<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: EAP Chaining ? in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/eap-chaining/m-p/4441848#M568783</link>
    <description>&lt;P&gt;Hi Bakaji,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for replying.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Everything works when the user initiate the computer at office, (1) machine gets authenticated first and then, (2) user gets authenticated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The scenario when it fails is:&lt;/P&gt;&lt;P&gt;MAR timeout is 8 hours in ISE.&lt;/P&gt;&lt;P&gt;User comes from home and computer is locked, then unlocks. Then user cannot access the wireless network unless user log off so machine can be authenticated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My question is, can the machine and the user be authenticated when the user already initiated a session in the computer at home.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Edouard.&lt;/P&gt;</description>
    <pubDate>Fri, 30 Jul 2021 14:53:55 GMT</pubDate>
    <dc:creator>EdouardZorrilla0939</dc:creator>
    <dc:date>2021-07-30T14:53:55Z</dc:date>
    <item>
      <title>EAP Chaining ?</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-chaining/m-p/4441536#M568776</link>
      <description>&lt;P&gt;Greetings,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have deployed machine and user authentication, and there is something unexpected.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When the user, who has signed in to W10, tries to connect the computer, the access is denied because the machine has not authenticated first.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can the W10 supplicant send the machine and user authentication when the user has already logged in to W10 ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Edouard.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Jul 2021 04:24:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-chaining/m-p/4441536#M568776</guid>
      <dc:creator>EdouardZorrilla0939</dc:creator>
      <dc:date>2021-07-30T04:24:57Z</dc:date>
    </item>
    <item>
      <title>Re: EAP Chaining ?</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-chaining/m-p/4441699#M568778</link>
      <description>&lt;P&gt;In general Deployment, Device authenticate with Certificate installed already, and user authenticated with giiving user and password(based on the AD or any other form to get in to network), Once it authenticated it not required again and again, Until device moved or different network.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;Can the W10 supplicant send the machine and user authentication when the user has already logged in to W10 ?&lt;/PRE&gt;
&lt;P&gt;not sure we undersand this quesiton correctly, can you explain this, if the user already logged in why he need to send that information again ?&lt;/P&gt;
&lt;P&gt;based on the first login user conencted port on the switch and dACL already populated right ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;or do i miss understood your requirement ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;good reference :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.ise-support.com/2020/05/29/using-teap-for-eap-chaining/" target="_blank"&gt;https://www.ise-support.com/2020/05/29/using-teap-for-eap-chaining/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Jul 2021 09:49:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-chaining/m-p/4441699#M568778</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2021-07-30T09:49:55Z</dc:date>
    </item>
    <item>
      <title>Re: EAP Chaining ?</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-chaining/m-p/4441744#M568779</link>
      <description>&lt;P&gt;In regard to eap-chaining,&lt;SPAN&gt;&amp;nbsp;ISE 2.7 and Windows 10 build 2004 (May 2020) and later added support for&amp;nbsp;the industry standard TEAP.&amp;nbsp; Prior to this eap-chaining required the use of the Cisco proprietary EAP-FAST, and in order to use EAP-FAST you needed to use the AnyConnect NAM module.&amp;nbsp; Remember that eap-chaining grants you the ability to chain user and machine authentications together.&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN&gt;Now with TEAP you can use the native supplicant but you need ISE 2.7 or later as well as the specific Win10 OS.&amp;nbsp; Take a look at the following for examples &amp;amp; a better understanding of eap-chaining/supplicant usage:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://community.cisco.com/t5/security-documents/teap-for-windows-10-using-group-policy-and-ise-teap/ta-p/4134289" target="_blank"&gt;TEAP for Windows 10 using Group Policy and ISE TEAP Configuration - Cisco Community&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless-mobility/eap-fast/200322-Understanding-EAP-FAST-and-Chaining-imp.html#anc0" target="_blank"&gt;Understanding EAP-FAST and Chaining implementations on AnyConnect NAM and ISE - Cisco&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;HTH!&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Jul 2021 11:45:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-chaining/m-p/4441744#M568779</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2021-07-30T11:45:48Z</dc:date>
    </item>
    <item>
      <title>Re: EAP Chaining ?</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-chaining/m-p/4441848#M568783</link>
      <description>&lt;P&gt;Hi Bakaji,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for replying.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Everything works when the user initiate the computer at office, (1) machine gets authenticated first and then, (2) user gets authenticated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The scenario when it fails is:&lt;/P&gt;&lt;P&gt;MAR timeout is 8 hours in ISE.&lt;/P&gt;&lt;P&gt;User comes from home and computer is locked, then unlocks. Then user cannot access the wireless network unless user log off so machine can be authenticated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My question is, can the machine and the user be authenticated when the user already initiated a session in the computer at home.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Edouard.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Jul 2021 14:53:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-chaining/m-p/4441848#M568783</guid>
      <dc:creator>EdouardZorrilla0939</dc:creator>
      <dc:date>2021-07-30T14:53:55Z</dc:date>
    </item>
    <item>
      <title>Re: EAP Chaining ?</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-chaining/m-p/4441851#M568784</link>
      <description>&lt;P&gt;Hi Mike,&lt;/P&gt;&lt;P&gt;Thanks for replying.&lt;/P&gt;&lt;P&gt;Please let me read the documentation you share and maybe I can find the answer there.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Edouard.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Jul 2021 14:58:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-chaining/m-p/4441851#M568784</guid>
      <dc:creator>EdouardZorrilla0939</dc:creator>
      <dc:date>2021-07-30T14:58:17Z</dc:date>
    </item>
    <item>
      <title>Re: EAP Chaining ?</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-chaining/m-p/4441870#M568785</link>
      <description>&lt;PRE&gt;My question is, can the machine and the user be authenticated when the user already initiated a session in the computer at home.&lt;/PRE&gt;
&lt;P&gt;no it wont be work this way, because the Port conencted is changed, and IP address going to change here. (there is some tweaks required to be done Windows side)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/833210"&gt;@Mike.Cifelli&lt;/a&gt;&amp;nbsp; given you good resouces to resolve this issue, still issue let us know.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Jul 2021 15:31:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-chaining/m-p/4441870#M568785</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2021-07-30T15:31:44Z</dc:date>
    </item>
  </channel>
</rss>

