<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE EasyConnect and 802.1X machine authentication integration... in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-easyconnect-and-802-1x-machine-authentication-integration/m-p/4566871#M573325</link>
    <description>&lt;P&gt;Thanks for your reply...&lt;/P&gt;&lt;P&gt;My first question is that, is this scenario supported by Cisco?&lt;/P&gt;&lt;P&gt;My second question is, are the configured policies are correct?&lt;/P&gt;&lt;P&gt;Yes, I have checked the AD integration, and everything is OK!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 09 Mar 2022 07:58:14 GMT</pubDate>
    <dc:creator>rezaalikhani</dc:creator>
    <dc:date>2022-03-09T07:58:14Z</dc:date>
    <item>
      <title>ISE EasyConnect and 802.1X machine authentication integration...</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-easyconnect-and-802-1x-machine-authentication-integration/m-p/4565275#M573270</link>
      <description>&lt;P&gt;Hi all;&lt;/P&gt;&lt;P&gt;Because of some limitations of implementing User-based 802.1X port-based authentication (like, a user cannot change an expired password), I want to implements machine-based 802.1X authentication (based on PEAP - MSCHAPv2). Based on &lt;A href="https://community.cisco.com/t5/security-documents/ise-easy-connect/ta-p/3638861" target="_self"&gt;this document&lt;/A&gt;, it is a supported scenario. So, I have implemented machine-based 802.1X and now everything looks great. Please look at the following figure:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/145550i74B1067AD9A79863/image-size/large?v=v2&amp;amp;px=999" role="button" title="2.png" alt="2.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I have created the above Authorization Policy for the purpose of this scenario (machine-based 802.1X authentication).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now, I created the following Authorization Policy for the purpose of implementing EasyConnect:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="3.png" style="width: 994px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/145561iC2E5A89D189637D0/image-size/large?v=v2&amp;amp;px=999" role="button" title="3.png" alt="3.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Although I have enabled the "Passive Identity Tracking" option for "HR_Users" Authorization Profile, when a user in "HR_Users" group logins to the machine, ISE does not match with the above rule!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Mar 2022 09:29:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-easyconnect-and-802-1x-machine-authentication-integration/m-p/4565275#M573270</guid>
      <dc:creator>rezaalikhani</dc:creator>
      <dc:date>2022-03-07T09:29:38Z</dc:date>
    </item>
    <item>
      <title>Re: ISE EasyConnect and 802.1X machine authentication integration...</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-easyconnect-and-802-1x-machine-authentication-integration/m-p/4566694#M573318</link>
      <description>&lt;P&gt;Is your integration with AD working correctly? It's been a while since I tried this, but I recall that you can see all the events in ISE (if the WMI integration is working)&lt;/P&gt;</description>
      <pubDate>Tue, 08 Mar 2022 21:59:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-easyconnect-and-802-1x-machine-authentication-integration/m-p/4566694#M573318</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2022-03-08T21:59:56Z</dc:date>
    </item>
    <item>
      <title>Re: ISE EasyConnect and 802.1X machine authentication integration...</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-easyconnect-and-802-1x-machine-authentication-integration/m-p/4566871#M573325</link>
      <description>&lt;P&gt;Thanks for your reply...&lt;/P&gt;&lt;P&gt;My first question is that, is this scenario supported by Cisco?&lt;/P&gt;&lt;P&gt;My second question is, are the configured policies are correct?&lt;/P&gt;&lt;P&gt;Yes, I have checked the AD integration, and everything is OK!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Mar 2022 07:58:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-easyconnect-and-802-1x-machine-authentication-integration/m-p/4566871#M573325</guid>
      <dc:creator>rezaalikhani</dc:creator>
      <dc:date>2022-03-09T07:58:14Z</dc:date>
    </item>
    <item>
      <title>Re: ISE EasyConnect and 802.1X machine authentication integration...</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-easyconnect-and-802-1x-machine-authentication-integration/m-p/4567750#M573360</link>
      <description>&lt;P&gt;If your ISE is of 2.2 before Patch 17, 2.4 before Patch 13, 2.6 before Patch 7, you might run into a known bug which resolved in these patch releases.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Mar 2022 04:17:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-easyconnect-and-802-1x-machine-authentication-integration/m-p/4567750#M573360</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2022-03-10T04:17:20Z</dc:date>
    </item>
    <item>
      <title>Re: ISE EasyConnect and 802.1X machine authentication integration...</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-easyconnect-and-802-1x-machine-authentication-integration/m-p/4568068#M573376</link>
      <description>&lt;P&gt;Thanks for your reply;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you please give me the link of any docs that help me to implement this scenario?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 10 Mar 2022 14:12:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-easyconnect-and-802-1x-machine-authentication-integration/m-p/4568068#M573376</guid>
      <dc:creator>rezaalikhani</dc:creator>
      <dc:date>2022-03-10T14:12:03Z</dc:date>
    </item>
    <item>
      <title>Re: ISE EasyConnect and 802.1X machine authentication integration...</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-easyconnect-and-802-1x-machine-authentication-integration/m-p/4568335#M573396</link>
      <description>&lt;P&gt;You can try &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-2/pic_admin_guide/PIC_admin/PIC_admin_chapter_01011.html" target="_self"&gt;this link here&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;And Labminutes.com h&lt;A href="http://www.labminutes.com/sec0286_ise_22_easy_connect_1" target="_self"&gt;as a two part video series&lt;/A&gt; where you can watch how it's done (Easy Connect using Passive ID)&lt;/P&gt;</description>
      <pubDate>Thu, 10 Mar 2022 20:16:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-easyconnect-and-802-1x-machine-authentication-integration/m-p/4568335#M573396</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2022-03-10T20:16:36Z</dc:date>
    </item>
  </channel>
</rss>

