<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Issue with Windows 10 and PEAP in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/issue-with-windows-10-and-peap/m-p/4489795#M570561</link>
    <description>&lt;P&gt;Hi ,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Did you got any solution for this , I face same issue but not getting any solution for this .&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please let me know if you got solution for this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 21 Oct 2021 10:58:07 GMT</pubDate>
    <dc:creator>Mahendervyas35821</dc:creator>
    <dc:date>2021-10-21T10:58:07Z</dc:date>
    <item>
      <title>Issue with Windows 10 and PEAP</title>
      <link>https://community.cisco.com/t5/network-access-control/issue-with-windows-10-and-peap/m-p/4146597#M562707</link>
      <description>&lt;P&gt;&amp;nbsp; &amp;nbsp; Hello, community&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We're experiencing a following issue with our&amp;nbsp; ISE 2.7 (patch 2).&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PEAP&amp;nbsp; doesn't work if we don't save credentials manually.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We can't save credential for all our employees for an obvious reason of security. (We don't&amp;nbsp; know each particular password and we can't run GPO either).&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PEAP runs smoothly if we save credentials.&amp;nbsp; &amp;nbsp;Anyconnect NAM (EAP-FAST) also works great but we still need to be able to run native 802.1x on Windows 10 PCs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We suspect it can be Windows 10 supplicant ( the version is 1703 build 15063.2108) . Should we apply some MSFT KB patches? If so which&amp;nbsp; are those?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If anyone had this issue please comment.&lt;/P&gt;&lt;P&gt;Thank You!&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Save Credentials.PNG" style="width: 831px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/82859i30D6BBA145E901D8/image-size/large?v=v2&amp;amp;px=999" role="button" title="Save Credentials.PNG" alt="Save Credentials.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Sep 2020 18:20:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/issue-with-windows-10-and-peap/m-p/4146597#M562707</guid>
      <dc:creator>Igor.Dyakonov</dc:creator>
      <dc:date>2020-09-04T18:20:17Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with Windows 10 and PEAP</title>
      <link>https://community.cisco.com/t5/network-access-control/issue-with-windows-10-and-peap/m-p/4146802#M562711</link>
      <description>&lt;P&gt;First thing is that your version of Windows 10 that you are running is End of Service.&amp;nbsp; There have been quite a few versions since then.&amp;nbsp; Check out the following page for more information on the Windows 10 versions and associated KB articles:&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.microsoft.com/en-us/windows/release-information/" target="_blank"&gt;https://docs.microsoft.com/en-us/windows/release-information/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Are your computers joined to a domain?&amp;nbsp; When you say PEAP doesn't work, can you provide more details?&amp;nbsp; Is it a case of the computer having no access when the user is not logged in?&lt;/P&gt;</description>
      <pubDate>Sat, 05 Sep 2020 15:34:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/issue-with-windows-10-and-peap/m-p/4146802#M562711</guid>
      <dc:creator>Colby LeMaire</dc:creator>
      <dc:date>2020-09-05T15:34:52Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with Windows 10 and PEAP</title>
      <link>https://community.cisco.com/t5/network-access-control/issue-with-windows-10-and-peap/m-p/4146840#M562712</link>
      <description>&lt;P&gt;&amp;nbsp;&amp;nbsp; Hi, Colby&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm aware that our PCs has EoS version of Windows 10. I can't do much there as it's not my decision.&lt;/P&gt;&lt;P&gt;Thank You for the link. Not sure whether we can still apply some dot1x related patches to our current Win10 or just upgrade to newer version of Win10.&amp;nbsp; The last option "upgrade Win10" will be just too long to wait in our implementation of ISE in this moment.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Are your computers joined to a domain?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Yes, they are.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;When you say PEAP doesn't work, can you provide more details? &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;PEAP (MSHCAP) doesn't work if we don't save credentials manually (screenshot in my previous post) however&amp;nbsp;PEAP runs smoothly if we save credentials.&amp;nbsp; We have tried to "Lock the user" and "Restart" Windows 10 but nothing helps.&lt;/P&gt;&lt;P&gt;So it's not that ISE has some issue it's rather supplicant PCs don't send user credentials. Running from switch "show auth sess int x/x"&amp;nbsp; and doing some debug we can only see that dot1x is rather "running" or "stopped".&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is a complete configuration of dot1x on a PC.&amp;nbsp; Nothing special.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PEAP config.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/82879iE988E0A9B21F5BD6/image-size/large?v=v2&amp;amp;px=999" role="button" title="PEAP config.png" alt="PEAP config.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;gt;&amp;gt;Is it a case of the computer having no access when the user is not logged in?&lt;/P&gt;&lt;P&gt;User always has an access because right now these ports run in open mode.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 05 Sep 2020 19:25:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/issue-with-windows-10-and-peap/m-p/4146840#M562712</guid>
      <dc:creator>Igor.Dyakonov</dc:creator>
      <dc:date>2020-09-05T19:25:41Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with Windows 10 and PEAP</title>
      <link>https://community.cisco.com/t5/network-access-control/issue-with-windows-10-and-peap/m-p/4146895#M562713</link>
      <description>&lt;P&gt;Ok, I see the issue now.&amp;nbsp; It is not a problem with the supplicant at all.&amp;nbsp; You are configured to do "User authentication" only.&amp;nbsp; With Windows, the native supplicant does not have access to the user credentials until the user logs in.&amp;nbsp; Or as in your case, you save the credentials that the supplicant should use before the user logs in.&amp;nbsp; So that makes sense that you see 802.1x running or stopped because the supplicant won't respond unless it has credentials to send.&lt;/P&gt;&lt;P&gt;I highly recommend changing your supplicant configuration to "Computer authentication" so that you know the computers connecting are machines within your domain.&amp;nbsp; And the computers would be able to authenticate to the network before the user logs in.&lt;/P&gt;</description>
      <pubDate>Sun, 06 Sep 2020 03:27:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/issue-with-windows-10-and-peap/m-p/4146895#M562713</guid>
      <dc:creator>Colby LeMaire</dc:creator>
      <dc:date>2020-09-06T03:27:09Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with Windows 10 and PEAP</title>
      <link>https://community.cisco.com/t5/network-access-control/issue-with-windows-10-and-peap/m-p/4147083#M562717</link>
      <description>&lt;P&gt;Is the screenshot above that shows the 'Automatically use my Windows logon name...' option ticked from a working or non-working PC? If this is from a working PC, you might be running into an issue with Credential Guard being enabled for the non-working PCs.&lt;/P&gt;
&lt;P&gt;See &lt;A href="https://community.cisco.com/t5/network-access-control/5440-supplicant-abandon-session-start-new-peap-mschapv2/td-p/4124461" target="_blank" rel="noopener"&gt;this post&lt;/A&gt; for more info on Credential Guard.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Sep 2020 00:36:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/issue-with-windows-10-and-peap/m-p/4147083#M562717</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2020-09-07T00:36:27Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with Windows 10 and PEAP</title>
      <link>https://community.cisco.com/t5/network-access-control/issue-with-windows-10-and-peap/m-p/4147294#M562728</link>
      <description>&lt;P&gt;&lt;STRONG&gt;&amp;gt;&amp;gt;With Windows, the native supplicant does not have access to the user credentials until the user logs in.&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The native supplicant should have access to the user credential because of enabled checkbox "Automatically use my Windows logon name and password". Even if it hasn't a user credentials Windows should&amp;nbsp; presenet a Security pop-up window like this&amp;nbsp;&lt;A href="https://filestore.community.support.microsoft.com/api/images/112e975c-62f9-4bb0-97e6-2b8cbc7dcaa5" target="_blank"&gt;https://filestore.community.support.microsoft.com/api/images/112e975c-62f9-4bb0-97e6-2b8cbc7dcaa5&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;gt;&amp;gt;I highly recommend changing your supplicant configuration to "Computer authentication" so that you know the computers connecting are machines within your domain.&amp;nbsp; And the computers would be able to authenticate to the network before the user logs in.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I've already ran different options as&amp;nbsp; "Computer auth" or "User or Computer auth" . Computer authenticates but user doesn't.&amp;nbsp; We still need to authenticate user.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Sep 2020 12:29:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/issue-with-windows-10-and-peap/m-p/4147294#M562728</guid>
      <dc:creator>Igor.Dyakonov</dc:creator>
      <dc:date>2020-09-07T12:29:38Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with Windows 10 and PEAP</title>
      <link>https://community.cisco.com/t5/network-access-control/issue-with-windows-10-and-peap/m-p/4147298#M562729</link>
      <description>&lt;P&gt;&lt;STRONG&gt;&amp;gt;&amp;gt;Is the screenshot above that shows the 'Automatically use my Windows logon name...' option ticked from a working or non-working PC?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Non-working PC. I have tried to disable/enable this option but it dind't help.Even if it hasn't a user credentials Windows should&amp;nbsp; presenet a Security pop-up window like this&amp;nbsp;&lt;A href="https://filestore.community.support.microsoft.com/api/images/112e975c-62f9-4bb0-97e6-2b8cbc7dcaa5" target="_blank" rel="nofollow noopener noreferrer"&gt;https://filestore.community.support.microsoft.com/api/images/112e975c-62f9-4bb0-97e6-2b8cbc7dcaa5&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;But it doesn't show this popup&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;gt;&amp;gt;you might be running into an issue with Credential Guard being enabled for the non-working PCs.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Yes,&amp;nbsp; it's clearly something to do with Windows credentials.&amp;nbsp; I've disabled every option related to Credential Guard. Still it didn't help.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Sep 2020 12:37:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/issue-with-windows-10-and-peap/m-p/4147298#M562729</guid>
      <dc:creator>Igor.Dyakonov</dc:creator>
      <dc:date>2020-09-07T12:37:10Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with Windows 10 and PEAP</title>
      <link>https://community.cisco.com/t5/network-access-control/issue-with-windows-10-and-peap/m-p/4489795#M570561</link>
      <description>&lt;P&gt;Hi ,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Did you got any solution for this , I face same issue but not getting any solution for this .&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please let me know if you got solution for this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Oct 2021 10:58:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/issue-with-windows-10-and-peap/m-p/4489795#M570561</guid>
      <dc:creator>Mahendervyas35821</dc:creator>
      <dc:date>2021-10-21T10:58:07Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with Windows 10 and PEAP</title>
      <link>https://community.cisco.com/t5/network-access-control/issue-with-windows-10-and-peap/m-p/4793101#M580449</link>
      <description>&lt;P&gt;Hello Colby:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;This was very helpful information. I was experiencing similar issues however now I am my users are have to accept multiple user certificates and in the event they log into a new machine, they again have to accept the cert. If I set the supplicant to Computer Authentcation only, does that resolve that issue as they would only accept the cert presented to them by ISE during initial access.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Mar 2023 00:01:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/issue-with-windows-10-and-peap/m-p/4793101#M580449</guid>
      <dc:creator>leejasper</dc:creator>
      <dc:date>2023-03-14T00:01:22Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with Windows 10 and PEAP</title>
      <link>https://community.cisco.com/t5/network-access-control/issue-with-windows-10-and-peap/m-p/4828094#M581530</link>
      <description>&lt;P&gt;&lt;STRONG&gt;&amp;gt;&amp;gt;With Windows, the native supplicant does not have access to the user credentials until the user logs in.&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;My question is:&lt;/P&gt;
&lt;P&gt;NAM (supplicant Cisco) does have it?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 May 2023 23:57:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/issue-with-windows-10-and-peap/m-p/4828094#M581530</guid>
      <dc:creator>isravr</dc:creator>
      <dc:date>2023-05-03T23:57:33Z</dc:date>
    </item>
  </channel>
</rss>

