<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE support for Machine Certificate plus User authentication in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-support-for-machine-certificate-plus-user-authentication/m-p/4195606#M564229</link>
    <description>&lt;P&gt;I found the following that was posted here many years ago.&lt;/P&gt;
&lt;P&gt;Is this post still valid? Is EAP Chaining with AnyConnect client the only way to accomplish this?&lt;/P&gt;
&lt;P&gt;OR has something changed in ISE to support 2 authentications from one device?&lt;/P&gt;
&lt;P&gt;Cut from previous post.&lt;/P&gt;
&lt;P&gt;I don't believe that this is possible and it is due to the limitations of the native windows supplicant where can do either one of the following:&lt;/P&gt;
&lt;P&gt;1. User authentication&lt;/P&gt;
&lt;P&gt;2. Machine authentication&lt;/P&gt;
&lt;P&gt;3. Machine or user authentication&lt;/P&gt;
&lt;P&gt;Machine+User authentication can only be accomplished with EAP-Chaining which is only supported by AnyConnect.&lt;/P&gt;</description>
    <pubDate>Wed, 09 Dec 2020 01:20:38 GMT</pubDate>
    <dc:creator>tiryan</dc:creator>
    <dc:date>2020-12-09T01:20:38Z</dc:date>
    <item>
      <title>ISE support for Machine Certificate plus User authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-support-for-machine-certificate-plus-user-authentication/m-p/4195606#M564229</link>
      <description>&lt;P&gt;I found the following that was posted here many years ago.&lt;/P&gt;
&lt;P&gt;Is this post still valid? Is EAP Chaining with AnyConnect client the only way to accomplish this?&lt;/P&gt;
&lt;P&gt;OR has something changed in ISE to support 2 authentications from one device?&lt;/P&gt;
&lt;P&gt;Cut from previous post.&lt;/P&gt;
&lt;P&gt;I don't believe that this is possible and it is due to the limitations of the native windows supplicant where can do either one of the following:&lt;/P&gt;
&lt;P&gt;1. User authentication&lt;/P&gt;
&lt;P&gt;2. Machine authentication&lt;/P&gt;
&lt;P&gt;3. Machine or user authentication&lt;/P&gt;
&lt;P&gt;Machine+User authentication can only be accomplished with EAP-Chaining which is only supported by AnyConnect.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Dec 2020 01:20:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-support-for-machine-certificate-plus-user-authentication/m-p/4195606#M564229</guid>
      <dc:creator>tiryan</dc:creator>
      <dc:date>2020-12-09T01:20:38Z</dc:date>
    </item>
    <item>
      <title>Re: ISE support for Machine Certificate plus User authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-support-for-machine-certificate-plus-user-authentication/m-p/4195613#M564232</link>
      <description>&lt;P&gt;ISE 2.7 release also provided the option for EAP-TEAP as an alternative to EAP-Chaining with NAM. As of today, only Windows supports EAP-TEAP, and of that only the Windows 10 2004+ (May 2020 release) 2H builds or newer.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/security-documents/teap-for-windows-10-using-group-policy-and-ise-teap/ta-p/4134289" target="_blank"&gt;https://community.cisco.com/t5/security-documents/teap-for-windows-10-using-group-policy-and-ise-teap/ta-p/4134289&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There were a couple open bugs in 2.7 for TEAP, but I believe patch 3 was going to address them.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Dec 2020 01:51:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-support-for-machine-certificate-plus-user-authentication/m-p/4195613#M564232</guid>
      <dc:creator>Damien Miller</dc:creator>
      <dc:date>2020-12-09T01:51:28Z</dc:date>
    </item>
    <item>
      <title>Re: ISE support for Machine Certificate plus User authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-support-for-machine-certificate-plus-user-authentication/m-p/4195655#M564234</link>
      <description>&lt;P&gt;In addition to the excellent answer from Damien, you can also do EAP+CWA chaining where machines that successfully authenticate with machine certificates are punted through the Central Web Authentication flow for user based authentication.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Thank you rating helpful posts!&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Dec 2020 05:37:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-support-for-machine-certificate-plus-user-authentication/m-p/4195655#M564234</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2020-12-09T05:37:12Z</dc:date>
    </item>
    <item>
      <title>Re: ISE support for Machine Certificate plus User authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-support-for-machine-certificate-plus-user-authentication/m-p/4195928#M564246</link>
      <description>&lt;P&gt;Thank you to both of you for the quick responses.&amp;nbsp; Do you know what version of ISE is needed to support the EAP+CWA chaining?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Dec 2020 14:46:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-support-for-machine-certificate-plus-user-authentication/m-p/4195928#M564246</guid>
      <dc:creator>tiryan</dc:creator>
      <dc:date>2020-12-09T14:46:35Z</dc:date>
    </item>
    <item>
      <title>Re: ISE support for Machine Certificate plus User authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-support-for-machine-certificate-plus-user-authentication/m-p/4196103#M564255</link>
      <description>&lt;P&gt;I really don't recall but this has been supported for a while...probably since ISE 2.0 days.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Thank you rating helpful posts!&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Dec 2020 17:20:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-support-for-machine-certificate-plus-user-authentication/m-p/4196103#M564255</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2020-12-09T17:20:26Z</dc:date>
    </item>
  </channel>
</rss>

