<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cannot authenticate printer via PEAP in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cannot-authenticate-printer-via-peap/m-p/4944762#M584749</link>
    <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have twelve network printers in our remote location. We've recently enabled dot1x authentication on a switch. In order to limit the number of unprotected ports, we would also like to enable authentication on network printers. Since using certifiates creates a lot of administrative overhead (local IT guys would have to generate CSR and certificatesare are valid only for a limited period of time) we've come to the conclusion that PEAP/MS-CHAPv2 would be the most appropriate authentication method. the following policy has been created on Cisco ISE:&lt;BR /&gt;Network Access·EapAuthentication equals EAP-MS-CHAPv2&lt;BR /&gt;Network Access Network Device Name starts with xxxxxxx&lt;BR /&gt;Identity group is external AD group&lt;/P&gt;&lt;P&gt;Unfortunately I do not see any hitcounts, the policy is failing. Obviously, the account is added to AD group, right authentication method and credentials are set up in administrative panel of a printer. In my opinion the issue can be on the end device as previosuly we were having such issue on wireless network (two iPhones were able to authenticate via PEAP, my Samsung Android device was working fine, but the problem was with other Android device)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 20 Oct 2023 07:42:07 GMT</pubDate>
    <dc:creator>lnw-team</dc:creator>
    <dc:date>2023-10-20T07:42:07Z</dc:date>
    <item>
      <title>Cannot authenticate printer via PEAP</title>
      <link>https://community.cisco.com/t5/network-access-control/cannot-authenticate-printer-via-peap/m-p/4944762#M584749</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have twelve network printers in our remote location. We've recently enabled dot1x authentication on a switch. In order to limit the number of unprotected ports, we would also like to enable authentication on network printers. Since using certifiates creates a lot of administrative overhead (local IT guys would have to generate CSR and certificatesare are valid only for a limited period of time) we've come to the conclusion that PEAP/MS-CHAPv2 would be the most appropriate authentication method. the following policy has been created on Cisco ISE:&lt;BR /&gt;Network Access·EapAuthentication equals EAP-MS-CHAPv2&lt;BR /&gt;Network Access Network Device Name starts with xxxxxxx&lt;BR /&gt;Identity group is external AD group&lt;/P&gt;&lt;P&gt;Unfortunately I do not see any hitcounts, the policy is failing. Obviously, the account is added to AD group, right authentication method and credentials are set up in administrative panel of a printer. In my opinion the issue can be on the end device as previosuly we were having such issue on wireless network (two iPhones were able to authenticate via PEAP, my Samsung Android device was working fine, but the problem was with other Android device)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Oct 2023 07:42:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cannot-authenticate-printer-via-peap/m-p/4944762#M584749</guid>
      <dc:creator>lnw-team</dc:creator>
      <dc:date>2023-10-20T07:42:07Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot authenticate printer via PEAP</title>
      <link>https://community.cisco.com/t5/network-access-control/cannot-authenticate-printer-via-peap/m-p/4944806#M584751</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/520091"&gt;@lnw-team&lt;/a&gt; I assume other devices connected to the same switch are authenticating correctly, so we can rule out the switch configuration?&lt;/P&gt;
&lt;P&gt;From the switch run "show authentication session interface x/y/z detail" &amp;lt; replace x/y/z with the actual switchport the printer is connected to.&lt;/P&gt;
&lt;P&gt;In the ISE live logs do you see the authentication request come through for the printer? If so which rule does it match? Provide a screenshot.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Oct 2023 08:29:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cannot-authenticate-printer-via-peap/m-p/4944806#M584751</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2023-10-20T08:29:46Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot authenticate printer via PEAP</title>
      <link>https://community.cisco.com/t5/network-access-control/cannot-authenticate-printer-via-peap/m-p/4944826#M584752</link>
      <description>&lt;P&gt;Hello Rob,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I did that, it hits the last policy (Default - Deny access).&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Oct 2023 08:46:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cannot-authenticate-printer-via-peap/m-p/4944826#M584752</guid>
      <dc:creator>lnw-team</dc:creator>
      <dc:date>2023-10-20T08:46:57Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot authenticate printer via PEAP</title>
      <link>https://community.cisco.com/t5/network-access-control/cannot-authenticate-printer-via-peap/m-p/4944830#M584753</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/520091"&gt;@lnw-team&lt;/a&gt; ok well then you need to determine what conditions it does not match or the device failed authentication or your Policy Set allowed protocols does not permit PEAP/MSCHAPv2, so therefore the request does not match your Policy Set and hits the default policy.&lt;/P&gt;
&lt;P&gt;Check the live logs (provide them here if you want us to review).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Oct 2023 09:19:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cannot-authenticate-printer-via-peap/m-p/4944830#M584753</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2023-10-20T09:19:13Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot authenticate printer via PEAP</title>
      <link>https://community.cisco.com/t5/network-access-control/cannot-authenticate-printer-via-peap/m-p/4946832#M584811</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Please take a look at the logs from ISE. As you can see, at some point ISE is recognizing the user.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="lnwteam_0-1698148297368.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/200533iDDDE477ADB17314D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="lnwteam_0-1698148297368.png" alt="lnwteam_0-1698148297368.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="lnwteam_1-1698148467908.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/200530iC75D770DB17694B4/image-size/medium?v=v2&amp;amp;px=400" role="button" title="lnwteam_1-1698148467908.png" alt="lnwteam_1-1698148467908.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="lnwteam_2-1698148736329.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/200534iFD6A98E92B0FF027/image-size/medium?v=v2&amp;amp;px=400" role="button" title="lnwteam_2-1698148736329.png" alt="lnwteam_2-1698148736329.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Oct 2023 12:00:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cannot-authenticate-printer-via-peap/m-p/4946832#M584811</guid>
      <dc:creator>lnw-team</dc:creator>
      <dc:date>2023-10-24T12:00:14Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot authenticate printer via PEAP</title>
      <link>https://community.cisco.com/t5/network-access-control/cannot-authenticate-printer-via-peap/m-p/4946837#M584812</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/520091"&gt;@lnw-team&lt;/a&gt; the clients do not trust the certificate that ISE is using. Add the root certificate used by ISE on to the printers, so the printers trust the certificate or (not secure and not recommended) configure the printer to not trust the ISE certificate.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Oct 2023 12:08:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cannot-authenticate-printer-via-peap/m-p/4946837#M584812</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2023-10-24T12:08:08Z</dc:date>
    </item>
  </channel>
</rss>

