<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NAC Policy for OS Boot vs Initial Boot in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/nac-policy-for-os-boot-vs-initial-boot/m-p/4776772#M579874</link>
    <description>&lt;P&gt;Hi BB,&lt;BR /&gt;No not PXE boot. This is just the initial boot screen, i.e. when the Laptop is first powered on.&lt;BR /&gt;(Or for that matter it is left idle for some time....even here we seen at times the "Employee VLAN" gets lost and the Laptop for in the "Guest VLAN")&lt;BR /&gt;&lt;BR /&gt;Thanks!&lt;BR /&gt;N&lt;/P&gt;</description>
    <pubDate>Thu, 16 Feb 2023 12:55:29 GMT</pubDate>
    <dc:creator>network_geek1979</dc:creator>
    <dc:date>2023-02-16T12:55:29Z</dc:date>
    <item>
      <title>NAC Policy for OS Boot vs Initial Boot</title>
      <link>https://community.cisco.com/t5/network-access-control/nac-policy-for-os-boot-vs-initial-boot/m-p/4776748#M579871</link>
      <description>&lt;P&gt;Folks,&lt;BR /&gt;I needed some suggestion on Policies getting applied when the 802.1x authentication kicks in vs Initial Boot by a system.&lt;BR /&gt;&lt;BR /&gt;Our policies say that once the 802.1x authentication succeeds allow the machine to get authorized on the "Employee VLAN". This policy works just fine, but the catch here is when the system performs an initial boot the system does not get in the&amp;nbsp;"Employee VLAN", which is expected as the OS cannot perform a 802.1x authentication.&lt;BR /&gt;&lt;BR /&gt;Any suggestions to overcome this challenge?&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Thanks!&lt;BR /&gt;N.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Feb 2023 12:23:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nac-policy-for-os-boot-vs-initial-boot/m-p/4776748#M579871</guid>
      <dc:creator>network_geek1979</dc:creator>
      <dc:date>2023-02-16T12:23:38Z</dc:date>
    </item>
    <item>
      <title>Re: NAC Policy for OS Boot vs Initial Boot</title>
      <link>https://community.cisco.com/t5/network-access-control/nac-policy-for-os-boot-vs-initial-boot/m-p/4776753#M579872</link>
      <description>&lt;P&gt;You mean PXE boot ?&lt;/P&gt;</description>
      <pubDate>Thu, 16 Feb 2023 12:29:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nac-policy-for-os-boot-vs-initial-boot/m-p/4776753#M579872</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2023-02-16T12:29:54Z</dc:date>
    </item>
    <item>
      <title>Re: NAC Policy for OS Boot vs Initial Boot</title>
      <link>https://community.cisco.com/t5/network-access-control/nac-policy-for-os-boot-vs-initial-boot/m-p/4776772#M579874</link>
      <description>&lt;P&gt;Hi BB,&lt;BR /&gt;No not PXE boot. This is just the initial boot screen, i.e. when the Laptop is first powered on.&lt;BR /&gt;(Or for that matter it is left idle for some time....even here we seen at times the "Employee VLAN" gets lost and the Laptop for in the "Guest VLAN")&lt;BR /&gt;&lt;BR /&gt;Thanks!&lt;BR /&gt;N&lt;/P&gt;</description>
      <pubDate>Thu, 16 Feb 2023 12:55:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nac-policy-for-os-boot-vs-initial-boot/m-p/4776772#M579874</guid>
      <dc:creator>network_geek1979</dc:creator>
      <dc:date>2023-02-16T12:55:29Z</dc:date>
    </item>
    <item>
      <title>Re: NAC Policy for OS Boot vs Initial Boot</title>
      <link>https://community.cisco.com/t5/network-access-control/nac-policy-for-os-boot-vs-initial-boot/m-p/4776822#M579876</link>
      <description>&lt;P&gt;I assume you are doing user auth?&amp;nbsp; If so there is no 802.1X transaction by design until a user logs into the system.&amp;nbsp; You should also enable machine authentication if you need to provide network access before login.&amp;nbsp; That being said, why change VLANs at all?&amp;nbsp; Why not use a dACL or some other enforcement method?&lt;/P&gt;</description>
      <pubDate>Thu, 16 Feb 2023 14:01:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nac-policy-for-os-boot-vs-initial-boot/m-p/4776822#M579876</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2023-02-16T14:01:35Z</dc:date>
    </item>
    <item>
      <title>Re: NAC Policy for OS Boot vs Initial Boot</title>
      <link>https://community.cisco.com/t5/network-access-control/nac-policy-for-os-boot-vs-initial-boot/m-p/4785908#M580170</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/199513"&gt;@ahollifield&lt;/a&gt;&amp;nbsp;: Thanks for the answer and apologies for the late response.&lt;BR /&gt;Any details you can share on machine authentication? This is new to us and would like to check how this can work.&lt;BR /&gt;Thanks a ton.&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;/P&gt;&lt;P&gt;N!&lt;/P&gt;</description>
      <pubDate>Thu, 02 Mar 2023 12:52:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nac-policy-for-os-boot-vs-initial-boot/m-p/4785908#M580170</guid>
      <dc:creator>network_geek1979</dc:creator>
      <dc:date>2023-03-02T12:52:22Z</dc:date>
    </item>
    <item>
      <title>Re: NAC Policy for OS Boot vs Initial Boot</title>
      <link>https://community.cisco.com/t5/network-access-control/nac-policy-for-os-boot-vs-initial-boot/m-p/4785935#M580171</link>
      <description>&lt;P&gt;These are windows endpoints correct?&amp;nbsp; If so enable "Computer Authentication" in the supplicant configuration.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Mar 2023 13:19:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nac-policy-for-os-boot-vs-initial-boot/m-p/4785935#M580171</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2023-03-02T13:19:04Z</dc:date>
    </item>
    <item>
      <title>Re: NAC Policy for OS Boot vs Initial Boot</title>
      <link>https://community.cisco.com/t5/network-access-control/nac-policy-for-os-boot-vs-initial-boot/m-p/4792165#M580412</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/47004"&gt;@network_geek1979&lt;/a&gt;&amp;nbsp;Adding to what&amp;nbsp;&lt;A href="https://community.cisco.com/t5/user/viewprofilepage/user-id/199513" target="_blank"&gt;&lt;SPAN class="text-large"&gt;ahollifield&lt;/SPAN&gt;&lt;/A&gt; suggested...&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.asquaredozen.com/2018/07/29/configuring-802-1x-authentication-for-windows-deployment/" target="_self"&gt;Configuring 802.1x Authentication for Windows Deployment at A. Gross Blog&lt;/A&gt; might be of interest to you.&lt;/P&gt;</description>
      <pubDate>Sun, 12 Mar 2023 18:24:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nac-policy-for-os-boot-vs-initial-boot/m-p/4792165#M580412</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2023-03-12T18:24:40Z</dc:date>
    </item>
  </channel>
</rss>

