<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE WIN10 Slow Logon in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-win10-slow-logon/m-p/3850200#M543692</link>
    <description>&lt;P&gt;Not sure if ACL is used, but if so, suggest allowing IP fragments to AD servers. See: &lt;A href="https://community.cisco.com/t5/security-documents/advanced-ise-tips-to-make-your-deployment-easier/ta-p/3850189#toc-hId-1913177494" target="_blank"&gt;https://community.cisco.com/t5/security-documents/advanced-ise-tips-to-make-your-deployment-easier/ta-p/3850189#toc-hId-1913177494&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sat, 04 May 2019 03:14:21 GMT</pubDate>
    <dc:creator>howon</dc:creator>
    <dc:date>2019-05-04T03:14:21Z</dc:date>
    <item>
      <title>ISE WIN10 Slow Logon</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-win10-slow-logon/m-p/3848454#M543653</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;With the increase of Windows 10 installations, there is an intermittent issue of slow logon which occurs after 5 to ten minutes.&lt;/P&gt;&lt;P&gt;This slow logon occurs after sign on, and the workaround the users have is to either use WIFI (not authenticated via ISE) or to pull out/ plug in the network cable. Then the client can be working fine for a month or more before the issue is seen again on this client (if ever). When there is an issue, we do not see any authentication log in ISE. The issue does not occur everytime for a user but mostly when the user has been out of office for a day or so.&lt;/P&gt;&lt;P&gt;This is a global problem and occurs on different types of networks with old and new, large and small networks, desktops and laptops.&lt;/P&gt;&lt;P&gt;The sites affected also have local and remote domain controllers.&lt;/P&gt;&lt;P&gt;The client version is Windows 10 Enterprise v1803. Running 802.1x (eap-tls) with machine certificates (no AD lookup). We are using windows own dot1x supplicant (same settings as our WIN7 that works)&lt;/P&gt;&lt;P&gt;We are seeing this on diferent switch platforms (2960, 3750, 3650 and 9300) with diferent IOS SW.&lt;/P&gt;&lt;P&gt;ISE version is : 2.1 patch 8 (running on 3495 appliances - 2 x PAN, 2x MON, 2 x PSN)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyone having the same problems and mayby solved this ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards Henrik&lt;/P&gt;</description>
      <pubDate>Wed, 01 May 2019 10:38:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-win10-slow-logon/m-p/3848454#M543653</guid>
      <dc:creator>henrikj</dc:creator>
      <dc:date>2019-05-01T10:38:00Z</dc:date>
    </item>
    <item>
      <title>Re: ISE WIN10 Slow Logon</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-win10-slow-logon/m-p/3848560#M543667</link>
      <description>What do you switchport configs look like? What does your native supplicant settings look like?</description>
      <pubDate>Wed, 01 May 2019 15:21:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-win10-slow-logon/m-p/3848560#M543667</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2019-05-01T15:21:04Z</dc:date>
    </item>
    <item>
      <title>Re: ISE WIN10 Slow Logon</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-win10-slow-logon/m-p/3850200#M543692</link>
      <description>&lt;P&gt;Not sure if ACL is used, but if so, suggest allowing IP fragments to AD servers. See: &lt;A href="https://community.cisco.com/t5/security-documents/advanced-ise-tips-to-make-your-deployment-easier/ta-p/3850189#toc-hId-1913177494" target="_blank"&gt;https://community.cisco.com/t5/security-documents/advanced-ise-tips-to-make-your-deployment-easier/ta-p/3850189#toc-hId-1913177494&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 04 May 2019 03:14:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-win10-slow-logon/m-p/3850200#M543692</guid>
      <dc:creator>howon</dc:creator>
      <dc:date>2019-05-04T03:14:21Z</dc:date>
    </item>
    <item>
      <title>Re: ISE WIN10 Slow Logon</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-win10-slow-logon/m-p/4269113#M564661</link>
      <description>&lt;P&gt;During our deployment we found out that the slow logon/bootup of windows machine was happening due to a Pre Authentication ACL that did not had all the necessary TCP/UDP Ports that were allowed for full communication between Endpoint and Domain Controllers.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So please make sure that the dACL which gets applied soon after the successful machine authentication is completed should have all the below ACL list.&lt;/P&gt;&lt;P&gt;Also remember If you have any additional ACL's applied for your Pre Authentication/Quarantine VLAN on your switch this below ACL should be applied there as well.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;STRONG&gt;!&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;STRONG&gt;remark DHCP&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;STRONG&gt;permit udp any eq bootpc any eq bootps&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;STRONG&gt;remark DNS&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;STRONG&gt;permit udp any any eq domain&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;STRONG&gt;remark Ping&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;STRONG&gt;permit icmp any any&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;STRONG&gt;remark Allow HTTPS to ISE PSN Nodes&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;STRONG&gt;permit tcp any host &amp;lt;ISE_Node&amp;gt; eq 443&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;STRONG&gt;permit tcp any host &amp;lt;ISE_Node&amp;gt; eq 8443&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;STRONG&gt;remark Allowing Ports for DNS/LDAP/NTP&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;STRONG&gt;permit tcp any any eq 88&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;STRONG&gt;permit udp any any eq 88&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;STRONG&gt;permit udp any any eq ntp&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;STRONG&gt;permit tcp any any eq 135&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;STRONG&gt;permit udp any any eq netbios-ns&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;STRONG&gt;permit tcp any any eq 139&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;STRONG&gt;permit tcp any any eq 389&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;STRONG&gt;permit udp any any eq 389&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;STRONG&gt;permit tcp any any eq 445&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;STRONG&gt;permit tcp any any eq 636&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;STRONG&gt;permit udp any any eq 636&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;STRONG&gt;Permit tcp any any eq 464&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;STRONG&gt;Permit udp any any eq 464&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;STRONG&gt;Permit tcp any any range 49152 65535&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;STRONG&gt;Permit tcp any any range 3268 3269&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;STRONG&gt;remark Drop all the rest&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;STRONG&gt;deny&amp;nbsp;&amp;nbsp; ip any any&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;STRONG&gt;!&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="Pre_Auth_ACL.jpg" style="width: 800px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/101187i1D904BE625FCEA36/image-size/large?v=v2&amp;amp;px=999" role="button" title="Pre_Auth_ACL.jpg" alt="Pre_Auth_ACL.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/443403"&gt;@MU_B&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/868083"&gt;@_Warren&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Jan 2021 17:16:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-win10-slow-logon/m-p/4269113#M564661</guid>
      <dc:creator>MU_B</dc:creator>
      <dc:date>2021-01-08T17:16:04Z</dc:date>
    </item>
  </channel>
</rss>

