<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Workgroup PC need to add on Domain in secure port in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/workgroup-pc-need-to-add-on-domain-in-secure-port/m-p/4433516#M568475</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1223492"&gt;@Anil Ku&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you have any challenges in case we have many branches. so, you need to separate build area for each branches?&lt;/P&gt;&lt;P&gt;other thing, we need to bring that workstation from user placed to that build area. to do that it required alot of time and will delay for fixing issue. example: sometime not for new workstation need to join domain, it can be exiting that have problem with domain not sycn or need to re-join.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cisco should have good solution for this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any other advise based on above concern. Thank you so much.&lt;/P&gt;</description>
    <pubDate>Thu, 15 Jul 2021 04:25:52 GMT</pubDate>
    <dc:creator>Sina Dy</dc:creator>
    <dc:date>2021-07-15T04:25:52Z</dc:date>
    <item>
      <title>Workgroup PC need to add on Domain in secure port</title>
      <link>https://community.cisco.com/t5/network-access-control/workgroup-pc-need-to-add-on-domain-in-secure-port/m-p/4394155#M566899</link>
      <description>&lt;P&gt;Hello Team,&lt;/P&gt;&lt;P&gt;I have Cisco ISE 2.4.. 802.1x with domain authentication is working perfectly..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;when i am adding any new laptop to domain.. I am not able to do that in secure port.. means port where 802.1x is already configured..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;in non secure port, I am able to build new laptop and add it into the domain..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any idea, what should i do here..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best Regards&lt;/P&gt;&lt;P&gt;Anil Singh&lt;/P&gt;</description>
      <pubDate>Tue, 27 Apr 2021 16:01:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/workgroup-pc-need-to-add-on-domain-in-secure-port/m-p/4394155#M566899</guid>
      <dc:creator>anilkumar.cisco</dc:creator>
      <dc:date>2021-04-27T16:01:12Z</dc:date>
    </item>
    <item>
      <title>Re: Workgroup PC need to add on Domain in secure port</title>
      <link>https://community.cisco.com/t5/network-access-control/workgroup-pc-need-to-add-on-domain-in-secure-port/m-p/4394160#M566900</link>
      <description>&lt;P&gt;In most cases that will be in the Build stage and Build area,&amp;nbsp; the ports can be unauthenticated, so you know these are used for building new devices and join them to Domain.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Apr 2021 16:09:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/workgroup-pc-need-to-add-on-domain-in-secure-port/m-p/4394160#M566900</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2021-04-27T16:09:31Z</dc:date>
    </item>
    <item>
      <title>Re: Workgroup PC need to add on Domain in secure port</title>
      <link>https://community.cisco.com/t5/network-access-control/workgroup-pc-need-to-add-on-domain-in-secure-port/m-p/4394401#M566911</link>
      <description>&lt;P&gt;Any alternative to this..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Shall i allow AD IP in pre-auth ACL.. after this things started working.. but seems some security issue..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also, if i will create an White-list MAC address on the ISE then.. the extra burden will come ISE Admin.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the problem is , The customer is challenging that the same thing was working perfectly on some old site.. which is decommision now..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is it possible.. i can will add computer Certificate + USer certificate manually to the PC which i am building and then&amp;nbsp; add it domain via dot1x policy...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best Regards&lt;/P&gt;&lt;P&gt;Anil Singh&lt;/P&gt;</description>
      <pubDate>Tue, 27 Apr 2021 23:21:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/workgroup-pc-need-to-add-on-domain-in-secure-port/m-p/4394401#M566911</guid>
      <dc:creator>anilkumar.cisco</dc:creator>
      <dc:date>2021-04-27T23:21:04Z</dc:date>
    </item>
    <item>
      <title>Re: Workgroup PC need to add on Domain in secure port</title>
      <link>https://community.cisco.com/t5/network-access-control/workgroup-pc-need-to-add-on-domain-in-secure-port/m-p/4394458#M566913</link>
      <description>&lt;P&gt;This is a common issue due to the way Windows builds work. See a similar discussion with some options in this post.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/network-access-control/pc-imaging-on-nac-secured-ports/td-p/3486098" target="_blank" rel="noopener"&gt;PC Imaging on NAC secured ports&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Apr 2021 02:30:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/workgroup-pc-need-to-add-on-domain-in-secure-port/m-p/4394458#M566913</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2021-04-28T02:30:04Z</dc:date>
    </item>
    <item>
      <title>Re: Workgroup PC need to add on Domain in secure port</title>
      <link>https://community.cisco.com/t5/network-access-control/workgroup-pc-need-to-add-on-domain-in-secure-port/m-p/4394884#M566942</link>
      <description>&lt;P&gt;I am confuse now..&lt;/P&gt;&lt;P&gt;after changing the switch side configuration order from mab dotx to dot1x mab.. the device of work group started authenticated via dot1x..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;is it because the workgroup device is already have certificate installed on it that's why....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Apr 2021 15:49:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/workgroup-pc-need-to-add-on-domain-in-secure-port/m-p/4394884#M566942</guid>
      <dc:creator>anilkumar.cisco</dc:creator>
      <dc:date>2021-04-28T15:49:02Z</dc:date>
    </item>
    <item>
      <title>Re: Workgroup PC need to add on Domain in secure port</title>
      <link>https://community.cisco.com/t5/network-access-control/workgroup-pc-need-to-add-on-domain-in-secure-port/m-p/4432910#M568449</link>
      <description>&lt;P&gt;Hi, I have the same case. Any suggestion for that compatible solution?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Note: we're ISE administrator, for&amp;nbsp; our current when have new PC that need to join domain we help whitelist from ISE dashboard or exclude the switch port without apply low impact mode then Desktop Support team can perform join domain and install software from their checklist. and after they completed we remove from whitelist. but this is required alot teams for help and also workload and low productivity. example sometime Desktop Support team need to fix issue or re-join domain immediately&amp;nbsp;but they need to contact ISE administrator&amp;nbsp;or network team to do whitelist or exclusive switch port.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;And our environment&amp;nbsp;before apply ISE, Desktop Support team can join or re-join domain at user place.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you so much for advise.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jul 2021 09:46:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/workgroup-pc-need-to-add-on-domain-in-secure-port/m-p/4432910#M568449</guid>
      <dc:creator>Sina Dy</dc:creator>
      <dc:date>2021-07-14T09:46:13Z</dc:date>
    </item>
    <item>
      <title>Re: Workgroup PC need to add on Domain in secure port</title>
      <link>https://community.cisco.com/t5/network-access-control/workgroup-pc-need-to-add-on-domain-in-secure-port/m-p/4432994#M568451</link>
      <description>&lt;P&gt;Hello Sina,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the solution is already provided by&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/388087"&gt;@Greg Gibbs&lt;/a&gt;&amp;nbsp;..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.cisco.com/t5/network-access-control/pc-imaging-on-nac-secured-ports/td-p/3486098" target="_blank"&gt;Solved: PC Imaging on NAC secured ports - Cisco Community&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we have to choose from the options..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have chosen option 1&lt;/P&gt;&lt;P&gt;i.e.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Provide a separate build area that does not have NAC enabled but requires physical security to access&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jul 2021 12:09:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/workgroup-pc-need-to-add-on-domain-in-secure-port/m-p/4432994#M568451</guid>
      <dc:creator>Anil Ku</dc:creator>
      <dc:date>2021-07-14T12:09:52Z</dc:date>
    </item>
    <item>
      <title>Re: Workgroup PC need to add on Domain in secure port</title>
      <link>https://community.cisco.com/t5/network-access-control/workgroup-pc-need-to-add-on-domain-in-secure-port/m-p/4433516#M568475</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1223492"&gt;@Anil Ku&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you have any challenges in case we have many branches. so, you need to separate build area for each branches?&lt;/P&gt;&lt;P&gt;other thing, we need to bring that workstation from user placed to that build area. to do that it required alot of time and will delay for fixing issue. example: sometime not for new workstation need to join domain, it can be exiting that have problem with domain not sycn or need to re-join.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cisco should have good solution for this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any other advise based on above concern. Thank you so much.&lt;/P&gt;</description>
      <pubDate>Thu, 15 Jul 2021 04:25:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/workgroup-pc-need-to-add-on-domain-in-secure-port/m-p/4433516#M568475</guid>
      <dc:creator>Sina Dy</dc:creator>
      <dc:date>2021-07-15T04:25:52Z</dc:date>
    </item>
    <item>
      <title>Re: Workgroup PC need to add on Domain in secure port</title>
      <link>https://community.cisco.com/t5/network-access-control/workgroup-pc-need-to-add-on-domain-in-secure-port/m-p/4436647#M568587</link>
      <description>&lt;P&gt;what i know.. I have already shared with you.. Best check with your Cisco Account Management team.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Jul 2021 13:05:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/workgroup-pc-need-to-add-on-domain-in-secure-port/m-p/4436647#M568587</guid>
      <dc:creator>anilkumar.cisco</dc:creator>
      <dc:date>2021-07-21T13:05:32Z</dc:date>
    </item>
  </channel>
</rss>

