<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NON-DOMAIN MACHINE AUTHENTICATION in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/non-domain-machine-authentication/m-p/4605221#M574591</link>
    <description>&lt;P&gt;Did you create an Autorization profile as well ?&lt;/P&gt;&lt;P&gt;Take a look on this video.&lt;/P&gt;&lt;P&gt;&lt;A title="https://www.youtube.com/watch?v=E_s9WHSVLYQ" href="https://www.youtube.com/watch?v=E_s9WHSVLYQ" target="_self"&gt;https://www.youtube.com/watch?v=E_s9WHSVLYQ&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 05 May 2022 16:34:23 GMT</pubDate>
    <dc:creator>Flavio Miranda</dc:creator>
    <dc:date>2022-05-05T16:34:23Z</dc:date>
    <item>
      <title>NON-DOMAIN MACHINE AUTHENTICATION</title>
      <link>https://community.cisco.com/t5/network-access-control/non-domain-machine-authentication/m-p/4605011#M574565</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I authenticate the user using the local database of ISE and I also want to authenticate my machine. But this machine is not joined to AD.&lt;/P&gt;&lt;P&gt;How can I authenticate a nondomain machine?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Machine username is host/example so I created the same username in the local database with a random password. I saw in logs an error 22063 Wrong password.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How is it possible to authenticate also my non-domain machine?&lt;/P&gt;</description>
      <pubDate>Thu, 05 May 2022 11:27:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/non-domain-machine-authentication/m-p/4605011#M574565</guid>
      <dc:creator>RustamRustamov1023</dc:creator>
      <dc:date>2022-05-05T11:27:10Z</dc:date>
    </item>
    <item>
      <title>Re: NON-DOMAIN MACHINE AUTHENTICATION</title>
      <link>https://community.cisco.com/t5/network-access-control/non-domain-machine-authentication/m-p/4605045#M574571</link>
      <description>&lt;P&gt;What is your EAP type?&amp;nbsp; PEAP?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am not an AD expert but AFAIK you cannot do this without Active Directory.&amp;nbsp; AD manages the password on the machine, there is no way to change/update the machine password, hence why you are seeing incorrect password.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If this is what you are trying to do why?&amp;nbsp; What is the use-case?&amp;nbsp; What significance would a non-domain machine account have?&lt;/P&gt;</description>
      <pubDate>Thu, 05 May 2022 12:20:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/non-domain-machine-authentication/m-p/4605045#M574571</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2022-05-05T12:20:25Z</dc:date>
    </item>
    <item>
      <title>Re: NON-DOMAIN MACHINE AUTHENTICATION</title>
      <link>https://community.cisco.com/t5/network-access-control/non-domain-machine-authentication/m-p/4605047#M574572</link>
      <description>&lt;P&gt;I use PEAP. This is the requirement of my customer so I have to authenticate user and also non-domain machine.&lt;/P&gt;&lt;P&gt;Is there any other methods to authenticate non-domain machine?&lt;/P&gt;</description>
      <pubDate>Thu, 05 May 2022 12:24:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/non-domain-machine-authentication/m-p/4605047#M574572</guid>
      <dc:creator>RustamRustamov1023</dc:creator>
      <dc:date>2022-05-05T12:24:18Z</dc:date>
    </item>
    <item>
      <title>Re: NON-DOMAIN MACHINE AUTHENTICATION</title>
      <link>https://community.cisco.com/t5/network-access-control/non-domain-machine-authentication/m-p/4605057#M574576</link>
      <description>&lt;P&gt;First I would question the requirement.&amp;nbsp; What exactly does the customer hope to gain by this?&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;EAP-TLS using a certificate issued to that computer (stored in the computer account) is a possible option.&amp;nbsp; However, without AD or an MDM how are you going to get a certificate to that machine and manage the certificate renewal process?&lt;/P&gt;</description>
      <pubDate>Thu, 05 May 2022 12:37:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/non-domain-machine-authentication/m-p/4605057#M574576</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2022-05-05T12:37:05Z</dc:date>
    </item>
    <item>
      <title>Re: NON-DOMAIN MACHINE AUTHENTICATION</title>
      <link>https://community.cisco.com/t5/network-access-control/non-domain-machine-authentication/m-p/4605059#M574577</link>
      <description>&lt;P&gt;If you are using ISE local Data Base, then you are not using AD.&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you selected "Internal User" under "Password Type"&amp;nbsp; Then, you need to select the User Group. And you need to add your user on the User group.&lt;/P&gt;</description>
      <pubDate>Thu, 05 May 2022 12:38:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/non-domain-machine-authentication/m-p/4605059#M574577</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2022-05-05T12:38:28Z</dc:date>
    </item>
    <item>
      <title>Re: NON-DOMAIN MACHINE AUTHENTICATION</title>
      <link>https://community.cisco.com/t5/network-access-control/non-domain-machine-authentication/m-p/4605217#M574590</link>
      <description>&lt;P&gt;Yes, I did it in the way that you described but there is a 22063 Wrong password error. The non-domain machine uses some username and password. I know which username it is from logs but I do not which password is it used.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;The main question is how can I authenticate also my non-domain machine?&lt;/P&gt;</description>
      <pubDate>Thu, 05 May 2022 16:31:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/non-domain-machine-authentication/m-p/4605217#M574590</guid>
      <dc:creator>RustamRustamov1023</dc:creator>
      <dc:date>2022-05-05T16:31:31Z</dc:date>
    </item>
    <item>
      <title>Re: NON-DOMAIN MACHINE AUTHENTICATION</title>
      <link>https://community.cisco.com/t5/network-access-control/non-domain-machine-authentication/m-p/4605221#M574591</link>
      <description>&lt;P&gt;Did you create an Autorization profile as well ?&lt;/P&gt;&lt;P&gt;Take a look on this video.&lt;/P&gt;&lt;P&gt;&lt;A title="https://www.youtube.com/watch?v=E_s9WHSVLYQ" href="https://www.youtube.com/watch?v=E_s9WHSVLYQ" target="_self"&gt;https://www.youtube.com/watch?v=E_s9WHSVLYQ&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 05 May 2022 16:34:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/non-domain-machine-authentication/m-p/4605221#M574591</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2022-05-05T16:34:23Z</dc:date>
    </item>
    <item>
      <title>Re: NON-DOMAIN MACHINE AUTHENTICATION</title>
      <link>https://community.cisco.com/t5/network-access-control/non-domain-machine-authentication/m-p/4605222#M574592</link>
      <description>&lt;P&gt;Yes, I authenticated the non-domain machine with a certificate but now I have to do it using PEAP-MSCHAPv2&lt;/P&gt;</description>
      <pubDate>Thu, 05 May 2022 16:34:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/non-domain-machine-authentication/m-p/4605222#M574592</guid>
      <dc:creator>RustamRustamov1023</dc:creator>
      <dc:date>2022-05-05T16:34:25Z</dc:date>
    </item>
    <item>
      <title>Re: NON-DOMAIN MACHINE AUTHENTICATION</title>
      <link>https://community.cisco.com/t5/network-access-control/non-domain-machine-authentication/m-p/4605230#M574594</link>
      <description>&lt;P&gt;Yes, I created Authorization Profile and I have a wired dot1x environment, not wireless. There are no questions about user authentication there is a question about how to authenticate a non-domain machine using PEAP-MSCHAPv2?&lt;/P&gt;</description>
      <pubDate>Thu, 05 May 2022 16:43:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/non-domain-machine-authentication/m-p/4605230#M574594</guid>
      <dc:creator>RustamRustamov1023</dc:creator>
      <dc:date>2022-05-05T16:43:32Z</dc:date>
    </item>
    <item>
      <title>Re: NON-DOMAIN MACHINE AUTHENTICATION</title>
      <link>https://community.cisco.com/t5/network-access-control/non-domain-machine-authentication/m-p/4605462#M574598</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/934333"&gt;@RustamRustamov1023&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can authenticate a non-domain joined machine in the following ways. Since this machine is not domain joined, you cannot and will never succeed in performing computer authentication with EAP-PEAP&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Therefore your choices of how to configure the native Win 10 supplicant are:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Computer authentication using EAP-TLS&lt;/LI&gt;
&lt;LI&gt;User authentication using EAP-TLS or using EAP-PEAP&lt;/LI&gt;
&lt;LI&gt;User/Computer authentication using EAP-TLS only (Win10 won't allow mixing of EAP methods unless you try EAP-TEAP)&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 06 May 2022 00:48:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/non-domain-machine-authentication/m-p/4605462#M574598</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2022-05-06T00:48:08Z</dc:date>
    </item>
    <item>
      <title>Re: NON-DOMAIN MACHINE AUTHENTICATION</title>
      <link>https://community.cisco.com/t5/network-access-control/non-domain-machine-authentication/m-p/4605476#M574600</link>
      <description>&lt;P&gt;You can't.&amp;nbsp; There is no concept of this AFAIK without being joined to a domain.&amp;nbsp; Again though what is the use-case here?&lt;/P&gt;</description>
      <pubDate>Fri, 06 May 2022 14:17:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/non-domain-machine-authentication/m-p/4605476#M574600</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2022-05-06T14:17:14Z</dc:date>
    </item>
  </channel>
</rss>

