<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Non AD users using Anyconnect and ISE in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/non-ad-users-using-anyconnect-and-ise/m-p/4427050#M568269</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/326046"&gt;@Marvin Rhoads&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your response. Your response seems most viable.&lt;/P&gt;&lt;P&gt;Can you please share some document to register certificates.&lt;/P&gt;&lt;P&gt;TIA&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 02 Jul 2021 05:28:10 GMT</pubDate>
    <dc:creator>Asfandyar70754</dc:creator>
    <dc:date>2021-07-02T05:28:10Z</dc:date>
    <item>
      <title>Non AD users using Anyconnect and ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/non-ad-users-using-anyconnect-and-ise/m-p/4425850#M568221</link>
      <description>&lt;P&gt;Hi guys&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;BR /&gt;We have some third party employees that VPN using Anyconnect on 5525-x asa.&lt;/P&gt;&lt;P&gt;The thing is that they are not part of our AD. We want to deploy ISE in our network and we are looking to authenticate/authorize users using ISE instead of Asa.&lt;/P&gt;&lt;P&gt;Usually non AD users can Anyconnect using any laptop they want, but we are thinking to limit this, we want these non AD users to connect via Anyconnect using only company assigned laptops. Is there some way we can do this, maybe is there any feature in Posturing?&lt;/P&gt;&lt;P&gt;Would really appreciate if you guys can help me out here.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jun 2021 05:14:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/non-ad-users-using-anyconnect-and-ise/m-p/4425850#M568221</guid>
      <dc:creator>Asfandyar70754</dc:creator>
      <dc:date>2021-06-30T05:14:18Z</dc:date>
    </item>
    <item>
      <title>Re: Non AD users using Anyconnect and ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/non-ad-users-using-anyconnect-and-ise/m-p/4425901#M568225</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1034099"&gt;@Asfandyar70754&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Use ISE posture (or ASA Dynamic Access Policies) to check for which AD domain the computer is joined to and the corporate issued AV/AM software or other attributes unique to your domain. If the device does not meet these requirements, they can be denied access.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jun 2021 07:21:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/non-ad-users-using-anyconnect-and-ise/m-p/4425901#M568225</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2021-06-30T07:21:42Z</dc:date>
    </item>
    <item>
      <title>Re: Non AD users using Anyconnect and ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/non-ad-users-using-anyconnect-and-ise/m-p/4425908#M568226</link>
      <description>&lt;P&gt;Hello Rob&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your reply.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Unfortunately the users(3rd part users/contractors) are not in AD, that is the issue.&lt;/P&gt;&lt;P&gt;Can we install some sort of certificate in their devices to ensure that they use only assigned devices?&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jun 2021 07:32:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/non-ad-users-using-anyconnect-and-ise/m-p/4425908#M568226</guid>
      <dc:creator>Asfandyar70754</dc:creator>
      <dc:date>2021-06-30T07:32:12Z</dc:date>
    </item>
    <item>
      <title>Re: Non AD users using Anyconnect and ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/non-ad-users-using-anyconnect-and-ise/m-p/4425957#M568228</link>
      <description>&lt;P&gt;If you like you can also create 3rd party users in AD, with out any otehr resources access (that is what we do).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jun 2021 09:21:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/non-ad-users-using-anyconnect-and-ise/m-p/4425957#M568228</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2021-06-30T09:21:18Z</dc:date>
    </item>
    <item>
      <title>Re: Non AD users using Anyconnect and ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/non-ad-users-using-anyconnect-and-ise/m-p/4425962#M568229</link>
      <description>&lt;P&gt;Hi Balaji,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is this the only solution?&lt;/P&gt;&lt;P&gt;We have number of new contractors every other month we want to avoid the hassle of making users in AD again and again.&lt;/P&gt;&lt;P&gt;TIA&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jun 2021 09:32:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/non-ad-users-using-anyconnect-and-ise/m-p/4425962#M568229</guid>
      <dc:creator>Asfandyar70754</dc:creator>
      <dc:date>2021-06-30T09:32:14Z</dc:date>
    </item>
    <item>
      <title>Re: Non AD users using Anyconnect and ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/non-ad-users-using-anyconnect-and-ise/m-p/4425986#M568230</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1034099"&gt;@Asfandyar70754&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Fine, you can use the ISE Local Identity Store for the user accounts.....but you are issuing them with AD joined corporate laptop, so why not give them an AD user account?&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jun 2021 10:34:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/non-ad-users-using-anyconnect-and-ise/m-p/4425986#M568230</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2021-06-30T10:34:36Z</dc:date>
    </item>
    <item>
      <title>Re: Non AD users using Anyconnect and ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/non-ad-users-using-anyconnect-and-ise/m-p/4426011#M568232</link>
      <description>&lt;P&gt;the user not required any Local access ? you can use Local account that is not best ( as your requirement different with many other 3rd parties.)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;or setup different source for these 3rd party in your area for authentication.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jun 2021 11:23:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/non-ad-users-using-anyconnect-and-ise/m-p/4426011#M568232</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2021-06-30T11:23:12Z</dc:date>
    </item>
    <item>
      <title>Re: Non AD users using Anyconnect and ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/non-ad-users-using-anyconnect-and-ise/m-p/4426083#M568236</link>
      <description>&lt;P&gt;You can check both machine and user attributes as part of your authorization condition.&lt;/P&gt;
&lt;P&gt;The machine check can be things like presence of a registry key showing the computer is domain-joined or a field in a certificate (for instance the issuing CA) or any number of other checks. Of course the certificate check assumes an enterprise CA is already setup and able to issue certificates to machines.&lt;/P&gt;
&lt;P&gt;So the check could be IF machine has key xxx and user is member of ISE local identity group yyy (i.e., NOT AD authentication for the user) then assign an Authorization result that is appropriate for third party employees.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jun 2021 13:06:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/non-ad-users-using-anyconnect-and-ise/m-p/4426083#M568236</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2021-06-30T13:06:50Z</dc:date>
    </item>
    <item>
      <title>Re: Non AD users using Anyconnect and ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/non-ad-users-using-anyconnect-and-ise/m-p/4426480#M568252</link>
      <description>&lt;P&gt;Hello Marvin&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks a lot for your response.&lt;/P&gt;&lt;P&gt;Can you please share some document for registering the &lt;STRONG&gt;certificates&lt;/STRONG&gt;.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jul 2021 05:13:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/non-ad-users-using-anyconnect-and-ise/m-p/4426480#M568252</guid>
      <dc:creator>Asfandyar70754</dc:creator>
      <dc:date>2021-07-01T05:13:54Z</dc:date>
    </item>
    <item>
      <title>Re: Non AD users using Anyconnect and ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/non-ad-users-using-anyconnect-and-ise/m-p/4427050#M568269</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/326046"&gt;@Marvin Rhoads&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your response. Your response seems most viable.&lt;/P&gt;&lt;P&gt;Can you please share some document to register certificates.&lt;/P&gt;&lt;P&gt;TIA&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jul 2021 05:28:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/non-ad-users-using-anyconnect-and-ise/m-p/4427050#M568269</guid>
      <dc:creator>Asfandyar70754</dc:creator>
      <dc:date>2021-07-02T05:28:10Z</dc:date>
    </item>
    <item>
      <title>Re: Non AD users using Anyconnect and ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/non-ad-users-using-anyconnect-and-ise/m-p/4428190#M568320</link>
      <description>&lt;P&gt;Check out some of videos from Lab Minutes:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="http://www.labminutes.com/sec0134_ssl_vpn_anyconnect_secure_mobility_scep_proxy_1" target="_blank"&gt;SEC0134 - SSL VPN AnyConnect Secure Mobility SCEP Proxy (Part 1)&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="http://www.labminutes.com/sec0134_ssl_vpn_anyconnect_secure_mobility_scep_proxy_2" target="_blank"&gt;SEC0134 - SSL VPN AnyConnect Secure Mobility SCEP Proxy (Part 2)&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="http://www.labminutes.com/sec0213_ise_20_internal_ca_scep_anyconnect_vpn_1" target="_blank"&gt;SEC0213 - ISE 2.0 Internal CA SCEP with AnyConnect VPN (Part 1)&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="http://www.labminutes.com/sec0213_ise_20_internal_ca_scep_anyconnect_vpn_2" target="_blank"&gt;SEC0213 - ISE 2.0 Internal CA SCEP with AnyConnect VPN (Part 2)&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 16:54:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/non-ad-users-using-anyconnect-and-ise/m-p/4428190#M568320</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2021-07-05T16:54:08Z</dc:date>
    </item>
  </channel>
</rss>

