<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Same username in two domains. in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/same-username-in-two-domains/m-p/4474344#M569948</link>
    <description>&lt;P&gt;I do have a custom AD scope that has both blue.red.com and red.com in the authentication search list.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But in my case it never checks the blue.red.com domain if it finds the username in the red.com domain.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My workaround was to change the order in which ISE looks at the domains.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The perfect solution for me would be ISE looking up both domains and then using the one that authenticates successfull,&lt;BR /&gt;I just dont see any way to get that working in my setup.&lt;/P&gt;</description>
    <pubDate>Mon, 27 Sep 2021 07:47:48 GMT</pubDate>
    <dc:creator>Janne K.</dc:creator>
    <dc:date>2021-09-27T07:47:48Z</dc:date>
    <item>
      <title>Same username in two domains.</title>
      <link>https://community.cisco.com/t5/network-access-control/same-username-in-two-domains/m-p/4470100#M569814</link>
      <description>&lt;P&gt;What would be the correct setup in ise for allowing accounts from different AD's but same username to log into my wireless.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;E.G. tomparis@voyager.com exist in the first domain and tomparis@bridge.voyager.com exist in the second domain. Both with the same username.&lt;BR /&gt;The account belongs to the same person, and changing the username for one of them is in my case not an option because of other infrastructure that depend on it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a fair amount of users that have the same 'problem' and want to find a more suitable solution than asking the user to actually write either &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/500397"&gt;@voyager&lt;/a&gt;.com or &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/19006"&gt;@bridge&lt;/a&gt;.voyager.com, as many users have no idea when to use the one or the other.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Would it work if i create two identical authentication policy where the first one looks into the voyager.com and i set the option to&lt;/P&gt;&lt;P&gt;'if auth fail' -&amp;gt; CONTINUE&lt;/P&gt;&lt;P&gt;'if User not found' -&amp;gt; CONTINUE&lt;/P&gt;&lt;P&gt;and then the second policy to look into the bridge.voyager.com with the options to&lt;/P&gt;&lt;P&gt;'if auth fail' -&amp;gt; REJECT&lt;/P&gt;&lt;P&gt;'if User not found' -&amp;gt; REJECT&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm not sure if this works.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Sep 2021 13:18:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/same-username-in-two-domains/m-p/4470100#M569814</guid>
      <dc:creator>Janne K.</dc:creator>
      <dc:date>2021-09-20T13:18:30Z</dc:date>
    </item>
    <item>
      <title>Re: Same username in two domains.</title>
      <link>https://community.cisco.com/t5/network-access-control/same-username-in-two-domains/m-p/4470151#M569818</link>
      <description>&lt;P&gt;Hello ;&lt;/P&gt;&lt;P&gt;it will be easy if you work with group, you create group in DC and you add users authorized to connect after that in authorization policy you add condition with external group created&lt;/P&gt;</description>
      <pubDate>Mon, 20 Sep 2021 14:18:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/same-username-in-two-domains/m-p/4470151#M569818</guid>
      <dc:creator>Nadia Bbz</dc:creator>
      <dc:date>2021-09-20T14:18:21Z</dc:date>
    </item>
    <item>
      <title>Re: Same username in two domains.</title>
      <link>https://community.cisco.com/t5/network-access-control/same-username-in-two-domains/m-p/4470181#M569821</link>
      <description>&lt;P&gt;Do users have same password on both accounts? If so you can use identity rewrite to change the username before it gets forwarded to AD: &lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2021-09-20 at 10.00.49 AM.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/131502i120030CCFC6D509B/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2021-09-20 at 10.00.49 AM.png" alt="Screen Shot 2021-09-20 at 10.00.49 AM.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Sep 2021 15:02:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/same-username-in-two-domains/m-p/4470181#M569821</guid>
      <dc:creator>howon</dc:creator>
      <dc:date>2021-09-20T15:02:48Z</dc:date>
    </item>
    <item>
      <title>Re: Same username in two domains.</title>
      <link>https://community.cisco.com/t5/network-access-control/same-username-in-two-domains/m-p/4470512#M569830</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/974132"&gt;@Nadia Bbz&lt;/a&gt;Yes, we already implement groups, but ise is matching the user from the wrong AD.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/386008"&gt;@howon&lt;/a&gt;They do not have the same password for the two accounts.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As a workaround right now i have changed the order in the Identity Source Sequences so that it checks the other domain first where the 'correct' user is.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Sep 2021 07:41:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/same-username-in-two-domains/m-p/4470512#M569830</guid>
      <dc:creator>Janne K.</dc:creator>
      <dc:date>2021-09-21T07:41:05Z</dc:date>
    </item>
    <item>
      <title>Re: Same username in two domains.</title>
      <link>https://community.cisco.com/t5/network-access-control/same-username-in-two-domains/m-p/4470566#M569834</link>
      <description>&lt;P&gt;Hello ;&lt;/P&gt;&lt;P&gt;did you added all the domain in Administration -&amp;gt; identity Management -&amp;gt; External Identity Sources -&amp;gt; Active directory&lt;/P&gt;&lt;P&gt;in Identity Source Sequence&amp;nbsp; have you added all domains in authentication search list&lt;/P&gt;</description>
      <pubDate>Tue, 21 Sep 2021 09:33:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/same-username-in-two-domains/m-p/4470566#M569834</guid>
      <dc:creator>Nadia Bbz</dc:creator>
      <dc:date>2021-09-21T09:33:49Z</dc:date>
    </item>
    <item>
      <title>Re: Same username in two domains.</title>
      <link>https://community.cisco.com/t5/network-access-control/same-username-in-two-domains/m-p/4474260#M569944</link>
      <description>&lt;P&gt;Try using the built-in All_AD_Join_Points or an AD scope.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Below are the results from my tests using the Advanced Tools &amp;gt; Test User for All Join Points&lt;/P&gt;
&lt;PRE&gt;Test Username : test
ISE NODE : ise-1.demo.local
Scope : All_AD_Join_Points
Authentication Result : SUCCESS

Authentication Domain : demo.local
User found in Instance : demoAD
User Principal Name : test@demo.local
User Distinguished Name : CN=test,CN=Users,DC=demo,DC=local

Groups : 2 found.
Attributes : 32 found.

Authentication time : 117 ms.
Groups fetching time : 2 ms.
Attributes fetching time : 5 ms.

Processing Steps:
05:38:02:717: Resolving identity - test
05:38:02:717: Search for matching accounts at join point - demo.local
05:38:02:723: Single matching account found in forest - demo.local
05:38:02:723: Search for matching accounts at join point - ise.local
05:38:02:729: Single matching account found in forest - ise.local
05:38:02:729: Identity resolution detected multiple matching accounts
05:38:02:738: RPC Logon request succeeded - test@demo.local
05:38:02:833: RPC Logon request failed - STATUS_WRONG_PASSWORD,ERROR_INVALID_PASSWORD,test@ise.local&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;Test Username : test
ISE NODE : ise-1.demo.local
Scope : All_AD_Join_Points
Authentication Result : SUCCESS

Authentication Domain : ise.local
User found in Instance : iseAD
User Principal Name : test@ise.local
User Distinguished Name : CN=test,CN=Users,DC=ise,DC=local

Groups : 2 found.
Attributes : 32 found.

Authentication time : 61 ms.
Groups fetching time : 11 ms.
Attributes fetching time : 6 ms.

Processing Steps:
05:39:14:866: Resolving identity - test
05:39:14:866: Search for matching accounts at join point - demo.local
05:39:14:873: Single matching account found in forest - demo.local
05:39:14:873: Search for matching accounts at join point - ise.local
05:39:14:879: Single matching account found in forest - ise.local
05:39:14:879: Identity resolution detected multiple matching accounts
05:39:14:916: RPC Logon request failed - STATUS_WRONG_PASSWORD,ERROR_INVALID_PASSWORD,test@demo.local
05:39:14:926: RPC Logon request succeeded - test@ise.local&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Sep 2021 05:42:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/same-username-in-two-domains/m-p/4474260#M569944</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2021-09-27T05:42:51Z</dc:date>
    </item>
    <item>
      <title>Re: Same username in two domains.</title>
      <link>https://community.cisco.com/t5/network-access-control/same-username-in-two-domains/m-p/4474344#M569948</link>
      <description>&lt;P&gt;I do have a custom AD scope that has both blue.red.com and red.com in the authentication search list.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But in my case it never checks the blue.red.com domain if it finds the username in the red.com domain.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My workaround was to change the order in which ISE looks at the domains.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The perfect solution for me would be ISE looking up both domains and then using the one that authenticates successfull,&lt;BR /&gt;I just dont see any way to get that working in my setup.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Sep 2021 07:47:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/same-username-in-two-domains/m-p/4474344#M569948</guid>
      <dc:creator>Janne K.</dc:creator>
      <dc:date>2021-09-27T07:47:48Z</dc:date>
    </item>
  </channel>
</rss>

