<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE Dot 1x Wired Authentication in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-dot-1x-wired-authentication/m-p/5243280#M594003</link>
    <description>&lt;P&gt;Yes, the ISE EAP is the one that expired. I got a pop up on the client machine informing of the expired certificate&lt;/P&gt;</description>
    <pubDate>Sat, 04 Jan 2025 10:31:12 GMT</pubDate>
    <dc:creator>Dkiptoo</dc:creator>
    <dc:date>2025-01-04T10:31:12Z</dc:date>
    <item>
      <title>ISE Dot 1x Wired Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-dot-1x-wired-authentication/m-p/5242677#M593984</link>
      <description>&lt;P&gt;Am still new to this Technology. I have Dot1x wired authentication on my Local Network whereby ISE I believe authenticates&amp;nbsp; domain joined PCs using User Certs and Root certs from a PKI Server. My PC currently cannot be authenticate and therefore cannot be placed on the right VLAN, and after checking , I get a error that&amp;nbsp; certificate issued to the ISE by the PKI server has expired. How do I go about it? Where do I start to renew the cert.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jan 2025 11:07:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-dot-1x-wired-authentication/m-p/5242677#M593984</guid>
      <dc:creator>Dkiptoo</dc:creator>
      <dc:date>2025-01-02T11:07:43Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Dot 1x Wired Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-dot-1x-wired-authentication/m-p/5242679#M593985</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1752514"&gt;@Dkiptoo&lt;/a&gt; is it just a PC that cannot authenticate or all of them? If it's a single PC (rather than all of them), then it's likely that computers' certificate has expired. If it's AD joined and the CA is the Microsoft CA then that CA will need to issue a new certificate, that should be automatic depending on how your GPOs are configured.&lt;/P&gt;
&lt;P&gt;If all computers are failing to authenticate, that it could be the ISE "EAP certificiate" has expired, refer to this guide to renew the EAP certificate &lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/217191-configuration-guide-to-certificate-renew.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/217191-configuration-guide-to-certificate-renew.html&lt;/A&gt; just ensure the same CA issues the certificate, then you know the client computers will trust the certificate.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jan 2025 11:13:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-dot-1x-wired-authentication/m-p/5242679#M593985</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2025-01-02T11:13:34Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Dot 1x Wired Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-dot-1x-wired-authentication/m-p/5242708#M593987</link>
      <description>&lt;P&gt;Yes it is an AD joined PC. It is only one PC having the issue&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jan 2025 12:22:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-dot-1x-wired-authentication/m-p/5242708#M593987</guid>
      <dc:creator>Dkiptoo</dc:creator>
      <dc:date>2025-01-02T12:22:03Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Dot 1x Wired Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-dot-1x-wired-authentication/m-p/5243260#M594000</link>
      <description>&lt;P&gt;Hi Rob,&amp;nbsp; just a follow up on the same, after accessing the ISE from another client machine, I realized the&amp;nbsp;&lt;SPAN&gt;EAP certificate has expired. My question in, why am I still being able to access with another client machine if the Root certificate is expired. I expected not to authenticate other client machines. Your input kindly&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 04 Jan 2025 08:50:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-dot-1x-wired-authentication/m-p/5243260#M594000</guid>
      <dc:creator>Dkiptoo</dc:creator>
      <dc:date>2025-01-04T08:50:32Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Dot 1x Wired Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-dot-1x-wired-authentication/m-p/5243261#M594001</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1752514"&gt;@Dkiptoo&lt;/a&gt; I would expect the client machine to pop up a warning. Possibly the supplicant (on the computer) is configured not to validate the ISE EAP certificate and so no error/warning is displayed on the computer.&lt;/P&gt;
&lt;P&gt;I assume you mean the ISE EAP certificiate is expired, not the root certificate that issued the EAP certificate?&lt;/P&gt;</description>
      <pubDate>Sat, 04 Jan 2025 08:56:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-dot-1x-wired-authentication/m-p/5243261#M594001</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2025-01-04T08:56:36Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Dot 1x Wired Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-dot-1x-wired-authentication/m-p/5243280#M594003</link>
      <description>&lt;P&gt;Yes, the ISE EAP is the one that expired. I got a pop up on the client machine informing of the expired certificate&lt;/P&gt;</description>
      <pubDate>Sat, 04 Jan 2025 10:31:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-dot-1x-wired-authentication/m-p/5243280#M594003</guid>
      <dc:creator>Dkiptoo</dc:creator>
      <dc:date>2025-01-04T10:31:12Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Dot 1x Wired Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-dot-1x-wired-authentication/m-p/5243281#M594004</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1752514"&gt;@Dkiptoo&lt;/a&gt; ok, so you accepted the warning and continued to be authenticated. &lt;/P&gt;
&lt;P&gt;Renew the ISE EAP certificate as the link above, you should no longer have any client side warnings.&lt;/P&gt;</description>
      <pubDate>Sat, 04 Jan 2025 10:38:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-dot-1x-wired-authentication/m-p/5243281#M594004</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2025-01-04T10:38:21Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Dot 1x Wired Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-dot-1x-wired-authentication/m-p/5244389#M594051</link>
      <description>&lt;P&gt;Hi Rob, thank you for&amp;nbsp; your input. I was able to renew the EAP Certificate&amp;nbsp; signed by the CA and services resumed normal. However I have 2 ISE nodes, PAN and Secondary and I did on the PAN. On the secondary it still show expired. Do I need to repeat the process on the secondary node&amp;nbsp; again to keep them in sync? Currently they are not in Sync. The also during the process, I noticed despite all other client machines not being able to be authenticated due to expired certificate, there was still&amp;nbsp; one machine that was still on the respective VLAN. Could this&amp;nbsp; be a case maybe&amp;nbsp;802.1X&amp;nbsp; is &amp;nbsp;disabled on the specific switchport?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jan 2025 13:40:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-dot-1x-wired-authentication/m-p/5244389#M594051</guid>
      <dc:creator>Dkiptoo</dc:creator>
      <dc:date>2025-01-07T13:40:33Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Dot 1x Wired Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-dot-1x-wired-authentication/m-p/5244393#M594052</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1752514"&gt;@Dkiptoo&lt;/a&gt; you need a certificate on each node, so repeat the process for the Secondary node - you do this from the Primary PAN, just select the other node.&lt;/P&gt;
&lt;P&gt;Possibly 802.1X is not enabled on that port, check the switchport configuration and run "show authentication session interface &amp;lt;number&amp;gt; detail".&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jan 2025 13:44:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-dot-1x-wired-authentication/m-p/5244393#M594052</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2025-01-07T13:44:54Z</dc:date>
    </item>
  </channel>
</rss>

