<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: troubleshooting over not functioning credentials in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/troubleshooting-over-not-functioning-credentials/m-p/4269115#M564662</link>
    <description>&lt;P&gt;The log on the right, which is resulting in an access reject, appears to be matching the username/AD account in a different domain, possibly across a two way trust in the AD config. If this is the case, the AD groups mapped in the Authz for access may not exist in the other domain. At least that's one possible scenario here.&lt;BR /&gt;&lt;BR /&gt;You can do some AD test authentications and look to see the difference between user1 and user 2. Do this from the External ID sources page.&amp;nbsp;&lt;BR /&gt;&lt;A href="https://&amp;lt;ise" target="_blank"&gt;https://&amp;lt;ise&lt;/A&gt;&amp;nbsp;admin node&amp;gt;/admin/#administration/administration_identitymanagement/administration_identitymanagement_external&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ad-test.png" style="width: 712px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/101188iEB6D17B33ACF55B4/image-dimensions/712x397?v=v2" width="712" height="397" role="button" title="ad-test.png" alt="ad-test.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 08 Jan 2021 17:17:27 GMT</pubDate>
    <dc:creator>Damien Miller</dc:creator>
    <dc:date>2021-01-08T17:17:27Z</dc:date>
    <item>
      <title>troubleshooting over not functioning credentials</title>
      <link>https://community.cisco.com/t5/network-access-control/troubleshooting-over-not-functioning-credentials/m-p/4268949#M564650</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;We need to access to some Cisco devices in a ISE managed infrastructure.&lt;/P&gt;&lt;P&gt;we theoretically have been granted access with multiple credentials but now only a few of them work. The others seems not to be authorized (error "&lt;SPAN&gt;Unable to authorize access.")&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I've tried to troubleshoot this in the ISE But I can't figure out what's the matter with our non functioning credentials. Here is a compare between Username1 (working) and username2 (not working)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2021-01-08 14_29_02-_new 1 - Notepad++ [Administrator].png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/101162i87D44F2D6B49A0D5/image-size/large?v=v2&amp;amp;px=999" role="button" title="2021-01-08 14_29_02-_new 1 - Notepad++ [Administrator].png" alt="2021-01-08 14_29_02-_new 1 - Notepad++ [Administrator].png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Can anyone tell me where exactly to look in those logs in order to troubleshoot problems like this?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;thanks!&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Jan 2021 13:46:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/troubleshooting-over-not-functioning-credentials/m-p/4268949#M564650</guid>
      <dc:creator>maring13482</dc:creator>
      <dc:date>2021-01-08T13:46:06Z</dc:date>
    </item>
    <item>
      <title>Re: troubleshooting over not functioning credentials</title>
      <link>https://community.cisco.com/t5/network-access-control/troubleshooting-over-not-functioning-credentials/m-p/4269115#M564662</link>
      <description>&lt;P&gt;The log on the right, which is resulting in an access reject, appears to be matching the username/AD account in a different domain, possibly across a two way trust in the AD config. If this is the case, the AD groups mapped in the Authz for access may not exist in the other domain. At least that's one possible scenario here.&lt;BR /&gt;&lt;BR /&gt;You can do some AD test authentications and look to see the difference between user1 and user 2. Do this from the External ID sources page.&amp;nbsp;&lt;BR /&gt;&lt;A href="https://&amp;lt;ise" target="_blank"&gt;https://&amp;lt;ise&lt;/A&gt;&amp;nbsp;admin node&amp;gt;/admin/#administration/administration_identitymanagement/administration_identitymanagement_external&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ad-test.png" style="width: 712px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/101188iEB6D17B33ACF55B4/image-dimensions/712x397?v=v2" width="712" height="397" role="button" title="ad-test.png" alt="ad-test.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Jan 2021 17:17:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/troubleshooting-over-not-functioning-credentials/m-p/4269115#M564662</guid>
      <dc:creator>Damien Miller</dc:creator>
      <dc:date>2021-01-08T17:17:27Z</dc:date>
    </item>
    <item>
      <title>Re: troubleshooting over not functioning credentials</title>
      <link>https://community.cisco.com/t5/network-access-control/troubleshooting-over-not-functioning-credentials/m-p/4271444#M564754</link>
      <description>&lt;P&gt;I've tried authenticating both users through the tool you've suggested and I've noted no difference between the two. There just one AD server configured as an external identity source and it's successful for both&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jan 2021 10:05:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/troubleshooting-over-not-functioning-credentials/m-p/4271444#M564754</guid>
      <dc:creator>maring13482</dc:creator>
      <dc:date>2021-01-13T10:05:28Z</dc:date>
    </item>
    <item>
      <title>Re: troubleshooting over not functioning credentials</title>
      <link>https://community.cisco.com/t5/network-access-control/troubleshooting-over-not-functioning-credentials/m-p/4273137#M564799</link>
      <description>&lt;P&gt;hi &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1150482"&gt;@maring13482&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The access rejects comes from your authorization rules, not your authentication.&lt;/P&gt;&lt;P&gt;Please check your authorization rules, share them if you need more help.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jan 2021 10:15:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/troubleshooting-over-not-functioning-credentials/m-p/4273137#M564799</guid>
      <dc:creator>Panos Bouras</dc:creator>
      <dc:date>2021-01-15T10:15:39Z</dc:date>
    </item>
    <item>
      <title>Re: troubleshooting over not functioning credentials</title>
      <link>https://community.cisco.com/t5/network-access-control/troubleshooting-over-not-functioning-credentials/m-p/4275364#M564859</link>
      <description>&lt;P&gt;I don't really know much of the ISE's lingo. Here is the closest thing to "authorization rules" that I've found (looking through some documentation searching for "authorization rule", I've found some reference to policy sets)&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2021-01-19 16_58_01.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/102153iF6623127A1033040/image-size/large?v=v2&amp;amp;px=999" role="button" title="2021-01-19 16_58_01.png" alt="2021-01-19 16_58_01.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jan 2021 16:04:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/troubleshooting-over-not-functioning-credentials/m-p/4275364#M564859</guid>
      <dc:creator>maring13482</dc:creator>
      <dc:date>2021-01-19T16:04:21Z</dc:date>
    </item>
    <item>
      <title>Re: troubleshooting over not functioning credentials</title>
      <link>https://community.cisco.com/t5/network-access-control/troubleshooting-over-not-functioning-credentials/m-p/4279107#M564986</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1150482"&gt;@maring13482&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I apologize for using ISE lingo.&lt;BR /&gt;You found your policy sets which is a good starting point, next if you click on the "&amp;gt;" on your corresponding policy e.g. WIFI_802.1X you'll find the authorization rules. There you must observe the options that must match in order for an authorization policy to succeed, this could be a range of things like use must belong to specific AD group, or for a specific SSID or/ and specific hour.&lt;/P&gt;&lt;P&gt;As policies can be either very simple or to complex there's no way to guide you without specific requirements.&lt;/P&gt;&lt;P&gt;We can try if it's a one off situation, but is always recommended to hire an ISE consultant, especially if you're in an security "sensitive" environment.&lt;/P&gt;&lt;P&gt;Also have a look at &lt;A href="https://www.network-node.com/" target="_blank"&gt;https://www.network-node.com/&lt;/A&gt; for some good videos on ISE.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jan 2021 17:14:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/troubleshooting-over-not-functioning-credentials/m-p/4279107#M564986</guid>
      <dc:creator>Panos Bouras</dc:creator>
      <dc:date>2021-01-25T17:14:30Z</dc:date>
    </item>
  </channel>
</rss>

