<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE dot1x eap-tls with logon script in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-dot1x-eap-tls-with-logon-script/m-p/3436509#M538450</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We covered this in the original answer.&lt;/P&gt;&lt;P&gt;They need to do whatever they need to do with GPO delays or Quarantine ACLs to ensure GPOs will work whenever they are invoked with whatever resources they are trying to access. Rather than deal with GPO timing delays it is probably easier to include any and all necessary file servers in their Non-Compliant/Quarantine ACL.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 08 Jul 2016 16:08:22 GMT</pubDate>
    <dc:creator>thomas</dc:creator>
    <dc:date>2016-07-08T16:08:22Z</dc:date>
    <item>
      <title>ISE dot1x eap-tls with logon script</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-dot1x-eap-tls-with-logon-script/m-p/3436504#M538442</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Dear Experts,&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Our customer has a question on ISE dot1x eat-tls with logon script as below:&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;There are two GPO : First Computer GPO and second GPO based logon script&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;execution (SMB)&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;I'm asking about the second when the user enters his active directory&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;credentials. So here the user had a DACL applied on the switch port then had&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;access to AD , DNS , DHCP and had an IP address due to SUCCESFULL MACHINE&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Authentication, so should we give him access to SMB ( providing shared&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;access to file server) in the DACL ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;We know that the GPO depends on the network connectivity .&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;When we apply the GPO (logon script ) after SUCCESFULL USER Authentication&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;on the client provisioning stage ( CPP ) . This GPO fails to be executed&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;and give us access to the file server ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;if this GPO failed due to network connectivity , what should we do to&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;prevent this failure ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Should we give him access to the file server in the DACL after machine&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;authentication and in the POSTURE STATUS UNKNOW ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Or we configure a delay for the GPO to be applied when the computer is&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;COMPLIANT ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Please help to answer. Thanks&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Yu Han&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Jun 2016 10:51:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-dot1x-eap-tls-with-logon-script/m-p/3436504#M538442</guid>
      <dc:creator>yhan2</dc:creator>
      <dc:date>2016-06-29T10:51:30Z</dc:date>
    </item>
    <item>
      <title>Re: ISE dot1x eap-tls with logon script</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-dot1x-eap-tls-with-logon-script/m-p/3436505#M538445</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If any of your ACLs prevent access to any resources needed by GPOs or logon scripts then you will have a problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Both of your options should work:&lt;/P&gt;&lt;P&gt;1) Ensure all ACLs (machine auth, compliant, non-compliant, etc.) will allow access to GPO resources&lt;/P&gt;&lt;P&gt;2) Delay your GPO until after the user has been authenticated and determined as compliant and any new ACLs applied&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Jun 2016 04:22:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-dot1x-eap-tls-with-logon-script/m-p/3436505#M538445</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2016-06-30T04:22:27Z</dc:date>
    </item>
    <item>
      <title>Re: ISE dot1x eap-tls with logon script</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-dot1x-eap-tls-with-logon-script/m-p/3436506#M538446</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px;"&gt;About roaming profile what we should do ? is there any specific &lt;/SPAN&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; line-height: 1.5em;"&gt;configuration on ISE or we will do the same as the below ?&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Jul 2016 02:00:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-dot1x-eap-tls-with-logon-script/m-p/3436506#M538446</guid>
      <dc:creator>yhan2</dc:creator>
      <dc:date>2016-07-04T02:00:46Z</dc:date>
    </item>
    <item>
      <title>Re: ISE dot1x eap-tls with logon script</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-dot1x-eap-tls-with-logon-script/m-p/3436507#M538447</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are you talking about computer roaming or user roaming?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ISE doesn't care about wireless roaming. If the WLC treats it as a new session, then ISE gets a RADIUS request.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For user roaming, if the computers are configured for user authentication, ISE will get authenticate and authorize each user login.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However if you are using Fast User Switching, ISE will not get an authentication request because Windows does not consider this a new authentication and does not trigger an 802.1X event.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Jul 2016 16:00:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-dot1x-eap-tls-with-logon-script/m-p/3436507#M538447</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2016-07-05T16:00:36Z</dc:date>
    </item>
    <item>
      <title>Re: ISE dot1x eap-tls with logon script</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-dot1x-eap-tls-with-logon-script/m-p/3436508#M538448</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;Thanks for your reply. I'm talking about user roaming in Windows for example when they applied 10 GPO on each user and &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;the purpose of those GPO's to access the fileserver. So when the user puts his windows credentials after that the GPO will &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;apply at this stage should they access to file server or should they wait to the PC to be compliant to access them ? Should &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;they see "folder is empty " if they access them before compliant ? should we deny those ip addresses (file servers) in the &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;redirect ACL ??? &lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Jul 2016 02:44:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-dot1x-eap-tls-with-logon-script/m-p/3436508#M538448</guid>
      <dc:creator>yhan2</dc:creator>
      <dc:date>2016-07-08T02:44:54Z</dc:date>
    </item>
    <item>
      <title>Re: ISE dot1x eap-tls with logon script</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-dot1x-eap-tls-with-logon-script/m-p/3436509#M538450</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We covered this in the original answer.&lt;/P&gt;&lt;P&gt;They need to do whatever they need to do with GPO delays or Quarantine ACLs to ensure GPOs will work whenever they are invoked with whatever resources they are trying to access. Rather than deal with GPO timing delays it is probably easier to include any and all necessary file servers in their Non-Compliant/Quarantine ACL.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Jul 2016 16:08:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-dot1x-eap-tls-with-logon-script/m-p/3436509#M538450</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2016-07-08T16:08:22Z</dc:date>
    </item>
  </channel>
</rss>

