<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE 2.6 Patch 5:  Macbook wireless fail using PEAP(MSCHAPv2) in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-2-6-patch-5-macbook-wireless-fail-using-peap-mschapv2/m-p/4145430#M562664</link>
    <description>&lt;P&gt;Mac OSX does not really have the same separate Computer/User states as Windows. They also do not have the native ability to join an AD domain, so I'm not sure how you have machine auth happening against any MacBooks.&lt;/P&gt;
&lt;P&gt;Where I've seen customers using PEAP-MSCHAPv2 with MacBooks, they considered them single-user devices, used JAMF Pro to enrol and configure the Network Profile with the user credentials, and only authenticated against the user credentials.&lt;/P&gt;
&lt;P&gt;From the logs you provided, I would also infer you are trying to use MAR (WasMachineAuthenticated = True)? If that's the case, I would strongly recommend against using MAR as it has known user experience issues with Windows PCs. I don't know that MAR has ever even been tested with OSX as it does not have a clear separation of Computer/User states.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/lan-switching/8021x/116516-problemsolution-technology-00.html" target="_blank" rel="noopener"&gt;Machine Access Restriction Pros and Cons&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 02 Sep 2020 22:58:51 GMT</pubDate>
    <dc:creator>Greg Gibbs</dc:creator>
    <dc:date>2020-09-02T22:58:51Z</dc:date>
    <item>
      <title>ISE 2.6 Patch 5:  Macbook wireless fail using PEAP(MSCHAPv2)</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-6-patch-5-macbook-wireless-fail-using-peap-mschapv2/m-p/4145252#M562650</link>
      <description>&lt;P&gt;ISE 2.6 patch 5&lt;/P&gt;&lt;P&gt;Macbook&lt;/P&gt;&lt;P&gt;Wireless connection:&amp;nbsp; user authc, previous machine authc&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do we know if there is still an issue with Macbook using PEAP(MSCHAPv2)?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have some macbook successfully connect on ISE (user &amp;amp; Machine.&amp;nbsp; i.e. user authc, successful previous machine authc) using LEAP but fail using PEAP(CHAPv2) stating below.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;TABLE cellpadding="3" border="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;24715&lt;/TD&gt;&lt;TD&gt;ISE has not confirmed locally previous successful machine authentication for user in Active Directory&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;24714&lt;/TD&gt;&lt;TD&gt;ISE peers have not confirmed previous successful machine authentication for user in Active Directory&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 02 Sep 2020 17:10:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-6-patch-5-macbook-wireless-fail-using-peap-mschapv2/m-p/4145252#M562650</guid>
      <dc:creator>KelvinT</dc:creator>
      <dc:date>2020-09-02T17:10:19Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.6 Patch 5:  Macbook wireless fail using PEAP(MSCHAPv2)</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-6-patch-5-macbook-wireless-fail-using-peap-mschapv2/m-p/4145430#M562664</link>
      <description>&lt;P&gt;Mac OSX does not really have the same separate Computer/User states as Windows. They also do not have the native ability to join an AD domain, so I'm not sure how you have machine auth happening against any MacBooks.&lt;/P&gt;
&lt;P&gt;Where I've seen customers using PEAP-MSCHAPv2 with MacBooks, they considered them single-user devices, used JAMF Pro to enrol and configure the Network Profile with the user credentials, and only authenticated against the user credentials.&lt;/P&gt;
&lt;P&gt;From the logs you provided, I would also infer you are trying to use MAR (WasMachineAuthenticated = True)? If that's the case, I would strongly recommend against using MAR as it has known user experience issues with Windows PCs. I don't know that MAR has ever even been tested with OSX as it does not have a clear separation of Computer/User states.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/lan-switching/8021x/116516-problemsolution-technology-00.html" target="_blank" rel="noopener"&gt;Machine Access Restriction Pros and Cons&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Sep 2020 22:58:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-6-patch-5-macbook-wireless-fail-using-peap-mschapv2/m-p/4145430#M562664</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2020-09-02T22:58:51Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.6 Patch 5:  Macbook wireless fail using PEAP(MSCHAPv2)</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-6-patch-5-macbook-wireless-fail-using-peap-mschapv2/m-p/4145690#M562681</link>
      <description>&lt;P&gt;Hi Greg,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for you respond.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are receiving a user and machine authc from the macbook configured with LEAP but not macbooks configure with PEAP(MSCHAPv2).&amp;nbsp; Doing some search I see old conversations about ISE/Macbook/PEAP(MSCHAPv2) issues which is why I asked.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm not an apple/macbook tech so my knowledge is very limited.&amp;nbsp; I can say I see on the ISE logs actually similar behavior as EAP-FAST.&amp;nbsp; The user and machine is sent in the same log and MARS is used for those macbooks configured with LEAP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Side note:&amp;nbsp; I am aware of the limitations with MAR.&amp;nbsp; Someone gave me a very good workaround.&amp;nbsp; Switch user causes the machine to reauthc every time.&amp;nbsp; So every time switch user is selected I see machine authc on ISE.&amp;nbsp; The user can log back in and get connected.&amp;nbsp; So just selecting switch user (no additional log in is required) then the same user logs back in is the best workaround.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks again Greg&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Sep 2020 10:20:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-6-patch-5-macbook-wireless-fail-using-peap-mschapv2/m-p/4145690#M562681</guid>
      <dc:creator>KelvinT</dc:creator>
      <dc:date>2020-09-03T10:20:42Z</dc:date>
    </item>
  </channel>
</rss>

