<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Thank you Fabio. in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-authentication-strategy/m-p/2788169#M56316</link>
    <description>&lt;P&gt;Thank you Fabio.&lt;/P&gt;</description>
    <pubDate>Thu, 10 Mar 2016 21:57:55 GMT</pubDate>
    <dc:creator>Daniel Stefani</dc:creator>
    <dc:date>2016-03-10T21:57:55Z</dc:date>
    <item>
      <title>Cisco ISE - Authentication Strategy</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-authentication-strategy/m-p/2788161#M56293</link>
      <description>&lt;P&gt;Hello guys,&lt;/P&gt;
&lt;P&gt;Would like opinions to a scalable &amp;nbsp;authentication strategy of users and / or workstations in Cisco ISE for the following scenario:&lt;/P&gt;
&lt;P&gt;Customer with approximately 130 branches. Each branch has a different AD domain, without trust relationship with the HQ&amp;nbsp;and with the other branches.&lt;/P&gt;
&lt;P&gt;Knowing that the ISE supports integration with up to 50 domains, which suggestion for this case?&lt;/P&gt;
&lt;P&gt;Regards,&lt;BR /&gt;Daniel Stefani&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 06:27:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-authentication-strategy/m-p/2788161#M56293</guid>
      <dc:creator>Daniel Stefani</dc:creator>
      <dc:date>2019-03-11T06:27:22Z</dc:date>
    </item>
    <item>
      <title>That is right. - Cisco ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-authentication-strategy/m-p/2788162#M56299</link>
      <description>&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;That is right. - Cisco ISE supports multiple joins to Active Directory domains. Cisco ISE supports up to 50 Active Directory joins. &lt;STRONG&gt;Cisco ISE can connect with multiple Active Directory domains that do not have a two-way trust or have zero trust between them.&lt;/STRONG&gt; Active Directory multi-domain join comprises a set of distinct Active Directory domains with their own groups, attributes, and authorization policies &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;for each join. More information - &lt;A href="http://www.cisco.com/c/en/us/td/docs/security/ise/1-3/ISE-ADIntegrationDoc/b_ISE-ADIntegration.pdf"&gt;ISE 1.3 &amp;amp; AD integration&lt;/A&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Feb 2016 14:57:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-authentication-strategy/m-p/2788162#M56299</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2016-02-04T14:57:54Z</dc:date>
    </item>
    <item>
      <title>Hi Jatin Katyal, Thank you.</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-authentication-strategy/m-p/2788163#M56302</link>
      <description>&lt;P&gt;Hi Jatin Katyal, Thank you.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;What the strategy for the other 80 branches?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Regards,&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Daniel Stefani&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Feb 2016 15:45:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-authentication-strategy/m-p/2788163#M56302</guid>
      <dc:creator>Daniel Stefani</dc:creator>
      <dc:date>2016-02-04T15:45:53Z</dc:date>
    </item>
    <item>
      <title>Hi Daniel,</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-authentication-strategy/m-p/2788164#M56306</link>
      <description>&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Hi Daniel,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Let me get back to you on this.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;~ Jatin&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Feb 2016 02:29:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-authentication-strategy/m-p/2788164#M56306</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2016-02-05T02:29:43Z</dc:date>
    </item>
    <item>
      <title>Hi Jatin,</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-authentication-strategy/m-p/2788165#M56307</link>
      <description>&lt;P&gt;Hi Jatin,&lt;/P&gt;
&lt;P&gt;thank you. I wait.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Best Regards,&lt;/P&gt;
&lt;P&gt;Daniel Stefani&lt;/P&gt;</description>
      <pubDate>Fri, 05 Feb 2016 17:17:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-authentication-strategy/m-p/2788165#M56307</guid>
      <dc:creator>Daniel Stefani</dc:creator>
      <dc:date>2016-02-05T17:17:06Z</dc:date>
    </item>
    <item>
      <title>Might not be ideal from a</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-authentication-strategy/m-p/2788166#M56309</link>
      <description>&lt;P&gt;Might not be ideal from a configuration standpoint, but you could build LDAP connections to the 80 remote branches, setup the user/group search base (CN=Users,DC=domain,DC=local and etc.) and then in your authentication policies, check network device group&amp;nbsp;then set the LDAP server for that site to process the request.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Feb 2016 18:21:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-authentication-strategy/m-p/2788166#M56309</guid>
      <dc:creator>jj27</dc:creator>
      <dc:date>2016-02-05T18:21:40Z</dc:date>
    </item>
    <item>
      <title>Hi JJohnston, thanks for</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-authentication-strategy/m-p/2788167#M56311</link>
      <description>&lt;P&gt;Hi JJohnston, thanks for aswer...use LDAP may be an alternative.&lt;BR /&gt;I was thinking of doing authentication using digital certificates only.&lt;BR /&gt;Each branch would have a CA (Windows) to generate and distribute a certificate to authenticate workstations.&lt;BR /&gt;In ISE, I would create authentication and authorization policies to validate these certificates(Workstatios).&lt;BR /&gt;Not sure if this design can work, but it is what I have in mind right now.&lt;/P&gt;
&lt;P&gt;What do you think ?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Best Regards,&lt;/P&gt;
&lt;P&gt;Daniel Stefani&lt;/P&gt;</description>
      <pubDate>Thu, 11 Feb 2016 12:44:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-authentication-strategy/m-p/2788167#M56311</guid>
      <dc:creator>Daniel Stefani</dc:creator>
      <dc:date>2016-02-11T12:44:12Z</dc:date>
    </item>
    <item>
      <title>Stefani,</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-authentication-strategy/m-p/2788168#M56313</link>
      <description>&lt;P&gt;Stefani,&lt;/P&gt;
&lt;P&gt;Sure it will work, you can even use a centralized CA architecture, just make sure you can distribute these certificates to the endpoints...&lt;/P&gt;
&lt;P&gt;Another option is to check if the AD &lt;SPAN class="content"&gt;User account is restricted (disabled, locked out, expired, password expired, and so on) via LDAP, but you need the username equals some field in the certificate (CN or SAN).&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="content"&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="content"&gt;regards,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="content"&gt;Fabio&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Feb 2016 18:14:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-authentication-strategy/m-p/2788168#M56313</guid>
      <dc:creator>fabioacarneiro</dc:creator>
      <dc:date>2016-02-22T18:14:10Z</dc:date>
    </item>
    <item>
      <title>Thank you Fabio.</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-authentication-strategy/m-p/2788169#M56316</link>
      <description>&lt;P&gt;Thank you Fabio.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Mar 2016 21:57:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-authentication-strategy/m-p/2788169#M56316</guid>
      <dc:creator>Daniel Stefani</dc:creator>
      <dc:date>2016-03-10T21:57:55Z</dc:date>
    </item>
  </channel>
</rss>

