<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: One PC working but can't get others authorised in ISE in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/one-pc-working-but-can-t-get-others-authorised-in-ise/m-p/5084379#M589161</link>
    <description>Check in MMC under the trusted certificates.&lt;BR /&gt;</description>
    <pubDate>Tue, 30 Apr 2024 14:05:09 GMT</pubDate>
    <dc:creator>ahollifield</dc:creator>
    <dc:date>2024-04-30T14:05:09Z</dc:date>
    <item>
      <title>One PC working but can't get others authorised in ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/one-pc-working-but-can-t-get-others-authorised-in-ise/m-p/5083906#M589146</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;I've managed to get one PC up and running using dot1x and it's all authenticating correctly. However when I try another PC it just fails.&lt;/P&gt;&lt;P&gt;What can I do to troubleshoot this? I've confirmed that the PC's have the same certificates and are in the same AD groups. The port configs are the same on both ports.&lt;/P&gt;&lt;P&gt;on the switch I'm seeing Authentication failed for client&amp;nbsp;Username: host/&lt;EM&gt;&lt;STRONG&gt;XXXXXXX&lt;/STRONG&gt;&lt;/EM&gt;.&lt;EM&gt;&lt;STRONG&gt;domain&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;When I check the logs in ISE I can see the following for the authenticated machine:&lt;/P&gt;&lt;TABLE border="0" cellpadding="3"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;1001&lt;/TD&gt;&lt;TD&gt;Received RADIUS Access-Request - &lt;STRONG&gt;XXXX&lt;/STRONG&gt;-DC-002&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11017&lt;/TD&gt;&lt;TD&gt;RADIUS created a new session - &lt;U&gt;&lt;STRONG&gt;XXX.domain&lt;/STRONG&gt;&lt;/U&gt;&lt;STRONG&gt;.uk&lt;/STRONG&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;15049&lt;/TD&gt;&lt;TD&gt;Evaluating Policy Group - &lt;EM&gt;&lt;STRONG&gt;XXXX &lt;/STRONG&gt;&lt;/EM&gt;-DC-002&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;15008&lt;/TD&gt;&lt;TD&gt;Evaluating Service Selection Policy&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;15048&lt;/TD&gt;&lt;TD&gt;Queried PIP - Normalised Radius.RadiusFlowType&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11507&lt;/TD&gt;&lt;TD&gt;Extracted EAP-Response/Identity&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;12500&lt;/TD&gt;&lt;TD&gt;Prepared EAP-Request proposing EAP-TLS with challenge&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;12625&lt;/TD&gt;&lt;TD&gt;Valid EAP-Key-Name attribute received&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11006&lt;/TD&gt;&lt;TD&gt;Returned RADIUS Access-Challenge&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11001&lt;/TD&gt;&lt;TD&gt;Received RADIUS Access-Request&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11018&lt;/TD&gt;&lt;TD&gt;RADIUS is re-using an existing session&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;12502&lt;/TD&gt;&lt;TD&gt;Extracted EAP-Response containing EAP-TLS challenge-response and accepting EAP-TLS as negotiated&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;and for the machine that fails it's not sending through the domain information:&lt;/P&gt;&lt;TABLE border="0" cellpadding="3"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;11001&lt;/TD&gt;&lt;TD&gt;Received RADIUS Access-Request&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11017&lt;/TD&gt;&lt;TD&gt;RADIUS created a new session&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;15049&lt;/TD&gt;&lt;TD&gt;Evaluating Policy Group&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;15008&lt;/TD&gt;&lt;TD&gt;Evaluating Service Selection Policy&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;15048&lt;/TD&gt;&lt;TD&gt;Queried PIP - Normalised Radius.RadiusFlowType&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11507&lt;/TD&gt;&lt;TD&gt;Extracted EAP-Response/Identity&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;12500&lt;/TD&gt;&lt;TD&gt;Prepared EAP-Request proposing EAP-TLS with challenge&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;12625&lt;/TD&gt;&lt;TD&gt;Valid EAP-Key-Name attribute received&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;11006&lt;/TD&gt;&lt;TD&gt;Returned RADIUS Access-Challenge&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;5440&lt;/TD&gt;&lt;TD&gt;Endpoint abandoned EAP session and started new (&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;Step latency=1018 ms)&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Apr 2024 10:22:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/one-pc-working-but-can-t-get-others-authorised-in-ise/m-p/5083906#M589146</guid>
      <dc:creator>alliasneo1</dc:creator>
      <dc:date>2024-04-30T10:22:55Z</dc:date>
    </item>
    <item>
      <title>Re: One PC working but can't get others authorised in ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/one-pc-working-but-can-t-get-others-authorised-in-ise/m-p/5084243#M589151</link>
      <description>&lt;P&gt;Looks like a supplicant configuration issue to me.&amp;nbsp; The expected EAP type is EAP-TLS?&amp;nbsp; Are the certificates correct on the second machine?&amp;nbsp; What is the endpoint?&amp;nbsp; What is the NAD?&amp;nbsp; Machine certificate or user certificate?&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/security-documents/how-to-ask-the-community-for-help/ta-p/3704356" target="_blank"&gt;https://community.cisco.com/t5/security-documents/how-to-ask-the-community-for-help/ta-p/3704356&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Apr 2024 12:20:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/one-pc-working-but-can-t-get-others-authorised-in-ise/m-p/5084243#M589151</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2024-04-30T12:20:01Z</dc:date>
    </item>
    <item>
      <title>Re: One PC working but can't get others authorised in ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/one-pc-working-but-can-t-get-others-authorised-in-ise/m-p/5084253#M589152</link>
      <description>&lt;P&gt;It is EAP-TLS yes.&lt;/P&gt;&lt;P&gt;The certificate is exactly the same on the second machine.&lt;/P&gt;&lt;P&gt;The endpoint is a HP PC - both the same make and model.&lt;/P&gt;&lt;P&gt;The NAD - Cisco 9200&lt;/P&gt;&lt;P&gt;Machine Certificate&lt;/P&gt;</description>
      <pubDate>Tue, 30 Apr 2024 12:28:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/one-pc-working-but-can-t-get-others-authorised-in-ise/m-p/5084253#M589152</guid>
      <dc:creator>alliasneo1</dc:creator>
      <dc:date>2024-04-30T12:28:18Z</dc:date>
    </item>
    <item>
      <title>Re: One PC working but can't get others authorised in ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/one-pc-working-but-can-t-get-others-authorised-in-ise/m-p/5084305#M589153</link>
      <description>“Exactly the same” each device should have its own unique certificate. Why are two machines sharing the same certificate? What type of certificate is on ISE? Public? Private? Is that certificate trusted by the second machine?&lt;BR /&gt;&lt;BR /&gt;What version of IOS-XE?&lt;BR /&gt;</description>
      <pubDate>Tue, 30 Apr 2024 12:41:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/one-pc-working-but-can-t-get-others-authorised-in-ise/m-p/5084305#M589153</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2024-04-30T12:41:07Z</dc:date>
    </item>
    <item>
      <title>Re: One PC working but can't get others authorised in ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/one-pc-working-but-can-t-get-others-authorised-in-ise/m-p/5084375#M589160</link>
      <description>&lt;P&gt;This is a certificate pushed to the machine via Group Policy.&lt;/P&gt;&lt;P&gt;It is a private certificate. Under 'Issued-By' it has our company name.&lt;/P&gt;&lt;P&gt;How do I check if the certificate is trusted by the second machine?&lt;/P&gt;</description>
      <pubDate>Tue, 30 Apr 2024 13:55:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/one-pc-working-but-can-t-get-others-authorised-in-ise/m-p/5084375#M589160</guid>
      <dc:creator>alliasneo1</dc:creator>
      <dc:date>2024-04-30T13:55:42Z</dc:date>
    </item>
    <item>
      <title>Re: One PC working but can't get others authorised in ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/one-pc-working-but-can-t-get-others-authorised-in-ise/m-p/5084379#M589161</link>
      <description>Check in MMC under the trusted certificates.&lt;BR /&gt;</description>
      <pubDate>Tue, 30 Apr 2024 14:05:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/one-pc-working-but-can-t-get-others-authorised-in-ise/m-p/5084379#M589161</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2024-04-30T14:05:09Z</dc:date>
    </item>
    <item>
      <title>Re: One PC working but can't get others authorised in ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/one-pc-working-but-can-t-get-others-authorised-in-ise/m-p/5084404#M589164</link>
      <description>&lt;P&gt;When I open MMC and go to Local Computer&amp;gt;Personal&amp;gt;Certificates&lt;/P&gt;&lt;P&gt;I can see the ISE cert in there.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Apr 2024 14:33:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/one-pc-working-but-can-t-get-others-authorised-in-ise/m-p/5084404#M589164</guid>
      <dc:creator>alliasneo1</dc:creator>
      <dc:date>2024-04-30T14:33:03Z</dc:date>
    </item>
    <item>
      <title>Re: One PC working but can't get others authorised in ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/one-pc-working-but-can-t-get-others-authorised-in-ise/m-p/5084750#M589167</link>
      <description>&lt;P&gt;"The ISE cert"?&amp;nbsp; Why isn't it the root and issuing CAs?&amp;nbsp; From the internal PKI?&amp;nbsp; There should be no need to trust the ISE EAP Certificate itself as long as you are trusting the roots.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That's also not the trusted CA store.&amp;nbsp; That's the certificates issues to that local computer.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Apr 2024 18:54:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/one-pc-working-but-can-t-get-others-authorised-in-ise/m-p/5084750#M589167</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2024-04-30T18:54:56Z</dc:date>
    </item>
    <item>
      <title>Re: One PC working but can't get others authorised in ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/one-pc-working-but-can-t-get-others-authorised-in-ise/m-p/5087297#M589206</link>
      <description>&lt;P&gt;We have created an intermediate certificate which we will push to devices. This is trusted by the Root CA. The Root C certificate is uploaded to ISE. Sorry, I don't know much about certificates but that is how it has been setup to my knowledge.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In ISE, if I look under Certificates&amp;gt;Trusted Certificates this is where I see our organisations Root Cert and this is trusted for client authentication.&lt;/P&gt;&lt;P&gt;I then have the ISE cert being pushed from Group Policy which is created from the PKI and under 'External Identity Store' the preloaded certificate profile is pointed to Active Directory and the certificate attribute is looking at 'Subject alternative name'.&lt;/P&gt;</description>
      <pubDate>Thu, 02 May 2024 08:24:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/one-pc-working-but-can-t-get-others-authorised-in-ise/m-p/5087297#M589206</guid>
      <dc:creator>alliasneo1</dc:creator>
      <dc:date>2024-05-02T08:24:10Z</dc:date>
    </item>
  </channel>
</rss>

