<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: User or machine EAP-TLS authentication for the first time in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/user-or-machine-eap-tls-authentication-for-the-first-time/m-p/5254531#M594627</link>
    <description>&lt;P&gt;Hello Flavio,&lt;BR /&gt;&lt;BR /&gt;Thank you so much for the feedback.&lt;BR /&gt;Yes, I saw several discuss about this issue, however I didn´t no what is the solution to fix it &lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;If you have ever faced it, please, let me know.&lt;/P&gt;</description>
    <pubDate>Thu, 30 Jan 2025 00:25:36 GMT</pubDate>
    <dc:creator>icarimo</dc:creator>
    <dc:date>2025-01-30T00:25:36Z</dc:date>
    <item>
      <title>User or machine EAP-TLS authentication for the first time</title>
      <link>https://community.cisco.com/t5/network-access-control/user-or-machine-eap-tls-authentication-for-the-first-time/m-p/5254520#M594624</link>
      <description>&lt;P&gt;I have a SSID with &lt;STRONG&gt;EAP-TLS using certificates.&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;Initially my GPO was configured to only use user certificate.&lt;/P&gt;
&lt;P&gt;However we found a issue for &lt;STRONG&gt;new users&lt;/STRONG&gt;, that was not possible to login via Wi-Fi on the first login. Since they don´t have the certificate to authenticate on Wi-Fi and to have the certificate it requires internet connection.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;To fix it, I &lt;STRONG&gt;updated&lt;/STRONG&gt; the GPO to use &lt;STRONG&gt;computer or machine certificate&lt;/STRONG&gt;.&lt;BR /&gt;Now, before first login, the user is able to connect to Wi-Fi via machine certificate. However, after the user logins for the first time, &lt;STRONG&gt;immediately he is disconnected to the Wi-Fi,&amp;nbsp;&lt;/STRONG&gt;and can´t connect manually because the user does not have a user certificate.&lt;/P&gt;
&lt;P&gt;My doubt is:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Is this the expected behavior?? I was expecting that we don´t lose Wi-Fi connection automatically ate this point during the logging process.&lt;/LI&gt;
&lt;LI&gt;If point 1 is the expected behavior, how can we overcome this situation? Because I don´t have wired connections.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Thank you&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;T&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2025 23:58:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/user-or-machine-eap-tls-authentication-for-the-first-time/m-p/5254520#M594624</guid>
      <dc:creator>icarimo</dc:creator>
      <dc:date>2025-01-29T23:58:20Z</dc:date>
    </item>
    <item>
      <title>Re: User or machine EAP-TLS authentication for the first time</title>
      <link>https://community.cisco.com/t5/network-access-control/user-or-machine-eap-tls-authentication-for-the-first-time/m-p/5254524#M594625</link>
      <description>&lt;P&gt;My current GPO:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="icarimo_2-1738195354982.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/238751i96A46EFB10C8B88A/image-size/medium?v=v2&amp;amp;px=400" role="button" title="icarimo_2-1738195354982.png" alt="icarimo_2-1738195354982.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="icarimo_0-1738195326748.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/238749iF362B16D8A4815C1/image-size/medium?v=v2&amp;amp;px=400" role="button" title="icarimo_0-1738195326748.png" alt="icarimo_0-1738195326748.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="icarimo_1-1738195349733.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/238750i096F882C03A940A4/image-size/medium?v=v2&amp;amp;px=400" role="button" title="icarimo_1-1738195349733.png" alt="icarimo_1-1738195349733.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jan 2025 00:02:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/user-or-machine-eap-tls-authentication-for-the-first-time/m-p/5254524#M594625</guid>
      <dc:creator>icarimo</dc:creator>
      <dc:date>2025-01-30T00:02:52Z</dc:date>
    </item>
    <item>
      <title>Re: User or machine EAP-TLS authentication for the first time</title>
      <link>https://community.cisco.com/t5/network-access-control/user-or-machine-eap-tls-authentication-for-the-first-time/m-p/5254529#M594626</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1711599"&gt;@icarimo&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;I think this is expected behavior. There are some discussions here in the forum related, this one below is a bit old but I believe can help you somehow.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/network-access-control/ise-deployment-eap-tls-machine-or-user-certificates-native/td-p/4094444" target="_blank"&gt;https://community.cisco.com/t5/network-access-control/ise-deployment-eap-tls-machine-or-user-certificates-native/td-p/4094444&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jan 2025 00:22:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/user-or-machine-eap-tls-authentication-for-the-first-time/m-p/5254529#M594626</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2025-01-30T00:22:11Z</dc:date>
    </item>
    <item>
      <title>Re: User or machine EAP-TLS authentication for the first time</title>
      <link>https://community.cisco.com/t5/network-access-control/user-or-machine-eap-tls-authentication-for-the-first-time/m-p/5254531#M594627</link>
      <description>&lt;P&gt;Hello Flavio,&lt;BR /&gt;&lt;BR /&gt;Thank you so much for the feedback.&lt;BR /&gt;Yes, I saw several discuss about this issue, however I didn´t no what is the solution to fix it &lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;If you have ever faced it, please, let me know.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jan 2025 00:25:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/user-or-machine-eap-tls-authentication-for-the-first-time/m-p/5254531#M594627</guid>
      <dc:creator>icarimo</dc:creator>
      <dc:date>2025-01-30T00:25:36Z</dc:date>
    </item>
    <item>
      <title>Re: User or machine EAP-TLS authentication for the first time</title>
      <link>https://community.cisco.com/t5/network-access-control/user-or-machine-eap-tls-authentication-for-the-first-time/m-p/5254535#M594628</link>
      <description>&lt;P&gt;This is absolutely expected behaviour due to the fact that the User GPO does not get applied until after the transition to the User state as shown in the order of operations image in the post shared by Flavio.&lt;/P&gt;
&lt;P&gt;The best workaround for this 'catch-22' situation is using TEAP(EAP-TLS) as described in this discussion:&lt;BR /&gt;&lt;A href="https://community.cisco.com/t5/network-access-control/eap-teap-first-time-user-login-chicken-amp-egg-scenario/td-p/4475351" target="_blank"&gt;https://community.cisco.com/t5/network-access-control/eap-teap-first-time-user-login-chicken-amp-egg-scenario/td-p/4475351&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jan 2025 00:33:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/user-or-machine-eap-tls-authentication-for-the-first-time/m-p/5254535#M594628</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2025-01-30T00:33:26Z</dc:date>
    </item>
    <item>
      <title>Re: User or machine EAP-TLS authentication for the first time</title>
      <link>https://community.cisco.com/t5/network-access-control/user-or-machine-eap-tls-authentication-for-the-first-time/m-p/5254536#M594629</link>
      <description>&lt;P&gt;Usually the device is provisioned before the end user gets it.&amp;nbsp; That way everything is ready to go.&amp;nbsp; What I have seen done was to have another rule to allow PEAP or machine auth and then a GPO is pushed to prevent the onboarding SSID from being viewed/selected.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jan 2025 00:35:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/user-or-machine-eap-tls-authentication-for-the-first-time/m-p/5254536#M594629</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2025-01-30T00:35:36Z</dc:date>
    </item>
  </channel>
</rss>

