<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi, I read the thread and it in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise1-4-user-authentication-issue-on-wlan/m-p/2748974#M57329</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I read the thread and it seems there is several limitations on how this works and in the same article not recommended.&lt;/P&gt;&lt;P&gt;However lets see if we can reproduce how it worked in your earlier version, when your wireless device connects to the SSID, do you see a successful machine authz?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Jason&lt;/P&gt;</description>
    <pubDate>Thu, 01 Oct 2015 11:48:27 GMT</pubDate>
    <dc:creator>Jason van den Berg</dc:creator>
    <dc:date>2015-10-01T11:48:27Z</dc:date>
    <item>
      <title>ISE1.4 - User authentication issue on WLAN</title>
      <link>https://community.cisco.com/t5/network-access-control/ise1-4-user-authentication-issue-on-wlan/m-p/2748969#M57321</link>
      <description>&lt;P&gt;Hi Experts,&lt;/P&gt;&lt;P&gt;Now, I do implement ISE 1.4 for machine and user authentication on wired and wirless network.&lt;/P&gt;&lt;P&gt;For wired network no issue.&lt;/P&gt;&lt;P&gt;For wireless network when I connect to ssid that integrate with ISE, The authorization has deny.&lt;/P&gt;&lt;P&gt;this the rule in authoraization.&lt;/P&gt;&lt;P&gt;first rule; Machine Authen&lt;/P&gt;&lt;P&gt;Radius:Called-Station-ID == Containt == Office&lt;/P&gt;&lt;P&gt;3D-AD:ExternalGroups == domain computer&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Second rule; User Authen&lt;/P&gt;&lt;P&gt;Radius:Called-Station-ID == Containt == Office&lt;/P&gt;&lt;P&gt;3D-AD:ExternalGroups == domain user&lt;/P&gt;&lt;P&gt;Network Access:WasMachineAuthenticated ==True&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I delete condition on Second rule in past of Network Access:WasMachineAuthenticated ==True. It can authentication pass.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could you please advise to me that root cause is?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 06:06:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise1-4-user-authentication-issue-on-wlan/m-p/2748969#M57321</guid>
      <dc:creator>Sarayuth.s01</dc:creator>
      <dc:date>2019-03-11T06:06:42Z</dc:date>
    </item>
    <item>
      <title>Hi, By the sounds of it you</title>
      <link>https://community.cisco.com/t5/network-access-control/ise1-4-user-authentication-issue-on-wlan/m-p/2748970#M57323</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;By the sounds of it you want to setup EAP chaining. I would suggest you read trough this document that has a good example on how to achieve this. The only missing part would be the AD groups which you can add however it also seems you using the default groups anyways.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/c/dam/en/us/td/docs/security/ise/how_to/HowTo-82_Deploy_EAP_Chaining.pdf"&gt;http://www.cisco.com/c/dam/en/us/td/docs/security/ise/how_to/HowTo-82_Deploy_EAP_Chaining.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Jason&lt;/P&gt;</description>
      <pubDate>Thu, 01 Oct 2015 10:28:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise1-4-user-authentication-issue-on-wlan/m-p/2748970#M57323</guid>
      <dc:creator>Jason van den Berg</dc:creator>
      <dc:date>2015-10-01T10:28:21Z</dc:date>
    </item>
    <item>
      <title>Hi Jason,I'm not to set up</title>
      <link>https://community.cisco.com/t5/network-access-control/ise1-4-user-authentication-issue-on-wlan/m-p/2748971#M57325</link>
      <description>&lt;P&gt;Hi Jason,&lt;/P&gt;&lt;P&gt;I'm not to set up EAP chaining, I using PEAP and EAP-TLS authentication method. I'm authen pass but stuck in authorization if apply&amp;nbsp;condition "&lt;STRONG&gt;&lt;SPAN style="font-size: 14.399998664856px; line-height: normal;"&gt;Network Access:WasMachineAuthenticated ==True" &amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN style="font-size: 14.399998664856px; line-height: normal;"&gt;so It go to default authoraization(Deny access).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Oct 2015 10:41:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise1-4-user-authentication-issue-on-wlan/m-p/2748971#M57325</guid>
      <dc:creator>Sarayuth.s01</dc:creator>
      <dc:date>2015-10-01T10:41:21Z</dc:date>
    </item>
    <item>
      <title>Hi, If you not using eap</title>
      <link>https://community.cisco.com/t5/network-access-control/ise1-4-user-authentication-issue-on-wlan/m-p/2748972#M57327</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you not using eap chaining then you cant combine machine and user success criteria as you have it in your authz. What are you attempting to achieve?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Jason&lt;/P&gt;</description>
      <pubDate>Thu, 01 Oct 2015 10:50:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise1-4-user-authentication-issue-on-wlan/m-p/2748972#M57327</guid>
      <dc:creator>Jason van den Berg</dc:creator>
      <dc:date>2015-10-01T10:50:35Z</dc:date>
    </item>
    <item>
      <title>Himy purpose like this topic</title>
      <link>https://community.cisco.com/t5/network-access-control/ise1-4-user-authentication-issue-on-wlan/m-p/2748973#M57328</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;my purpose like this topic please see the correct answer.&amp;nbsp;https://supportforums.cisco.com/discussion/11583721/machine-user-auth-windows-endpoint-autheticating-through-ise&lt;/P&gt;&lt;P&gt;It's work on my wired network.&amp;nbsp;&lt;/P&gt;&lt;P&gt;And wlan network used to work fine on ISE&amp;nbsp;1.2&lt;/P&gt;</description>
      <pubDate>Thu, 01 Oct 2015 11:24:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise1-4-user-authentication-issue-on-wlan/m-p/2748973#M57328</guid>
      <dc:creator>Sarayuth.s01</dc:creator>
      <dc:date>2015-10-01T11:24:38Z</dc:date>
    </item>
    <item>
      <title>Hi, I read the thread and it</title>
      <link>https://community.cisco.com/t5/network-access-control/ise1-4-user-authentication-issue-on-wlan/m-p/2748974#M57329</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I read the thread and it seems there is several limitations on how this works and in the same article not recommended.&lt;/P&gt;&lt;P&gt;However lets see if we can reproduce how it worked in your earlier version, when your wireless device connects to the SSID, do you see a successful machine authz?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Jason&lt;/P&gt;</description>
      <pubDate>Thu, 01 Oct 2015 11:48:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise1-4-user-authentication-issue-on-wlan/m-p/2748974#M57329</guid>
      <dc:creator>Jason van den Berg</dc:creator>
      <dc:date>2015-10-01T11:48:27Z</dc:date>
    </item>
    <item>
      <title>How many PSNs do you have? </title>
      <link>https://community.cisco.com/t5/network-access-control/ise1-4-user-authentication-issue-on-wlan/m-p/2748975#M57330</link>
      <description>&lt;P&gt;How many PSNs do you have?&amp;nbsp; Keep in mind that the MAR cache (where previous machine authentications are stored) does not replicate across PSNs.&amp;nbsp; So, if you machine authenticated against one PSN and then the user authentication hit a different PSN, that PSN wouldn't have a record of the previous machine authentication.&amp;nbsp; This is one of the limitations of MAR (machine access restrictions).&amp;nbsp;&lt;/P&gt;&lt;P&gt;One of the things you'll want to do if you plan to use MAR is to extend the MAR cache aging timer at Administration &amp;gt; Identity Management &amp;gt; External Identity Sources &amp;gt; Active Directory.&amp;nbsp; Once you click on your AD Join Point Name, click the Advanced Settings tab across the top.&amp;nbsp; The default is 6hrs, you may consider expanding that to something you feel would better serve your environment.&amp;nbsp; I've used 168hrs (7 days) a number of times.&amp;nbsp; This doesn't solve the machine auth replication between PSNs issue, but at least it holds the record of the machine auth for a decent amount of time.&lt;/P&gt;&lt;P&gt;That is one restriction of MAR.&amp;nbsp; Another is the idea of a user coming to work, putting her laptop on a docking station and powering it up.&amp;nbsp; That machine auth attempt will be wired.&amp;nbsp; An hour later, she needs to undock and go to a meeting - now she is authenticating with just user auth over wireless with potentially no matching machine auth.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Review this doc for more details:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/support/docs/lan-switching/8021x/116516-problemsolution-technology-00.html"&gt;http://www.cisco.com/c/en/us/support/docs/lan-switching/8021x/116516-problemsolution-technology-00.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;EAP Chaining with AnyConnect solves these issues, but it comes at the cost of the help desk having to support a new client which some companies want to avoid.&amp;nbsp; There is also the licensing cost to consider.&amp;nbsp; However, even with those costs, it is a good option to consider - especially if you are already using AnyConnect VPN on your endpoints.&amp;nbsp; There is now an RFC for a new EAP type called TEAP where "EAP Chaining" will be standardized.&amp;nbsp; Key word there is "will" as there are no supplicants supporting TEAP yet.&amp;nbsp; You can see more on that here:&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.networkworld.com/article/2466000/security0/industry-standards-for-secure-network-access.html"&gt;http://www.networkworld.com/article/2466000/security0/industry-standards-for-secure-network-access.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Tim&lt;/P&gt;</description>
      <pubDate>Thu, 01 Oct 2015 13:14:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise1-4-user-authentication-issue-on-wlan/m-p/2748975#M57330</guid>
      <dc:creator>Tim Steele</dc:creator>
      <dc:date>2015-10-01T13:14:46Z</dc:date>
    </item>
  </channel>
</rss>

