<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AnyConnect NAM Machine Authentication in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/anyconnect-nam-machine-authentication/m-p/3440243#M537999</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am trying certificate for either Machine and User.&lt;/P&gt;&lt;P&gt;User Certificate works too but my customer is looking at Machine auth using certificate.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 12 Aug 2016 15:48:01 GMT</pubDate>
    <dc:creator>wileong</dc:creator>
    <dc:date>2016-08-12T15:48:01Z</dc:date>
    <item>
      <title>AnyConnect NAM Machine Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/anyconnect-nam-machine-authentication/m-p/3440239#M537995</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am testing ISE 2.1 with AC 4.3.1095 for Windows Machine authentication using certificate.&lt;/P&gt;&lt;P&gt;EAP method is EAP-FAST with EAP-TLS as inner method. &lt;/P&gt;&lt;P&gt;Authentication failed with error "&lt;SPAN style="font-weight: bold; color: #6a6a6a; font-family: arial, sans-serif; font-size: small;"&gt;5440 Endpoint&lt;/SPAN&gt;&lt;SPAN style="color: #545454; font-family: arial, sans-serif; font-size: small;"&gt; abandoned EAP session and started new."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I have also tested User auth with the same AC profile as machine and it works. Certificate can be detected by AC and I am seeing hostname is corrected identified with CN.&lt;/P&gt;&lt;P&gt;Any idea?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Wing Churn&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Aug 2016 11:54:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyconnect-nam-machine-authentication/m-p/3440239#M537995</guid>
      <dc:creator>wileong</dc:creator>
      <dc:date>2016-08-11T11:54:53Z</dc:date>
    </item>
    <item>
      <title>Re: AnyConnect NAM Machine Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/anyconnect-nam-machine-authentication/m-p/3440240#M537996</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We use 802.1x authentication and I use EAP-Chaining to do the machine/user authentication. Here is a doc, but a little different for ISE 2.1 (I also use ISE 2.1)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/c/dam/en/us/solutions/collateral/enterprise/design-zone-security/howto_80_eapchaining_deployment.pdf" title="http://www.cisco.com/c/dam/en/us/solutions/collateral/enterprise/design-zone-security/howto_80_eapchaining_deployment.pdf"&gt;http://www.cisco.com/c/dam/en/us/solutions/collateral/enterprise/design-zone-security/howto_80_eapchaining_deployment.pd…&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If this is what you are trying to do, I can try to show some of my settings if it helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Aug 2016 15:29:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyconnect-nam-machine-authentication/m-p/3440240#M537996</guid>
      <dc:creator>Dustin Anderson</dc:creator>
      <dc:date>2016-08-12T15:29:44Z</dc:date>
    </item>
    <item>
      <title>Re: AnyConnect NAM Machine Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/anyconnect-nam-machine-authentication/m-p/3440241#M537997</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I was referring to the same document and it works for "password" inner method Machine Auth. What I am trying to achieve here is Certificate as inner method.&lt;/P&gt;&lt;P&gt;Are you using certificate in your lab?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Aug 2016 15:36:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyconnect-nam-machine-authentication/m-p/3440241#M537997</guid>
      <dc:creator>wileong</dc:creator>
      <dc:date>2016-08-12T15:36:53Z</dc:date>
    </item>
    <item>
      <title>Re: AnyConnect NAM Machine Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/anyconnect-nam-machine-authentication/m-p/3440242#M537998</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;For inner method we use EAP-MSCHAPv2 since the users log in.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What we do is machine joins and sits on a restricted network, then when the user logs in it re-checks and send them to whatever network they are assigned/have permissions to.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So your users join with a cert?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Aug 2016 15:43:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyconnect-nam-machine-authentication/m-p/3440242#M537998</guid>
      <dc:creator>Dustin Anderson</dc:creator>
      <dc:date>2016-08-12T15:43:08Z</dc:date>
    </item>
    <item>
      <title>Re: AnyConnect NAM Machine Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/anyconnect-nam-machine-authentication/m-p/3440243#M537999</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am trying certificate for either Machine and User.&lt;/P&gt;&lt;P&gt;User Certificate works too but my customer is looking at Machine auth using certificate.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Aug 2016 15:48:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyconnect-nam-machine-authentication/m-p/3440243#M537999</guid>
      <dc:creator>wileong</dc:creator>
      <dc:date>2016-08-12T15:48:01Z</dc:date>
    </item>
    <item>
      <title>Re: AnyConnect NAM Machine Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/anyconnect-nam-machine-authentication/m-p/3440244#M538000</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;windows 8, 8.1, or 10?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is an issue that windows will not pass the cert unencrypted to AnyConnect. Usually you will see in the failure bad credentials. This is fixed be adding the below reg key.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Windows Registry Editor Version 5.00&lt;/P&gt;&lt;P&gt;[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]&lt;/P&gt;&lt;P&gt;"LsaAllowReturningUnencryptedSecrets"=dword:00000001&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As for Machine/user cert login, I have not done it, so not sure if it's much different from password.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Aug 2016 16:01:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyconnect-nam-machine-authentication/m-p/3440244#M538000</guid>
      <dc:creator>Dustin Anderson</dc:creator>
      <dc:date>2016-08-12T16:01:58Z</dc:date>
    </item>
    <item>
      <title>Re: AnyConnect NAM Machine Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/anyconnect-nam-machine-authentication/m-p/3440245#M538001</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Does it work if EAP-TLS auth by itself but not as an inner method of EAP-FAST? What are the auth protocol settings for the matched authentication policy?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 13 Aug 2016 02:26:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyconnect-nam-machine-authentication/m-p/3440245#M538001</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2016-08-13T02:26:18Z</dc:date>
    </item>
    <item>
      <title>Re: AnyConnect NAM Machine Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/anyconnect-nam-machine-authentication/m-p/3440246#M538002</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Same error even with EAP-TLS. I only have 1 authentication policy default with certificate profile.&lt;/P&gt;&lt;P&gt;From ISE log AnyConnect is getting the correct certificate where CN is logged for username.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 13 Aug 2016 02:38:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyconnect-nam-machine-authentication/m-p/3440246#M538002</guid>
      <dc:creator>wileong</dc:creator>
      <dc:date>2016-08-13T02:38:59Z</dc:date>
    </item>
    <item>
      <title>Re: AnyConnect NAM Machine Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/anyconnect-nam-machine-authentication/m-p/3440247#M538003</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Try using the eventvwr to look at the AnyConnect log entries.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="eventvwrNAM.PNG" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/99484_eventvwrNAM.PNG" style="height: auto; width: auto;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The user certificate might have some problem or even the AC profile because it has different sections for user auth and machine auth. If you need further help on this, try the Cisco internal alias on AnyConnect with a copy of your DART file.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Aug 2016 15:34:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyconnect-nam-machine-authentication/m-p/3440247#M538003</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2016-08-17T15:34:39Z</dc:date>
    </item>
    <item>
      <title>Re: AnyConnect NAM Machine Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/anyconnect-nam-machine-authentication/m-p/3440248#M538004</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Hsing,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the tip. Apparently, the certificate installed without private key even it showed "Certificate has associated private key" while we double clicked the certificate. EAP-TLS for machine works for Windows 7 after importing the same certificate again.&lt;/P&gt;&lt;P&gt;I will try out Windows 8.1 and Windows 10 using latest AC 4.3.02039 next week.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Wing Churn&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 20 Aug 2016 06:36:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyconnect-nam-machine-authentication/m-p/3440248#M538004</guid>
      <dc:creator>wileong</dc:creator>
      <dc:date>2016-08-20T06:36:17Z</dc:date>
    </item>
  </channel>
</rss>

