<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AnyConnect NAM &amp;amp; ActivClient in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/anyconnect-nam-amp-activclient/m-p/3876807#M547807</link>
    <description>Since this is strictly a NAM issue it looks like then please post to the Anyconnect VPN forum</description>
    <pubDate>Thu, 20 Jun 2019 14:24:31 GMT</pubDate>
    <dc:creator>Jason Kunst</dc:creator>
    <dc:date>2019-06-20T14:24:31Z</dc:date>
    <item>
      <title>AnyConnect NAM &amp; ActivClient</title>
      <link>https://community.cisco.com/t5/network-access-control/anyconnect-nam-amp-activclient/m-p/3876774#M547806</link>
      <description>&lt;P&gt;I am wondering if anyone has come across the following scenario and if so what was your fix:&lt;/P&gt;&lt;P&gt;In some areas of our environment we run NAM on our Win10 workstations to utilize eap-chaining.&amp;nbsp; The machines use ActivClient as the middleware.&amp;nbsp; We have noticed that sometimes when users select their PIV (authentication) certificate to use for authentication in an attempt to map their UPN to their AD account that ActivClient &amp;amp; NAM pass the UPN without the extended string.&amp;nbsp; For example, what I mean by that is if my Sub. Alt. Name UPN is 123456789*121005* (121005 being the additional string) that NAM passes 123456789 to ISE and users are not hitting the proper authz policy because ISE does not see/attempt to map their UPN to AD.&amp;nbsp; We have ran through a lot of tests and will continue to.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here are the versions of everything:&lt;/P&gt;&lt;P&gt;ISE 2.4p5 (moving to patch 6 soon)&lt;/P&gt;&lt;P&gt;NAM 4.6.01103&lt;/P&gt;&lt;P&gt;Tested the following versions of ActivClient (7.1.0.153) (7.1.0.213) (7.1.0244)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any help is appreciated.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 19:07:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyconnect-nam-amp-activclient/m-p/3876774#M547806</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2020-02-21T19:07:08Z</dc:date>
    </item>
    <item>
      <title>Re: AnyConnect NAM &amp; ActivClient</title>
      <link>https://community.cisco.com/t5/network-access-control/anyconnect-nam-amp-activclient/m-p/3876807#M547807</link>
      <description>Since this is strictly a NAM issue it looks like then please post to the Anyconnect VPN forum</description>
      <pubDate>Thu, 20 Jun 2019 14:24:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyconnect-nam-amp-activclient/m-p/3876807#M547807</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2019-06-20T14:24:31Z</dc:date>
    </item>
    <item>
      <title>Re: AnyConnect NAM &amp; ActivClient</title>
      <link>https://community.cisco.com/t5/network-access-control/anyconnect-nam-amp-activclient/m-p/3882091#M547808</link>
      <description>&lt;P&gt;Please do continue on the other post at &lt;A href="https://community.cisco.com/t5/vpn-and-anyconnect/nam-amp-activclient-issue/m-p/3876867#M151097" target="_blank"&gt;NAM &amp;amp; ActivClient Issue&lt;/A&gt;. If you are unable to provide a DART bundle requested there, then do it through the regular Cisco TAC support process.&lt;/P&gt;</description>
      <pubDate>Sun, 30 Jun 2019 05:05:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyconnect-nam-amp-activclient/m-p/3882091#M547808</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2019-06-30T05:05:42Z</dc:date>
    </item>
  </channel>
</rss>

