<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Configure Wired 802.1X with NPS in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/configure-wired-802-1x-with-nps/m-p/3817941#M547886</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;can I use certificates to authenticate with NPS ?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;When i tried with NPS ,it always show username and password box but whatever username and password i type it is not success.I install root cert and i also using CSR for our PC.i use two certificate.Let me know do &lt;STRONG&gt;i need to export cert fom NPS and install this cert to clients ?&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;Which certificate template should i use for this ?&lt;/STRONG&gt; Should i use default user certificate template or customize (user ,workstation) ?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;802.1x using EAP and MAB using PAP. So&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;if i&amp;nbsp; want use NPS for both ( 802.1x and MAB) , &lt;STRONG&gt;i need to add two network policy in NPS (one for 802.1x and one for MAB) ?&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 10:07:24 GMT</pubDate>
    <dc:creator>MrBeginner</dc:creator>
    <dc:date>2019-03-12T10:07:24Z</dc:date>
    <item>
      <title>Configure Wired 802.1X with NPS</title>
      <link>https://community.cisco.com/t5/network-access-control/configure-wired-802-1x-with-nps/m-p/3817860#M547884</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I would like to request to help for 802.1 wired authentication with NPS.I already tested using PEAP and username,password authentication for 802.1x with NPS. It is working.&lt;/P&gt;
&lt;P&gt;I would like to use 802.1x authentication in our network but i don't want to join all my PCs to domain.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Now i would like to know can i use the 802.1x authentication for normal PC&amp;nbsp; ?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;If i don't want to type user name and password which method should i need to use ?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Even i am using certificate authenticate, still i need to type username and password ? &lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;My network have a lot of devices( printers and ip phones).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;if i add mac in domain to use MAB,it is very complicate&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;How to use MAB for those devices ?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Can i add this devices MAC in NPS server ?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 19:03:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/configure-wired-802-1x-with-nps/m-p/3817860#M547884</guid>
      <dc:creator>MrBeginner</dc:creator>
      <dc:date>2020-02-21T19:03:34Z</dc:date>
    </item>
    <item>
      <title>Re: Configure Wired 802.1X with NPS</title>
      <link>https://community.cisco.com/t5/network-access-control/configure-wired-802-1x-with-nps/m-p/3817914#M547885</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;You can use certificates to authenticate, this will not prompt you to enter a username or password. The login will be transparent.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;It appears MAB authentication is possibly on NPS, &lt;A href="https://documentation.meraki.com/MS/Access_Control/Configuring_Microsoft_NPS_for_MAC-Based_RADIUS_-_MS_Switches" target="_self"&gt;here&lt;/A&gt; is an example to help you. Ultimately you would need to add a user account within AD, the username and password would be the MAC address of the device. You will have to do this manually for each MAC address.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Alternatively depending on the make/model of your printers and phones you could probably use certificates or PEAP (username and password) instead of MAB.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;HTH&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 09:32:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/configure-wired-802-1x-with-nps/m-p/3817914#M547885</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2019-03-12T09:32:47Z</dc:date>
    </item>
    <item>
      <title>Re: Configure Wired 802.1X with NPS</title>
      <link>https://community.cisco.com/t5/network-access-control/configure-wired-802-1x-with-nps/m-p/3817941#M547886</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;can I use certificates to authenticate with NPS ?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;When i tried with NPS ,it always show username and password box but whatever username and password i type it is not success.I install root cert and i also using CSR for our PC.i use two certificate.Let me know do &lt;STRONG&gt;i need to export cert fom NPS and install this cert to clients ?&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;Which certificate template should i use for this ?&lt;/STRONG&gt; Should i use default user certificate template or customize (user ,workstation) ?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;802.1x using EAP and MAB using PAP. So&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;if i&amp;nbsp; want use NPS for both ( 802.1x and MAB) , &lt;STRONG&gt;i need to add two network policy in NPS (one for 802.1x and one for MAB) ?&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 10:07:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/configure-wired-802-1x-with-nps/m-p/3817941#M547886</guid>
      <dc:creator>MrBeginner</dc:creator>
      <dc:date>2019-03-12T10:07:24Z</dc:date>
    </item>
    <item>
      <title>Re: Configure Wired 802.1X with NPS</title>
      <link>https://community.cisco.com/t5/network-access-control/configure-wired-802-1x-with-nps/m-p/3817950#M547887</link>
      <description>Hi,&lt;BR /&gt;If the client computer is prompting you for a username and password then the native supplicant is probably mis-configured. On the client computer in the Ethernet adapter properties, ensure the network authentication method is "Microsoft: Smart card or certificate" - I assume currently it is PEAP?&lt;BR /&gt;&lt;BR /&gt;The client computers that are not domain joined will need the Root Certificate installed in the Trusted Root Store + the client identity certificate, either User or Computer or both depending on how you've configured the native supplicant.&lt;BR /&gt;&lt;BR /&gt;Do you plan on authenticating the User or Computer? Either way you could use the default Microsoft Templates "User" and "Computer" - if you wish you could duplicate those templates and create your own using those default settings.&lt;BR /&gt;&lt;BR /&gt;Yes, you would need another network policy for MAB.&lt;BR /&gt;&lt;BR /&gt;HTH</description>
      <pubDate>Tue, 12 Mar 2019 10:19:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/configure-wired-802-1x-with-nps/m-p/3817950#M547887</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2019-03-12T10:19:05Z</dc:date>
    </item>
    <item>
      <title>Re: Configure Wired 802.1X with NPS</title>
      <link>https://community.cisco.com/t5/network-access-control/configure-wired-802-1x-with-nps/m-p/3817993#M547888</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;On the client computer in the Ethernet adapter properties,i tried both . i install root cert in trust,and user cert and computer cert also installed.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If i use Microsoft: Smart card or certificate , authentication&amp;nbsp;show failed . if i use PEAP show username and address box.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="additional.PNG" style="width: 833px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/31781i69D5690CB66D6095/image-size/large?v=v2&amp;amp;px=999" role="button" title="additional.PNG" alt="additional.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PEAP.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/31783iB27BB16EF38E8092/image-size/large?v=v2&amp;amp;px=999" role="button" title="PEAP.PNG" alt="PEAP.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Smart Card.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/31782iCE5BAC3E4E20E37D/image-size/large?v=v2&amp;amp;px=999" role="button" title="Smart Card.PNG" alt="Smart Card.PNG" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I also tested MAB with computer by uncheck 802.1x box. but i got below error.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;FONT size="2"&gt;021840: *Mar 6 16:58:54: %DOT1X-5-FAIL: Authentication failed for client (d0bf.9cf9.5982) on Interface Fa0/20 AuditSessionID 0A648064000000421BA96976&lt;/FONT&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&lt;FONT size="2"&gt;021841: 5d08h: dot1x-packet:[d0bf.9cf9.5982, Fa0/20] Dot1x did not receive any key data&lt;/FONT&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&lt;FONT size="2"&gt;021842: 5d08h: dot1x-ev:[d0bf.9cf9.5982, Fa0/20] Processing client delete for hdl 0x540000EE sent by Auth Mgr&lt;/FONT&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&lt;FONT size="2"&gt;021843: 5d08h: dot1x-ev:[d0bf.9cf9.5982, Fa0/20] d0bf.9cf9.5982: sending canned failure due to method termination&lt;/FONT&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&lt;FONT size="2"&gt;021844: 5d08h: dot1x-ev:[Fa0/20] Sending EAPOL packet to group PAE address&lt;/FONT&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&lt;FONT size="2"&gt;021845: 5d08h: dot1x-registry:registry:dot1x_ether_macaddr called&lt;/FONT&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&lt;FONT size="2"&gt;021846: 5d08h: dot1x-ev:[Fa0/20] Sending out EAPOL packet&lt;/FONT&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&lt;FONT size="2"&gt;021847: 5d08h: dot1x-packet:EAPOL pak Tx - Ver: 0x3 type: 0x0&lt;/FONT&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&lt;FONT size="2"&gt;021848: 5d08h: dot1x-packet: length: 0x0004&lt;/FONT&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&lt;FONT size="2"&gt;021849: 5d08h: dot1x-packet:EAP code: 0x4 id: 0x1 length: 0x0004&lt;/FONT&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&lt;FONT size="2"&gt;021850: 5d08h: dot1x-packet:[d0bf.9cf9.5982, Fa0/20] EAPOL canned status packet sent to client 0x540000EE&lt;/FONT&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&lt;FONT size="2"&gt;021851: 5d08h: dot1x-ev:[d0bf.9cf9.5982, Fa0/20] Deleting client 0x540000EE (d0bf.9cf9.5982)&lt;/FONT&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&lt;FONT size="2"&gt;021852: 5d08h: dot1x-ev:[d0bf.9cf9.5982, Fa0/20] Delete auth client (0x540000EE) message&lt;/FONT&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&lt;FONT size="2"&gt;021853: 5d08h: dot1x-ev:Auth client ctx destroyed&lt;/FONT&gt;&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 11:19:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/configure-wired-802-1x-with-nps/m-p/3817993#M547888</guid>
      <dc:creator>MrBeginner</dc:creator>
      <dc:date>2019-03-12T11:19:06Z</dc:date>
    </item>
    <item>
      <title>Re: Configure Wired 802.1X with NPS</title>
      <link>https://community.cisco.com/t5/network-access-control/configure-wired-802-1x-with-nps/m-p/3817998#M547889</link>
      <description>What policies do you have configured on the NPS server?&lt;BR /&gt;What were the errors on the NPS server? Check the Windows Event logs for NPS and provide the output of the error&lt;BR /&gt;Do you have MAB configured under the interface aswell as dot1x?</description>
      <pubDate>Tue, 12 Mar 2019 11:27:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/configure-wired-802-1x-with-nps/m-p/3817998#M547889</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2019-03-12T11:27:46Z</dc:date>
    </item>
    <item>
      <title>Re: Configure Wired 802.1X with NPS</title>
      <link>https://community.cisco.com/t5/network-access-control/configure-wired-802-1x-with-nps/m-p/3818508#M547891</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I configure Two policy&amp;nbsp; 802.1x wired policy and MAB policy in NPS.&lt;/P&gt;
&lt;P&gt;Please see below attachment for NPS log.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;FONT size="2"&gt;interface FastEthernet0/19&lt;/FONT&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&lt;FONT size="2"&gt;description Management Network&lt;/FONT&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&lt;FONT size="2"&gt;switchport access vlan 203&lt;/FONT&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&lt;FONT size="2"&gt;switchport mode access&lt;/FONT&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&lt;FONT size="2"&gt;authentication host-mode multi-host&lt;/FONT&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&lt;FONT size="2"&gt;authentication port-control auto&lt;/FONT&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&lt;FONT size="2"&gt;dot1x pae authenticator&lt;/FONT&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&lt;FONT size="2"&gt;spanning-tree portfast&lt;/FONT&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&lt;FONT size="2"&gt;!&lt;/FONT&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&lt;FONT size="2"&gt;interface FastEthernet0/20&lt;/FONT&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&lt;FONT size="2"&gt;description Management Network&lt;/FONT&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&lt;FONT size="2"&gt;switchport access vlan 203&lt;/FONT&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&lt;FONT size="2"&gt;switchport mode access&lt;/FONT&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&lt;FONT size="2"&gt;authentication order mab dot1x&lt;/FONT&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&lt;FONT size="2"&gt;authentication port-control auto&lt;/FONT&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&lt;FONT size="2"&gt;mab&lt;/FONT&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&lt;FONT size="2"&gt;dot1x pae authenticator&lt;/FONT&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&lt;FONT size="2"&gt;spanning-tree portfast&lt;/FONT&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Mar 2019 01:43:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/configure-wired-802-1x-with-nps/m-p/3818508#M547891</guid>
      <dc:creator>MrBeginner</dc:creator>
      <dc:date>2019-03-13T01:43:24Z</dc:date>
    </item>
    <item>
      <title>Re: Configure Wired 802.1X with NPS</title>
      <link>https://community.cisco.com/t5/network-access-control/configure-wired-802-1x-with-nps/m-p/3819106#M547893</link>
      <description>Sorry but there isn't really anything useful in those attachments to determine where the issue is. What conditions do you have configured under each policy?</description>
      <pubDate>Wed, 13 Mar 2019 21:39:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/configure-wired-802-1x-with-nps/m-p/3819106#M547893</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2019-03-13T21:39:19Z</dc:date>
    </item>
    <item>
      <title>Re: Configure Wired 802.1X with NPS</title>
      <link>https://community.cisco.com/t5/network-access-control/configure-wired-802-1x-with-nps/m-p/3821221#M547894</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I am using below setting in NPS.If my client is join to domain,802.1x is working whatever i am using PEAP or EAP-TLS.Afer that i test as you advice with CSR and root Cert install to workgroup computer and tested.Ant then i export user certificate from domain computer and import to work group computer and tested.&lt;/P&gt;
&lt;P&gt;If&amp;nbsp;work group computer is using smart card authentication setting and connect&amp;nbsp; to 802.1x running port,authentication is fail.If working group computer is using PEAP setting, I saw below username and password box .but i don't know which user name and password should be use.I already typed domain user acc and pass but it is fail.&lt;STRONG&gt;Please help me to fix ?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="user name and password.PNG" style="width: 716px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/32116i0373D3D6EB23F42D/image-size/large?v=v2&amp;amp;px=999" role="button" title="user name and password.PNG" alt="user name and password.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I didn't put MAB setting in NPS. I would like to know can we put MAB setting in NPS ?&lt;/P&gt;
&lt;P&gt;Let me share your experience how to configure MAB configuration in NPS or sample link to follow.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2019 11:41:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/configure-wired-802-1x-with-nps/m-p/3821221#M547894</guid>
      <dc:creator>MrBeginner</dc:creator>
      <dc:date>2019-03-18T11:41:39Z</dc:date>
    </item>
    <item>
      <title>Re: Configure Wired 802.1X with NPS</title>
      <link>https://community.cisco.com/t5/network-access-control/configure-wired-802-1x-with-nps/m-p/3821346#M547897</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Your EAP-TLS Network Policy configuration looks incorrect, it should not have the Windows Groups as a condition. Check out this &lt;A href="https://documentation.meraki.com/MR/Encryption_and_Authentication/RADIUS%3A_Creating_a_Policy_in_NPS_to_support_EAP-TLS_authentication" target="_self"&gt;link&lt;/A&gt; for an example NPS EAP-TLS configuration&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;HTH&lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2019 15:29:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/configure-wired-802-1x-with-nps/m-p/3821346#M547897</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2019-03-18T15:29:52Z</dc:date>
    </item>
    <item>
      <title>Re: Configure Wired 802.1X with NPS</title>
      <link>https://community.cisco.com/t5/network-access-control/configure-wired-802-1x-with-nps/m-p/3824729#M547981</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;I tried it but still get error. i confuse when i read cisco 802.1x deployment documentations i saw below EAP-TLS process diagram.&lt;STRONG&gt;Let me know this mean : Even though we use EAP-TL with certificate we still need to type user name and passwords ?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Certificate.jpg" style="width: 500px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/32620iD921A4BE946E5E06/image-dimensions/500x314?v=v2" width="500" height="314" role="button" title="Certificate.jpg" alt="Certificate.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 23 Mar 2019 04:11:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/configure-wired-802-1x-with-nps/m-p/3824729#M547981</guid>
      <dc:creator>MrBeginner</dc:creator>
      <dc:date>2019-03-23T04:11:00Z</dc:date>
    </item>
    <item>
      <title>Re: Configure Wired 802.1X with NPS</title>
      <link>https://community.cisco.com/t5/network-access-control/configure-wired-802-1x-with-nps/m-p/3825853#M547982</link>
      <description>I found the document you are referring to, it does imply that there is a password involved in the screenshot. However EAP-TLS is mutual authentication of the server and client certificates - no actual username/password combo involved. PEAP/MSCHAPv2 requires a server certificate + username/password.&lt;BR /&gt;&lt;BR /&gt;If you are being prompted for authentication, then I would imagine your configuration is still not correct. I re-read a previous comment "i export user certificate from domain computer and import to work group computer and tested." - you shouldn't need to do this, you would create the CSR on the workgroup computer and take the CSR to the CA and sign the certificate. You would then import the signed certificate and import to the local computer store (user or computer). You would also need to import the Root CA certificate into the trusted root certificate store.&lt;BR /&gt;&lt;BR /&gt;HTH</description>
      <pubDate>Mon, 25 Mar 2019 20:55:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/configure-wired-802-1x-with-nps/m-p/3825853#M547982</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2019-03-25T20:55:37Z</dc:date>
    </item>
    <item>
      <title>Re: Configure Wired 802.1X with NPS</title>
      <link>https://community.cisco.com/t5/network-access-control/configure-wired-802-1x-with-nps/m-p/3826106#M547983</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;If you are being prompted for authentication, then I would imagine your configuration is still not correct.&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;=&amp;gt; Yes correct.I am using PEAP authentication. If i use EAP-TLS didn't prompted for authentication but authentication is also fail. I also concern my CSR request.&lt;/P&gt;&lt;P&gt;Because if i use "Build from this Active Directory information " under subject tab of Template ,this template can enroll from AD but cannot request with web.If i choose "supply in the request" under subject tab of Template,this templeate can see from web request &lt;U&gt;&lt;STRONG&gt;(http://localhost\certsrv)&amp;nbsp;&lt;/STRONG&gt;&lt;/U&gt;. I duplicate RAS and IAS server Template.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Second =&amp;gt;&lt;/STRONG&gt;&amp;nbsp;I also worry my csr request file configuration may be wrong. I use custom request with subject name is computer name,DNS name is my Domain (crypto.local),key usage is Digital sign,etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;Let me know we should use same Tamplate for NPS certificate and client certificate ?&amp;nbsp;&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;let me know should we use web enrollment for both NPS and clients ?&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;Let me know the key point of Certficate Template for 802.1x and which template should I use ?&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;Can i request to help if you any CSR request sample or key point or sample reference guide,please?&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Mar 2019 09:10:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/configure-wired-802-1x-with-nps/m-p/3826106#M547983</guid>
      <dc:creator>MrBeginner</dc:creator>
      <dc:date>2019-03-26T09:10:51Z</dc:date>
    </item>
    <item>
      <title>Re: Configure Wired 802.1X with NPS</title>
      <link>https://community.cisco.com/t5/network-access-control/configure-wired-802-1x-with-nps/m-p/3826166#M547984</link>
      <description>I wouldn't worry about creating a new template, you should be able to use the "User" template that already exists. Is it the CSR generation on the client computer you are having an issue with? &lt;BR /&gt;&lt;BR /&gt;From memory:-&lt;BR /&gt;- In the MMC add the Current User, then go to Personal &amp;gt; Certificates, then Advanced Operations &amp;gt; Create Custom Request. Create the CSR.&lt;BR /&gt;- Copy the contents of the CSR file&lt;BR /&gt;- Go to the WebGUI http://server/certsrv&lt;BR /&gt;- Click Request a certificate, then advanced certificate request&lt;BR /&gt;- Copy and paste the contents of the CSR&lt;BR /&gt;- Select template as "User"&lt;BR /&gt;- Submit and save file&lt;BR /&gt;- On the MMC select import and import the signed file&lt;BR /&gt;- Double click the newly imported certificate and confirm "You have a private key that corresponds to this certificate" - bottom of the General tab&lt;BR /&gt;- Confirm the certificate path, to make sure the computer has the root certificate.&lt;BR /&gt;&lt;BR /&gt;HTH</description>
      <pubDate>Tue, 26 Mar 2019 10:42:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/configure-wired-802-1x-with-nps/m-p/3826166#M547984</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2019-03-26T10:42:18Z</dc:date>
    </item>
    <item>
      <title>Re: Configure Wired 802.1X with NPS</title>
      <link>https://community.cisco.com/t5/network-access-control/configure-wired-802-1x-with-nps/m-p/3826691#M547985</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Now i can authentication work-group computers with user but i can use default user template only.If i duplicate Template of users and used this template,i got error.&lt;/P&gt;&lt;P&gt;Now i can authenticate with user CSR with default user template.&lt;/P&gt;&lt;P&gt;If i use local computer CSR ,I still got error .But i don't know why i can use computer certificate to authenticate.But no problem i will find solution late.&lt;/P&gt;&lt;P&gt;Now i testing MAB in NPS.if i use below setting i can authentication is success .But if i use authenticate requests on this server,authentication is fail.i added MAC in AD as users.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Let me know can i use below setting ?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MAB.PNG" style="width: 478px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/32876iBA590A9406A5A993/image-dimensions/478x394?v=v2" width="478" height="394" role="button" title="MAB.PNG" alt="MAB.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Mar 2019 12:18:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/configure-wired-802-1x-with-nps/m-p/3826691#M547985</guid>
      <dc:creator>MrBeginner</dc:creator>
      <dc:date>2019-03-27T12:18:42Z</dc:date>
    </item>
    <item>
      <title>Re: Configure Wired 802.1X with NPS</title>
      <link>https://community.cisco.com/t5/network-access-control/configure-wired-802-1x-with-nps/m-p/3827057#M547986</link>
      <description>What error do you get when you use a custom template? &lt;BR /&gt;Why exactly do you need to use a custom template?&lt;BR /&gt;What error (in the NPS server logs) do you get when the computer authentication fails?&lt;BR /&gt;&lt;BR /&gt;I wouldn't use that command, the NPS server is not authenticating the users then, that's not what you want.&lt;BR /&gt;&lt;BR /&gt;What errors (in the NPS server logs) do you get when attempting to authenticate MAB devices? What did you define as the password for these accounts?</description>
      <pubDate>Wed, 27 Mar 2019 13:12:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/configure-wired-802-1x-with-nps/m-p/3827057#M547986</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2019-03-27T13:12:39Z</dc:date>
    </item>
    <item>
      <title>Re: Configure Wired 802.1X with NPS</title>
      <link>https://community.cisco.com/t5/network-access-control/configure-wired-802-1x-with-nps/m-p/3827664#M547987</link>
      <description>&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;I followed&amp;nbsp;&lt;FONT color="#FF0000"&gt;&lt;A href="https://routemypacket.com/2017/12/31/nps-settings-for-mac-authentication-bypass-mab-using-802-1x/" target="_self"&gt;&lt;FONT color="#FF0000"&gt;this links&lt;/FONT&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/A&gt;&amp;nbsp;&lt;FONT color="#000000"&gt;. I defined mac address as username and password in AD.and i also to stored Mac address in NPS.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Mar 2019 01:26:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/configure-wired-802-1x-with-nps/m-p/3827664#M547987</guid>
      <dc:creator>MrBeginner</dc:creator>
      <dc:date>2019-03-28T01:26:42Z</dc:date>
    </item>
    <item>
      <title>Re: Configure Wired 802.1X with NPS</title>
      <link>https://community.cisco.com/t5/network-access-control/configure-wired-802-1x-with-nps/m-p/3936076#M547988</link>
      <description>&lt;P&gt;If you want to authenticate a PC to allow users to connect via wireless and not be prompted for a password after they have logged into the PC, you should use TLS (Smartcard).&amp;nbsp; However, you will need a PKI (Cert Server) issuing certs to all your PC"s.&amp;nbsp; At that stage, you might as well do users too. This can be done with the MS Cert server and AD.&amp;nbsp; But all nodes will have to be hardwired once to pull the cert when they log in.&amp;nbsp; After they get the cert, you will be good to go.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;One of the most significant issues I have seen with any authentication type is making sure you picked the correct cert under setting highlight your EAP type and click edit.&amp;nbsp; You will get a popup box.&amp;nbsp; Make sure you have the correct root cert being used on your NPS policy.&amp;nbsp; The next one is to change the user and computer Dial-in profile in AD from NPS control to allow access.&amp;nbsp; I have run into issues when they are set to allow NPS to control policy.&amp;nbsp; If you use PEAP, you do not need a PKI, but you will need a cert on NPS that is trusted by all your clients.&amp;nbsp; A third party cert, such as Godaddy, would work because, in most cases, the node will already have GoDaddy as a trusted cert provider.&amp;nbsp;&amp;nbsp; You will have to make sure that under settings Authentication Methods, you edit your EAP type to match your desired cert. &amp;nbsp; Remember, you also have to make sure you add your AP (Meraki)&amp;nbsp; or Wireless controllers to the NPS server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope this helps.&lt;/P&gt;</description>
      <pubDate>Sun, 06 Oct 2019 20:21:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/configure-wired-802-1x-with-nps/m-p/3936076#M547988</guid>
      <dc:creator>Kombi</dc:creator>
      <dc:date>2019-10-06T20:21:11Z</dc:date>
    </item>
  </channel>
</rss>

