<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cisco Prime authentication using CHAP and Active Directory in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-prime-authentication-using-chap-and-active-directory/m-p/4397117#M567096</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a prime infrastructure server (v3.4) currently configured with external authentication using PAP method.&lt;/P&gt;&lt;P&gt;An audit recommends we move to CHAP authentication, but we also want to authenticate users based on AD accounts.&lt;/P&gt;&lt;P&gt;Is there a way to achieve this ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So far i've found that i can either :&lt;/P&gt;&lt;P&gt;1. Authenticate users with the PAP method against AD accounts through ISE (v2.2) or Microsoft NPS.&lt;/P&gt;&lt;P&gt;2. Authenticate users with the CHAP method against internal users on ISE.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I need to have both CHAP authentication configured on Prime and users able to login with their AD accounts, but it's starting to look like this is simply not possible.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does someone know a working design to achieve this ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your time,&lt;/P&gt;&lt;P&gt;Have a nice day.&lt;/P&gt;</description>
    <pubDate>Mon, 03 May 2021 15:56:00 GMT</pubDate>
    <dc:creator>tom.barat@dimensiondata.com</dc:creator>
    <dc:date>2021-05-03T15:56:00Z</dc:date>
    <item>
      <title>Cisco Prime authentication using CHAP and Active Directory</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-prime-authentication-using-chap-and-active-directory/m-p/4397117#M567096</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a prime infrastructure server (v3.4) currently configured with external authentication using PAP method.&lt;/P&gt;&lt;P&gt;An audit recommends we move to CHAP authentication, but we also want to authenticate users based on AD accounts.&lt;/P&gt;&lt;P&gt;Is there a way to achieve this ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So far i've found that i can either :&lt;/P&gt;&lt;P&gt;1. Authenticate users with the PAP method against AD accounts through ISE (v2.2) or Microsoft NPS.&lt;/P&gt;&lt;P&gt;2. Authenticate users with the CHAP method against internal users on ISE.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I need to have both CHAP authentication configured on Prime and users able to login with their AD accounts, but it's starting to look like this is simply not possible.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does someone know a working design to achieve this ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your time,&lt;/P&gt;&lt;P&gt;Have a nice day.&lt;/P&gt;</description>
      <pubDate>Mon, 03 May 2021 15:56:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-prime-authentication-using-chap-and-active-directory/m-p/4397117#M567096</guid>
      <dc:creator>tom.barat@dimensiondata.com</dc:creator>
      <dc:date>2021-05-03T15:56:00Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Prime authentication using CHAP and Active Directory</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-prime-authentication-using-chap-and-active-directory/m-p/4397272#M567104</link>
      <description>&lt;P&gt;If you can enable "&lt;A href="https://docs.microsoft.com/en-us/windows/security/threat-protection/security-policy-settings/store-passwords-using-reversible-encryption" target="_self"&gt;Store password using reversible encryption&lt;/A&gt;" on those users, then in theory it will enable CHAP for that account.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="chap.png" style="width: 633px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/119459i405B614C49A862E8/image-size/large?v=v2&amp;amp;px=999" role="button" title="chap.png" alt="chap.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Having said that, I believe you also need to reset the password to force Windows to store it in the reversible format.&lt;/P&gt;
&lt;P&gt;I tried all this and it did not work for me. Perhaps it's disabled elsewhere in Windows 2012 and onwards. Either way, CHAP is not a great method. But better than PAP I guess.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Have a play and let us know if you get it working.&lt;/P&gt;</description>
      <pubDate>Mon, 03 May 2021 20:54:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-prime-authentication-using-chap-and-active-directory/m-p/4397272#M567104</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2021-05-03T20:54:54Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Prime authentication using CHAP and Active Directory</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-prime-authentication-using-chap-and-active-directory/m-p/4397919#M567127</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your answer.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Unfortunatley i don't think the client will agree to a trial and error approach.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If this is not supported, that's fine and we can move on, but ideally i would have a design or documentation piece explaining that it's not supported and why.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I also think it's strange that Prime only supports CHAP and PAP as external authentication methods.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 05 May 2021 07:01:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-prime-authentication-using-chap-and-active-directory/m-p/4397919#M567127</guid>
      <dc:creator>tom.barat@dimensiondata.com</dc:creator>
      <dc:date>2021-05-05T07:01:15Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Prime authentication using CHAP and Active Directory</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-prime-authentication-using-chap-and-active-directory/m-p/4398129#M567141</link>
      <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/796226"&gt;tom.barat@dimensiondata.com&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;please take a look at: &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-7/admin_guide/b_ise_27_admin_guide/b_ISE_admin_27_asset_visibility.html" target="_blank" rel="noopener"&gt;ISE Administrator Guide, 2.7&lt;/A&gt;, search for &lt;STRONG&gt;Authentication Protocols and Supported External Identity Sources&lt;/STRONG&gt;.&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="04 - Authentication Protocols and Supported External Identity Sources.png" style="width: 752px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/119567i253C9826588554DC/image-dimensions/752x801?v=v2" width="752" height="801" role="button" title="04 - Authentication Protocols and Supported External Identity Sources.png" alt="04 - Authentication Protocols and Supported External Identity Sources.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps !!!&lt;/P&gt;</description>
      <pubDate>Wed, 05 May 2021 12:43:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-prime-authentication-using-chap-and-active-directory/m-p/4398129#M567141</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2021-05-05T12:43:42Z</dc:date>
    </item>
  </channel>
</rss>

