<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cisco ISE 802.1x Machine Authentication Cert EAP-TLS in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-802-1x-machine-authentication-cert-eap-tls/m-p/4006109#M541006</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I've been tasked with helping roll out 802.1x on our network, and am primarily over the Windows side of setting up group policies for Machine Certificate Auto Enrollment, and configuring the authentication methods. Because the networking team will primarily be handling the Cisco ISE portion of 802.1x, there is quite a large disconnect about what needs to be done. I'm trying to find good documentation between Cisco ISE 802.1x and Windows 802.1x (Group Policies for setting the correct authentication type, Enterprise CA Certificates), but haven't found anything specific to this scenario. Most videos or guides I've found are only for PEAP (username/password) and EAP-TLS (certificate) combined.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We'd just like to use machine certificates to authenticate. From what I'd understand, I'd just set the network authentication method to: "Microsoft: Smart Card or other certificate", and select the trusted root certification authorities. I just don't see any guides for this type of configuration. It would be nice if there was more information about how to set up the Cisco ISE and Authentication within windows to match for this scenario. Are there any guides/documentation that you know of for EAP-TLS only? Or is PEAP and EAP-TLS necessary to work with Cisco ISE/Windows clients?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Annotation 2020-01-03 084443.PNG.jpg" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/64389i5B6CEA42C7D899EA/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Annotation 2020-01-03 084443.PNG.jpg" alt="Annotation 2020-01-03 084443.PNG.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I also am not sure what Cisco ISE requires as a subject name for certificates to work (both Mac &amp;amp; PC):&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Annotation 2020-01-03 084443.PNG-2.jpg" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/64390i16260959ADCAE813/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Annotation 2020-01-03 084443.PNG-2.jpg" alt="Annotation 2020-01-03 084443.PNG-2.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 19:12:48 GMT</pubDate>
    <dc:creator>rmoat</dc:creator>
    <dc:date>2020-02-21T19:12:48Z</dc:date>
    <item>
      <title>Cisco ISE 802.1x Machine Authentication Cert EAP-TLS</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-802-1x-machine-authentication-cert-eap-tls/m-p/4006109#M541006</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I've been tasked with helping roll out 802.1x on our network, and am primarily over the Windows side of setting up group policies for Machine Certificate Auto Enrollment, and configuring the authentication methods. Because the networking team will primarily be handling the Cisco ISE portion of 802.1x, there is quite a large disconnect about what needs to be done. I'm trying to find good documentation between Cisco ISE 802.1x and Windows 802.1x (Group Policies for setting the correct authentication type, Enterprise CA Certificates), but haven't found anything specific to this scenario. Most videos or guides I've found are only for PEAP (username/password) and EAP-TLS (certificate) combined.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We'd just like to use machine certificates to authenticate. From what I'd understand, I'd just set the network authentication method to: "Microsoft: Smart Card or other certificate", and select the trusted root certification authorities. I just don't see any guides for this type of configuration. It would be nice if there was more information about how to set up the Cisco ISE and Authentication within windows to match for this scenario. Are there any guides/documentation that you know of for EAP-TLS only? Or is PEAP and EAP-TLS necessary to work with Cisco ISE/Windows clients?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Annotation 2020-01-03 084443.PNG.jpg" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/64389i5B6CEA42C7D899EA/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Annotation 2020-01-03 084443.PNG.jpg" alt="Annotation 2020-01-03 084443.PNG.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I also am not sure what Cisco ISE requires as a subject name for certificates to work (both Mac &amp;amp; PC):&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Annotation 2020-01-03 084443.PNG-2.jpg" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/64390i16260959ADCAE813/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Annotation 2020-01-03 084443.PNG-2.jpg" alt="Annotation 2020-01-03 084443.PNG-2.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 19:12:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-802-1x-machine-authentication-cert-eap-tls/m-p/4006109#M541006</guid>
      <dc:creator>rmoat</dc:creator>
      <dc:date>2020-02-21T19:12:48Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 802.1x Machine Authentication Cert EAP-TLS</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-802-1x-machine-authentication-cert-eap-tls/m-p/4006437#M541017</link>
      <description>Under the assumption that the network team knows how to setup the ise radius policies to support dot1x with the proper cap profile, authz profiles, and identity source sequences, etc. it looks like you are on the right track. I did not see you mention ensuring that the wired autoconfig service is running. That can be added to the GPO too. Change your auth mode to computer only. As far as peap that adds an extra layer of encapsulation so peap(eap-tls) is definitely secure and the recommended way. As far as windows documentation for configuration you should be able to do a quick google search. Another place I like to recommend is: &lt;A href="http://labminutes.com/video/sec" target="_blank"&gt;http://labminutes.com/video/sec&lt;/A&gt; (Do a search for 802.1x. Free tutorials.)&lt;BR /&gt;HTH!</description>
      <pubDate>Sat, 04 Jan 2020 17:44:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-802-1x-machine-authentication-cert-eap-tls/m-p/4006437#M541017</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2020-01-04T17:44:05Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 802.1x Machine Authentication Cert EAP-TLS</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-802-1x-machine-authentication-cert-eap-tls/m-p/4006530#M541049</link>
      <description>Thanks so much, Mike! Very much appreciated. It's really great to know that peap(eap-tls) is the recommended way, as I can get on the same page as the networking team when we sit down and hash out the configuration together. I've done a bit of research, and there are so many different guides, so I appreciate the link to the labminutes videos. Thank you!&lt;BR /&gt;-Ryan</description>
      <pubDate>Sun, 05 Jan 2020 03:38:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-802-1x-machine-authentication-cert-eap-tls/m-p/4006530#M541049</guid>
      <dc:creator>rmoat</dc:creator>
      <dc:date>2020-01-05T03:38:14Z</dc:date>
    </item>
  </channel>
</rss>

