<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi, in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-domain-computer-authentication/m-p/2804268#M56771</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thank you for the response.&lt;/P&gt;
&lt;P&gt;Are&amp;nbsp;there&amp;nbsp;any&amp;nbsp;issues with PEAP/MSCHAP computer only authentication from a security perspective as well? I have had a few people request that we maintain 2-factor authentication of computer and user as its more secure so I'm being challenged with the computer only approach.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Tue, 10 Nov 2015 00:25:19 GMT</pubDate>
    <dc:creator>de1denta</dc:creator>
    <dc:date>2015-11-10T00:25:19Z</dc:date>
    <item>
      <title>ISE Domain Computer Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-domain-computer-authentication/m-p/2804266#M56769</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I'm trying to configure ISE to to differentiate between corporate and employee devices that connect to the wireless network using PEAP/MSCHAP authentication. I'm currently looking at only permitting users onto the corporate network who have passed machine and user authentication using machine access restriction but I have come to understand the limitations of MAR and the Windows Supplicant.&lt;/P&gt;
&lt;P&gt;Unfortunatey we cannot use any NAC clients at this time and we dont not have a PKI infrastructure so EAP Chaining is not an option at the moment.&lt;/P&gt;
&lt;P&gt;One option that I'm looking at is using computer only authentication with PEAP/MSCHAP. We will configure Windows group policy to push out a policy to&amp;nbsp;corporate laptops&amp;nbsp;to use computer only authentication pre and post login with no user level authentication.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Are there any issues with using computer only authentication using PEAP/MSCHAP?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 06:13:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-domain-computer-authentication/m-p/2804266#M56769</guid>
      <dc:creator>de1denta</dc:creator>
      <dc:date>2019-03-11T06:13:23Z</dc:date>
    </item>
    <item>
      <title>You have highlighted a</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-domain-computer-authentication/m-p/2804267#M56770</link>
      <description>&lt;P&gt;You have highlighted a majority of the methods for identifying domain computers. There are no issues with using computer only authentication other than all of your authenticated clients will show up as &lt;STRONG&gt;host/computer.domain.local&amp;nbsp;&lt;/STRONG&gt;so you will use the ability to be able to identify which user is on which computer, if that is a requirement.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Nov 2015 21:29:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-domain-computer-authentication/m-p/2804267#M56770</guid>
      <dc:creator>jj27</dc:creator>
      <dc:date>2015-11-09T21:29:35Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-domain-computer-authentication/m-p/2804268#M56771</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thank you for the response.&lt;/P&gt;
&lt;P&gt;Are&amp;nbsp;there&amp;nbsp;any&amp;nbsp;issues with PEAP/MSCHAP computer only authentication from a security perspective as well? I have had a few people request that we maintain 2-factor authentication of computer and user as its more secure so I'm being challenged with the computer only approach.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 10 Nov 2015 00:25:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-domain-computer-authentication/m-p/2804268#M56771</guid>
      <dc:creator>de1denta</dc:creator>
      <dc:date>2015-11-10T00:25:19Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-domain-computer-authentication/m-p/2804269#M56772</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Can anyone answer this? Much appreciated.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 11 Nov 2015 17:05:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-domain-computer-authentication/m-p/2804269#M56772</guid>
      <dc:creator>de1denta</dc:creator>
      <dc:date>2015-11-11T17:05:37Z</dc:date>
    </item>
    <item>
      <title>That largely depends on the</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-domain-computer-authentication/m-p/2804270#M56773</link>
      <description>&lt;P&gt;That largely depends on the organization's security policy.&amp;nbsp; As was mentioned, if you use machine authentication only, you will be missing the piece to the puzzle that tells you the user information.&amp;nbsp; In some organizations, the user info is required so machine auth only is simply not an option.&amp;nbsp; When it comes to an organization that doesn't have a security policy or one that is not complete enough to cover this topic, they just have to decide if they want to have the user info in their logs.&amp;nbsp; Using PEAP for machine authentication is somewhat common.&amp;nbsp; I would imagine financial institutions, government organizations, etc. will require user authentication as well.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Using machine authentication for differentiation of corp vs personal devices is clearly valid.&amp;nbsp; Requiring a user auth to have a cached, matching machine auth (MAR) does introduce caveats that you have to be aware of, no doubt.&amp;nbsp; But, there are still a number of customers that implement it.&lt;/P&gt;
&lt;P&gt;Also, you mentioned that EAP Chaining is not an option since there is no PKI.&amp;nbsp; But, you don't have to use certs for EAP Chaining.&amp;nbsp; Many customers that are concerned enough to implement EAP Chaining also have a PKI available, but not all.&lt;/P&gt;
&lt;P&gt;Tim&lt;/P&gt;</description>
      <pubDate>Wed, 11 Nov 2015 18:44:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-domain-computer-authentication/m-p/2804270#M56773</guid>
      <dc:creator>Tim Steele</dc:creator>
      <dc:date>2015-11-11T18:44:32Z</dc:date>
    </item>
  </channel>
</rss>

