looking for some way to identify the corporate assets without using AnyConnect.&lt;/P&gt;
&lt;P&gt;Please can you elaborate more on the AD probe and how to use it ?? whether in authentication or authorization.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please help. Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Sep 2018 15:00:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/limitations-of-windows-supplicant-with-802-1x/m-p/3714377#M536745</guid>
      <dc:creator>Shivaprasad Gudsi</dc:creator>
      <dc:date>2018-09-27T15:00:50Z</dc:date>
    </item>
  </channel>
</rss>

