<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE not able to authenticate computer and users using LDAP Server in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-not-able-to-authenticate-computer-and-users-using-ldap/m-p/3371887#M549173</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Can you provide a screenshot of your authentication and authorisation policy please?&lt;/P&gt;
&lt;P&gt;Can you provide a screenshot of the failed authentication?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In regard to your statement using Smart Card or other Certificate, this requires a User and/or Computer certificate on all of the computers, in addition to the Server certificate you've configured on ISE.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Why can you not fetch groups from AD? Once you've created an External Identity Source for AD, you just need to go to the groups tab and select the groups you want. Or is there a communications error? Perhaps take a screenshot and upload here?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;HTH&lt;/P&gt;</description>
    <pubDate>Tue, 24 Apr 2018 13:31:40 GMT</pubDate>
    <dc:creator>Rob Ingram</dc:creator>
    <dc:date>2018-04-24T13:31:40Z</dc:date>
    <item>
      <title>ISE not able to authenticate computer and users using LDAP Server</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-not-able-to-authenticate-computer-and-users-using-ldap/m-p/3371404#M549170</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Current Setup:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;LDAP&lt;/STRONG&gt; as Identity stores for both domain computers and users.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;PEAP-TLS or EAP-TLS &lt;/STRONG&gt;as authentication method&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Below the configuration of the computer LAN:&lt;/STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.JPG" style="width: 596px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/10849i99B7D108EABA5DDF/image-size/large?v=v2&amp;amp;px=999" role="button" title="Capture.JPG" alt="Capture.JPG" /&gt;&lt;/span&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Only below the available method for authentication:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.JPG2.JPG" style="width: 225px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/10850iE1A08BF526229477/image-size/large?v=v2&amp;amp;px=999" role="button" title="Capture.JPG2.JPG" alt="Capture.JPG2.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I tried the first method ( Smart Card or other Certificate) but getting prompt " need certificate" on the test computer. Take note that&amp;nbsp; I have the root cert of the server and also the&amp;nbsp;CSR from ISE&amp;nbsp; binded with the server. In short, i have all the required certificate on the ISE.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When I used the 2nd method, I getting below error:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.JPG3.JPG" style="width: 572px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/10851i09D770B5013EFF62/image-size/large?v=v2&amp;amp;px=999" role="button" title="Capture.JPG3.JPG" alt="Capture.JPG3.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have successfully integrated the ISE to LDAP as I able to fetch the groups from the LDAP and used in the Policy.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Why ISE not able to locate my username?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there compatibility between LDAP and the authentication that I have used?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I cant used the AD as I am not able to fetch the groups/users from AD that's why we used LDAP.&lt;/P&gt;
&lt;P&gt;Its already a couple of days looking for exact setup but always found most of them using AD as Identity Store.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;All I need is same setup, LDAP as server and what needs to configure on the computer LAN connection,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you in advance.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 18:54:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-not-able-to-authenticate-computer-and-users-using-ldap/m-p/3371404#M549170</guid>
      <dc:creator>ecejhe-old</dc:creator>
      <dc:date>2020-02-21T18:54:15Z</dc:date>
    </item>
    <item>
      <title>Re: ISE not able to authenticate computer and users using LDAP Server</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-not-able-to-authenticate-computer-and-users-using-ldap/m-p/3371887#M549173</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Can you provide a screenshot of your authentication and authorisation policy please?&lt;/P&gt;
&lt;P&gt;Can you provide a screenshot of the failed authentication?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In regard to your statement using Smart Card or other Certificate, this requires a User and/or Computer certificate on all of the computers, in addition to the Server certificate you've configured on ISE.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Why can you not fetch groups from AD? Once you've created an External Identity Source for AD, you just need to go to the groups tab and select the groups you want. Or is there a communications error? Perhaps take a screenshot and upload here?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;HTH&lt;/P&gt;</description>
      <pubDate>Tue, 24 Apr 2018 13:31:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-not-able-to-authenticate-computer-and-users-using-ldap/m-p/3371887#M549173</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2018-04-24T13:31:40Z</dc:date>
    </item>
    <item>
      <title>Re: ISE not able to authenticate computer and users using LDAP Server</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-not-able-to-authenticate-computer-and-users-using-ldap/m-p/3372431#M549176</link>
      <description>&lt;P&gt;Thank &lt;STRONG&gt;RJI&lt;/STRONG&gt;. I tried to rejoin the AD one more time but still not able to fetch the groups from AD.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I tried to test user from ISE and it was successful. Then, from the result I found the directory group and manually search it. That time, I was able to fetch the exact group that I was trying&amp;nbsp; to fetch.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now, my policy in ISE&amp;nbsp; is working fine and will just conduct more test.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I just wondering why I cant fetch groups using "&amp;nbsp;&lt;STRONG&gt;*&amp;nbsp; "&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Thank you so much.&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Apr 2018 05:54:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-not-able-to-authenticate-computer-and-users-using-ldap/m-p/3372431#M549176</guid>
      <dc:creator>ecejhe-old</dc:creator>
      <dc:date>2018-04-25T05:54:17Z</dc:date>
    </item>
  </channel>
</rss>

