<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ISE TEAP + EAP chaining in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-teap-eap-chaining/m-p/4760400#M579371</link>
    <description>&lt;P&gt;TEAP is an outer EAP method that uses either EAP-TLS or MSCHAPv2 as an inner method to provide credentials. If you are configuring the supplicant the same as the referenced documentation (authentication mode is 'User or computer authentication' and EAP method 'Smart card or other certificate'), then the supplicant is using TEAP(EAP-TLS) and you would need both a Computer and User certificate enrolled on the computer. If you do not have a User certificate, the supplicant is unable to provide a credential for User authentication.&lt;/P&gt;</description>
    <pubDate>Tue, 24 Jan 2023 03:28:46 GMT</pubDate>
    <dc:creator>Greg Gibbs</dc:creator>
    <dc:date>2023-01-24T03:28:46Z</dc:date>
    <item>
      <title>Cisco ISE TEAP + EAP chaining</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-teap-eap-chaining/m-p/4760355#M579370</link>
      <description>&lt;P&gt;Hello All,&amp;nbsp;&lt;/P&gt;&lt;P&gt;We need some assistance and guidance as we are trying to test EAP chaining using EAP TEAP on ISE 3.1 P5 for windows 10 laptops with latest updates . We followed the following documents for EAP-TEAP configuration and pushing GPO for TEAP&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/216510-eap-chaining-with-teap.html" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/216510-eap-chaining-with-teap.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.cisco.com/t5/security-knowledge-base/teap-for-windows-10-using-group-policy-and-ise-teap/ta-p/4134289" target="_blank" rel="noopener"&gt;https://community.cisco.com/t5/security-knowledge-base/teap-for-windows-10-using-group-policy-and-ise-teap/ta-p/4134289&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We notice that we are not able to get the user and machine authentication successful in one session , on ISE we only see machine authentication with host/machine name . Even though the user logs in successful there is no log on ISE. On Switch side , we do not see the actual username coming from endpoint, it is only anonymous which we see.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We checked the radius live log and we see a statement ' supplicant decline the inner EAP method' , we followed the GPO settings on Cisco community forum. Please note we never used wired802.1x using certs so not sure if user certificate is needed as we only have rootCA on machine. Please advise which inner EAP method is talked about here, I tried to allow all protocols under " allowed protocols" but nothing worked&lt;/P&gt;&lt;P&gt;There are zero hitcounts on user and machine succeeded policy and all logs are for user failed and machine successful&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please suggest, we also had a TAC case but no relevant information.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Mehnaz&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jan 2023 01:50:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-teap-eap-chaining/m-p/4760355#M579370</guid>
      <dc:creator>MehnazKhan2492</dc:creator>
      <dc:date>2023-01-24T01:50:57Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE TEAP + EAP chaining</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-teap-eap-chaining/m-p/4760400#M579371</link>
      <description>&lt;P&gt;TEAP is an outer EAP method that uses either EAP-TLS or MSCHAPv2 as an inner method to provide credentials. If you are configuring the supplicant the same as the referenced documentation (authentication mode is 'User or computer authentication' and EAP method 'Smart card or other certificate'), then the supplicant is using TEAP(EAP-TLS) and you would need both a Computer and User certificate enrolled on the computer. If you do not have a User certificate, the supplicant is unable to provide a credential for User authentication.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jan 2023 03:28:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-teap-eap-chaining/m-p/4760400#M579371</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2023-01-24T03:28:46Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE TEAP + EAP chaining</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-teap-eap-chaining/m-p/4760458#M579373</link>
      <description>&lt;P&gt;Hello&amp;nbsp;MehnazKhan2492, I hope you are doing well, I would suggest, if you are using native supplicant of windows, to configure it manually, without GPOs, this will allow you to play more with the settings and do test for the authentications using TEAP, with the different options and inner methods, once you make it work, with the easier way which is MSCHAPv2, then you can move to EAP-TLS where you'll require auto-enrollment and provide a certificate(separate process from MSFT CA), once you finish and feel comfortable with those tests and the successful authentications I'd recommend you to go ahead with the GPO.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jan 2023 04:24:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-teap-eap-chaining/m-p/4760458#M579373</guid>
      <dc:creator>dalbanil</dc:creator>
      <dc:date>2023-01-24T04:24:48Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE TEAP + EAP chaining</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-teap-eap-chaining/m-p/4762248#M579405</link>
      <description>&lt;P&gt;Thanks for the suggestion,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;is there a document in Cisco Repository which talks about enrolling user certificates + TEAP as explained in&amp;nbsp;&lt;A href="https://community.cisco.com/t5/security-knowledge-base/teap-for-windows-10-using-group-policy-and-ise-teap/ta-p/4134289" target="_blank"&gt;https://community.cisco.com/t5/security-knowledge-base/teap-for-windows-10-using-group-policy-and-ise-teap/ta-p/4134289&lt;/A&gt;&lt;/P&gt;&lt;P&gt;The above link does not add the user certificate using GPO.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Mehnaz&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2023 17:09:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-teap-eap-chaining/m-p/4762248#M579405</guid>
      <dc:creator>MehnazKhan2492</dc:creator>
      <dc:date>2023-01-25T17:09:06Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE TEAP + EAP chaining</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-teap-eap-chaining/m-p/4763592#M579438</link>
      <description>&lt;P&gt;Information on creating Group Policy to auto-enroll User certificates with your Microsoft PKI (AD Certificate Services) is provided by Microsoft.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/en-us/windows-server/networking/core-network-guide/cncg/server-certs/configure-server-certificate-autoenrollment" target="_blank"&gt;https://learn.microsoft.com/en-us/windows-server/networking/core-network-guide/cncg/server-certs/configure-server-certificate-autoenrollment&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jan 2023 21:36:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-teap-eap-chaining/m-p/4763592#M579438</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2023-01-26T21:36:57Z</dc:date>
    </item>
  </channel>
</rss>

