<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AnyConnect Network Access Manager can't handle machine authentication in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/anyconnect-network-access-manager-can-t-handle-machine/m-p/3409705#M548070</link>
    <description>&lt;P&gt;Windows 10 requires a registry fix for NAM machine auth to work.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;From the Anyconnect release notes:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/vpn_client/anyconnect/anyconnect46/release/notes/b_Release_Notes_AnyConnect_4_6.html#ID-1454-000002d1" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/vpn_client/anyconnect/anyconnect46/release/notes/b_Release_Notes_AnyConnect_4_6.html#ID-1454-000002d1&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-SPOILER&gt;
&lt;P class="p"&gt;For Network Access Manager, machine authentication using machine password will not work on Windows 8 or 10 / Server 2012 unless a registry fix described in Microsoft KB 2743127 is applied to the client desktop. This fix includes adding a DWORD value LsaAllowReturningUnencryptedSecrets to the HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa registry key and setting this value to 1. This change permits Local Security Authority (LSA) to provide clients like Cisco Network Access Manager with the Machine password. It is related to the increased default security settings in Windows 8 or 10 / Server 2012. Machine authentication using Machine certificate does not require this change and will work the same as it worked with pre-Windows 8 operating systems.&lt;/P&gt;
&lt;/LI-SPOILER&gt;</description>
    <pubDate>Tue, 03 Jul 2018 14:06:02 GMT</pubDate>
    <dc:creator>Rahul Govindan</dc:creator>
    <dc:date>2018-07-03T14:06:02Z</dc:date>
    <item>
      <title>AnyConnect Network Access Manager can't handle machine authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/anyconnect-network-access-manager-can-t-handle-machine/m-p/3409655#M548069</link>
      <description>&lt;P&gt;I'm using PEAP-mschapv2 for machine authentication(wired-dot1x). Client authenticated against AD when using windows native client but when I using nam, it fails.&lt;/P&gt;
&lt;P&gt;Client Windows 10 version 1803 it's updated.&lt;/P&gt;
&lt;P&gt;I have tried Windows 7 client with same nam config and client was authenticated successfully.&lt;/P&gt;
&lt;P&gt;Can someone help me for solution?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm using freeradius and freeradius uses ntlm for authentication.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 19:00:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyconnect-network-access-manager-can-t-handle-machine/m-p/3409655#M548069</guid>
      <dc:creator>akbasah</dc:creator>
      <dc:date>2020-02-21T19:00:07Z</dc:date>
    </item>
    <item>
      <title>Re: AnyConnect Network Access Manager can't handle machine authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/anyconnect-network-access-manager-can-t-handle-machine/m-p/3409705#M548070</link>
      <description>&lt;P&gt;Windows 10 requires a registry fix for NAM machine auth to work.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;From the Anyconnect release notes:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/vpn_client/anyconnect/anyconnect46/release/notes/b_Release_Notes_AnyConnect_4_6.html#ID-1454-000002d1" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/vpn_client/anyconnect/anyconnect46/release/notes/b_Release_Notes_AnyConnect_4_6.html#ID-1454-000002d1&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-SPOILER&gt;
&lt;P class="p"&gt;For Network Access Manager, machine authentication using machine password will not work on Windows 8 or 10 / Server 2012 unless a registry fix described in Microsoft KB 2743127 is applied to the client desktop. This fix includes adding a DWORD value LsaAllowReturningUnencryptedSecrets to the HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa registry key and setting this value to 1. This change permits Local Security Authority (LSA) to provide clients like Cisco Network Access Manager with the Machine password. It is related to the increased default security settings in Windows 8 or 10 / Server 2012. Machine authentication using Machine certificate does not require this change and will work the same as it worked with pre-Windows 8 operating systems.&lt;/P&gt;
&lt;/LI-SPOILER&gt;</description>
      <pubDate>Tue, 03 Jul 2018 14:06:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/anyconnect-network-access-manager-can-t-handle-machine/m-p/3409705#M548070</guid>
      <dc:creator>Rahul Govindan</dc:creator>
      <dc:date>2018-07-03T14:06:02Z</dc:date>
    </item>
  </channel>
</rss>

