<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE onboarding sith internal CA server in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-onboarding-sith-internal-ca-server/m-p/3405476#M548495</link>
    <description>&lt;P&gt;Guys! any idea?!&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm getting this message:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ise1.png" style="width: 629px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/13861iC6B69CACFDEB64D9/image-size/large?v=v2&amp;amp;px=999" role="button" title="ise1.png" alt="ise1.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 26 Jun 2018 09:04:03 GMT</pubDate>
    <dc:creator>ciscoworlds</dc:creator>
    <dc:date>2018-06-26T09:04:03Z</dc:date>
    <item>
      <title>ISE onboarding sith internal CA server</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-onboarding-sith-internal-ca-server/m-p/3395698#M548490</link>
      <description>&lt;P&gt;Hi;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm testing ISE onboarding and configured authentication/authorization rules on ISE. I also have a internal Windows server which I've configured it to be my internal CA server. My WLC is 2504 (software version 8.0.121.0 and field recovery image version 7.4.1.30).&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I started to test with an Android mobile device. After successfully authenticating with Active Directory, I redirected to BYOD portal where I was pushed&amp;nbsp;to download Cisco Network Assistant from Google Play. But the issue is I got this message on my Android device. How can I resolve this certificate issue on WLC?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_20180607-164220.png" style="width: 562px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/12850iC2CEB37D785A3FED/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot_20180607-164220.png" alt="Screenshot_20180607-164220.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 18:57:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-onboarding-sith-internal-ca-server/m-p/3395698#M548490</guid>
      <dc:creator>ciscoworlds</dc:creator>
      <dc:date>2020-02-21T18:57:44Z</dc:date>
    </item>
    <item>
      <title>Re: ISE onboarding sith internal CA server</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-onboarding-sith-internal-ca-server/m-p/3396131#M548492</link>
      <description>&lt;P&gt;During which stage of the on-boarding process do you get that error? The error message indicates that there is a proxy and/or another device on your network that is deencrypting/inspecting SSL/TLS traffic. Can you expand on the technical details and provide a screenshot of the certificate that is being used to encrypt the connection?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Jun 2018 00:14:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-onboarding-sith-internal-ca-server/m-p/3396131#M548492</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2018-06-08T00:14:00Z</dc:date>
    </item>
    <item>
      <title>Re: ISE onboarding sith internal CA server</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-onboarding-sith-internal-ca-server/m-p/3396349#M548494</link>
      <description>&lt;P&gt;Hi;&lt;/P&gt;
&lt;P&gt;I wanted to try to do the same, but before that, I got stuck at the beginning because I got these messages. Where I should change this option? On WLC or on ISE? I tried but didn't managed to affect that.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;06-08-2018 14:21:37 Local0.Warning 10.1.206.205 CWLC: *Dot1x_NW_MsgTask_7: Jun 08 11:21:31.456: #DOT1X-4-AAA_MAX_RETRY: 1x_bauth_sm.c:404 Max AAA authentication attempts exceeded for client 04:4f:4c:3b:8a:67



06-08-2018 14:21:37 Local0.Info 10.1.206.205 CWLC: *Dot1x_NW_MsgTask_7: Jun 08 11:21:31.456: #APF-6-MOBILE_EXCLUDED: apf_ms.c:6232 Excluded the mobile 04:4f:4c:3b:8a:67.&lt;/PRE&gt;
&lt;P&gt;&lt;SPAN&gt;10.1.206.205 belongs to Cisco WLC. The MAC address in log message belongs to my Android device.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;All I found was Wireless Client Exclusion Policy and I disabled it.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="wlc.png" style="width: 550px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/12922i105078356213AA01/image-size/large?v=v2&amp;amp;px=999" role="button" title="wlc.png" alt="wlc.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But after a while, something resets the failure and I get this message on ISE RADIUS live log page:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="wlc2.png" style="width: 559px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/12923i0430FA3BB79422F7/image-size/large?v=v2&amp;amp;px=999" role="button" title="wlc2.png" alt="wlc2.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I will send the details if I can get rid of this error.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Jun 2018 12:15:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-onboarding-sith-internal-ca-server/m-p/3396349#M548494</guid>
      <dc:creator>ciscoworlds</dc:creator>
      <dc:date>2018-06-08T12:15:36Z</dc:date>
    </item>
    <item>
      <title>Re: ISE onboarding sith internal CA server</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-onboarding-sith-internal-ca-server/m-p/3405476#M548495</link>
      <description>&lt;P&gt;Guys! any idea?!&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm getting this message:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ise1.png" style="width: 629px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/13861iC6B69CACFDEB64D9/image-size/large?v=v2&amp;amp;px=999" role="button" title="ise1.png" alt="ise1.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jun 2018 09:04:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-onboarding-sith-internal-ca-server/m-p/3405476#M548495</guid>
      <dc:creator>ciscoworlds</dc:creator>
      <dc:date>2018-06-26T09:04:03Z</dc:date>
    </item>
  </channel>
</rss>

