<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE failing user check using TEAP in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-failing-user-check-using-teap/m-p/5006575#M586780</link>
    <description>&lt;P&gt;Yes, but if the cert has multiple, and maybe the one that ISE picks doesn't match the identity on the AD. To avoid this, you can select the right attribute manually in the certificate authentication profile and see if that fixes the issue.&lt;/P&gt;</description>
    <pubDate>Fri, 26 Jan 2024 17:36:25 GMT</pubDate>
    <dc:creator>Aref Alsouqi</dc:creator>
    <dc:date>2024-01-26T17:36:25Z</dc:date>
    <item>
      <title>ISE failing user check using TEAP</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-failing-user-check-using-teap/m-p/5006449#M586761</link>
      <description>&lt;P&gt;We have successfully deployed the TEAP policy using &lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/216510-eap-chaining-with-teap.html" target="_blank" rel="noopener"&gt;Cisco's documentation&lt;/A&gt;&amp;nbsp;.&amp;nbsp; &amp;nbsp;The challenge seems to be that the Machine Compliant policy is the only hit we are getting.&amp;nbsp; Never hits the Fully Compliant policy.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Windows supplicant is provisioned as per documentation to use EAP-TLS for both primary and&amp;nbsp; secondary EAP methods.&amp;nbsp;&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;Both computer and user root cert providers are the same&lt;/LI&gt;&lt;LI&gt;User certificate is provisioned for "Client Authentication" and located in the Personal-&amp;gt;Cert store on the workstation&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ChrisS_0-1706275696752.png" style="width: 648px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/208653i25743015B434CDE7/image-dimensions/648x101?v=v2" width="648" height="101" role="button" title="ChrisS_0-1706275696752.png" alt="ChrisS_0-1706275696752.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are seeing this in the log - any ideas on what to look for?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;TABLE border="0" cellpadding="3"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;11627&lt;/TD&gt;&lt;TD&gt;Starting EAP chaining&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11573&lt;/TD&gt;&lt;TD&gt;Selected identity type 'User'&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11564&lt;/TD&gt;&lt;TD&gt;TEAP inner method started&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11521&lt;/TD&gt;&lt;TD&gt;Prepared EAP-Request/Identity for inner EAP method&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11596&lt;/TD&gt;&lt;TD&gt;Prepared EAP-Request with another TEAP challenge&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11006&lt;/TD&gt;&lt;TD&gt;Returned RADIUS Access-Challenge&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11001&lt;/TD&gt;&lt;TD&gt;Received RADIUS Access-Request&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11018&lt;/TD&gt;&lt;TD&gt;RADIUS is re-using an existing session&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11595&lt;/TD&gt;&lt;TD&gt;Extracted EAP-Response containing TEAP challenge-response&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11567&lt;/TD&gt;&lt;TD&gt;Identity type provided by client is equal to requested&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11522&lt;/TD&gt;&lt;TD&gt;Extracted EAP-Response/Identity for inner EAP method&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11806&lt;/TD&gt;&lt;TD&gt;Prepared EAP-Request for inner method proposing EAP-MSCHAP with challenge&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11596&lt;/TD&gt;&lt;TD&gt;Prepared EAP-Request with another TEAP challenge&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11006&lt;/TD&gt;&lt;TD&gt;Returned RADIUS Access-Challenge&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11001&lt;/TD&gt;&lt;TD&gt;Received RADIUS Access-Request&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11018&lt;/TD&gt;&lt;TD&gt;RADIUS is re-using an existing session&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11595&lt;/TD&gt;&lt;TD&gt;Extracted EAP-Response containing TEAP challenge-response&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11515&lt;/TD&gt;&lt;TD&gt;Supplicant declined inner EAP method selected by Authentication Policy but did not proposed another one; inner EAP negotiation failed&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11520&lt;/TD&gt;&lt;TD&gt;Prepared EAP-Failure for inner EAP method&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11566&lt;/TD&gt;&lt;TD&gt;TEAP inner method finished with failure&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;22028&lt;/TD&gt;&lt;TD&gt;Authentication failed and the advanced options are ignored&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Fri, 26 Jan 2024 13:32:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-failing-user-check-using-teap/m-p/5006449#M586761</guid>
      <dc:creator>Chris S</dc:creator>
      <dc:date>2024-01-26T13:32:20Z</dc:date>
    </item>
    <item>
      <title>Re: ISE failing user check using TEAP</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-failing-user-check-using-teap/m-p/5006453#M586762</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/285637"&gt;@Chris S&lt;/a&gt; the logs imply there is a problem with the EAP method, is the supplicant configured correctly?&lt;/P&gt;
&lt;P&gt;You are using a Posture compliant condition in the rule (this is not a requirement for TEAP), I assume the device has actually passed the posture compliance check without problem?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jan 2024 13:43:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-failing-user-check-using-teap/m-p/5006453#M586762</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2024-01-26T13:43:48Z</dc:date>
    </item>
    <item>
      <title>Re: ISE failing user check using TEAP</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-failing-user-check-using-teap/m-p/5006455#M586763</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp; Agree - but I can't see anything setup differently than the recomended settings. If I switch the supplicant to be MSCHAP, it works just fine.&lt;/P&gt;&lt;P&gt;Yes, posture is working ok.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jan 2024 13:47:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-failing-user-check-using-teap/m-p/5006455#M586763</guid>
      <dc:creator>Chris S</dc:creator>
      <dc:date>2024-01-26T13:47:51Z</dc:date>
    </item>
    <item>
      <title>Re: ISE failing user check using TEAP</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-failing-user-check-using-teap/m-p/5006465#M586764</link>
      <description>&lt;P&gt;One item to add that i'm working on - when the computer is turned on (no user logged in), it's only using MAB (which fails).&amp;nbsp; Doesn't look like any EAP auths are being done until a login event occurs.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jan 2024 13:57:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-failing-user-check-using-teap/m-p/5006465#M586764</guid>
      <dc:creator>Chris S</dc:creator>
      <dc:date>2024-01-26T13:57:40Z</dc:date>
    </item>
    <item>
      <title>Re: ISE failing user check using TEAP</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-failing-user-check-using-teap/m-p/5006466#M586765</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/285637"&gt;@Chris S&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;One item to add that i'm working on - when the computer is turned on (no user logged in), it's only using MAB (which fails).&amp;nbsp; Doesn't look like any EAP auths are being done until a login event occurs.&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/285637"&gt;@Chris S&lt;/a&gt; that should not be the case, it should at least authenticate the machine, so it should match your "Machine Compliant" AuthZ rule.&lt;/P&gt;
&lt;P&gt;Can you provide a screenshot of your Authentication Policy, CAP and Allowed Protocols please?&lt;/P&gt;
&lt;P&gt;And a screenshot of the machine failing MAB.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jan 2024 14:01:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-failing-user-check-using-teap/m-p/5006466#M586765</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2024-01-26T14:01:01Z</dc:date>
    </item>
    <item>
      <title>Re: ISE failing user check using TEAP</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-failing-user-check-using-teap/m-p/5006476#M586768</link>
      <description>&lt;P&gt;I'm not sure what CAP is?&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Auth Policy:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ChrisS_0-1706278264516.png" style="width: 675px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/208659i9051D50D8DCCB61F/image-dimensions/675x220?v=v2" width="675" height="220" role="button" title="ChrisS_0-1706278264516.png" alt="ChrisS_0-1706278264516.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Allowed Protocols :&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ChrisS_1-1706278346135.png" style="width: 509px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/208660iCE6EF16F6FEADD28/image-dimensions/509x524?v=v2" width="509" height="524" role="button" title="ChrisS_1-1706278346135.png" alt="ChrisS_1-1706278346135.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Computer MAB Failure:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ChrisS_2-1706278674619.png" style="width: 635px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/208661i717A15115B40CE5B/image-dimensions/635x401?v=v2" width="635" height="401" role="button" title="ChrisS_2-1706278674619.png" alt="ChrisS_2-1706278674619.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jan 2024 14:24:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-failing-user-check-using-teap/m-p/5006476#M586768</guid>
      <dc:creator>Chris S</dc:creator>
      <dc:date>2024-01-26T14:24:13Z</dc:date>
    </item>
    <item>
      <title>Re: ISE failing user check using TEAP</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-failing-user-check-using-teap/m-p/5006483#M586769</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/285637"&gt;@Chris S&lt;/a&gt; CAP = Certificate Authentication Profile. What is EAP_Chaining and how is it configured?&lt;/P&gt;
&lt;P&gt;I would suggest the supplicant is misconfigured, please provide screenshots of how the windows supplicant is configured.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jan 2024 14:31:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-failing-user-check-using-teap/m-p/5006483#M586769</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2024-01-26T14:31:42Z</dc:date>
    </item>
    <item>
      <title>Re: ISE failing user check using TEAP</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-failing-user-check-using-teap/m-p/5006485#M586770</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;My apologizes - the MAB issue was due to the wired auto config service not starting.&amp;nbsp; That is now fixed.&amp;nbsp; So the computer will pass the machine cert successfully before login .. but after the user logs in, it still complaining about that error in the first posting.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jan 2024 14:33:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-failing-user-check-using-teap/m-p/5006485#M586770</guid>
      <dc:creator>Chris S</dc:creator>
      <dc:date>2024-01-26T14:33:28Z</dc:date>
    </item>
    <item>
      <title>Re: ISE failing user check using TEAP</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-failing-user-check-using-teap/m-p/5006497#M586771</link>
      <description>&lt;P&gt;EAP_Chaining uses the certificate auth profile referencing our domain certs then active directory. The cert profile looks in the subject or alternative name attirbute.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ChrisS_0-1706280120633.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/208662iB29AF7D9C9B6B284/image-size/medium?v=v2&amp;amp;px=400" role="button" title="ChrisS_0-1706280120633.png" alt="ChrisS_0-1706280120633.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ChrisS_1-1706280152125.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/208663i8467539822D60196/image-size/medium?v=v2&amp;amp;px=400" role="button" title="ChrisS_1-1706280152125.png" alt="ChrisS_1-1706280152125.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ChrisS_2-1706280202183.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/208664i5D4613D3FA1E7A9F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="ChrisS_2-1706280202183.png" alt="ChrisS_2-1706280202183.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ChrisS_3-1706280244693.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/208665iEDAE745BF2D49D3E/image-size/medium?v=v2&amp;amp;px=400" role="button" title="ChrisS_3-1706280244693.png" alt="ChrisS_3-1706280244693.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jan 2024 14:46:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-failing-user-check-using-teap/m-p/5006497#M586771</guid>
      <dc:creator>Chris S</dc:creator>
      <dc:date>2024-01-26T14:46:35Z</dc:date>
    </item>
    <item>
      <title>Re: ISE failing user check using TEAP</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-failing-user-check-using-teap/m-p/5006501#M586772</link>
      <description>&lt;P&gt;Could you please share ISE certificate authentication profile settings and the identity source sequence "EAP_Chaining" for review?&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jan 2024 14:53:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-failing-user-check-using-teap/m-p/5006501#M586772</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2024-01-26T14:53:11Z</dc:date>
    </item>
    <item>
      <title>Re: ISE failing user check using TEAP</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-failing-user-check-using-teap/m-p/5006506#M586773</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ChrisS_1-1706280985280.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/208667i700D8F98B5E50C2A/image-size/medium?v=v2&amp;amp;px=400" role="button" title="ChrisS_1-1706280985280.png" alt="ChrisS_1-1706280985280.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ChrisS_2-1706281018354.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/208668iF52F4181038DB560/image-size/medium?v=v2&amp;amp;px=400" role="button" title="ChrisS_2-1706281018354.png" alt="ChrisS_2-1706281018354.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jan 2024 14:57:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-failing-user-check-using-teap/m-p/5006506#M586773</guid>
      <dc:creator>Chris S</dc:creator>
      <dc:date>2024-01-26T14:57:07Z</dc:date>
    </item>
    <item>
      <title>Re: ISE failing user check using TEAP</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-failing-user-check-using-teap/m-p/5006516#M586774</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp; If I change the supplicant to be MSCHAP and the user types their credentials, I hit the "Fully Compliant" policy.&amp;nbsp; With how ISE evaluates, would the policy care between cert based or password based?&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jan 2024 15:27:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-failing-user-check-using-teap/m-p/5006516#M586774</guid>
      <dc:creator>Chris S</dc:creator>
      <dc:date>2024-01-26T15:27:51Z</dc:date>
    </item>
    <item>
      <title>Re: ISE failing user check using TEAP</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-failing-user-check-using-teap/m-p/5006521#M586776</link>
      <description>&lt;P&gt;I would try to change the "Use Identity From" in the certificate authentication profile to be "Certificate Attribute" and select the attribute from the dropdown menu. The attribute you selected should be the one you see on the user certificate, typically it would be the DNS SAN value.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jan 2024 15:36:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-failing-user-check-using-teap/m-p/5006521#M586776</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2024-01-26T15:36:13Z</dc:date>
    </item>
    <item>
      <title>Re: ISE failing user check using TEAP</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-failing-user-check-using-teap/m-p/5006526#M586777</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/284594"&gt;@Aref Alsouqi&lt;/a&gt;&amp;nbsp; But wouldn't the "Any subject or Alternative Name.." checkbox cover that?&amp;nbsp; And also - would I have to create two separate profiles - 1 for users and 1 for machines?&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jan 2024 15:40:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-failing-user-check-using-teap/m-p/5006526#M586777</guid>
      <dc:creator>Chris S</dc:creator>
      <dc:date>2024-01-26T15:40:30Z</dc:date>
    </item>
    <item>
      <title>Re: ISE failing user check using TEAP</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-failing-user-check-using-teap/m-p/5006527#M586778</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/285637"&gt;@Chris S&lt;/a&gt; the authorisation policy rule does not discriminate between authentication protocol, merely whether user and computer succeeded (and posture compliance). So there is some reason why user TEAP with TLS certificate is failing then.&lt;/P&gt;
&lt;P&gt;Check the user certificate store and confirm the certificate is valid and using the correct template.&lt;/P&gt;
&lt;P&gt;Take a tcpdump on ISE of the user authentication attempt and confirm the user identity being sent and the protocol etc.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jan 2024 16:06:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-failing-user-check-using-teap/m-p/5006527#M586778</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2024-01-26T16:06:24Z</dc:date>
    </item>
    <item>
      <title>Re: ISE failing user check using TEAP</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-failing-user-check-using-teap/m-p/5006575#M586780</link>
      <description>&lt;P&gt;Yes, but if the cert has multiple, and maybe the one that ISE picks doesn't match the identity on the AD. To avoid this, you can select the right attribute manually in the certificate authentication profile and see if that fixes the issue.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jan 2024 17:36:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-failing-user-check-using-teap/m-p/5006575#M586780</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2024-01-26T17:36:25Z</dc:date>
    </item>
    <item>
      <title>Re: ISE failing user check using TEAP</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-failing-user-check-using-teap/m-p/5159151#M591175</link>
      <description>&lt;P&gt;did you solve this problem?&lt;/P&gt;</description>
      <pubDate>Sun, 11 Aug 2024 08:02:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-failing-user-check-using-teap/m-p/5159151#M591175</guid>
      <dc:creator>Mahmoud-elsayyad</dc:creator>
      <dc:date>2024-08-11T08:02:26Z</dc:date>
    </item>
  </channel>
</rss>

