<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic TEAP (EAP-TLS) issue with user authentication in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/teap-eap-tls-issue-with-user-authentication/m-p/5319425#M597717</link>
    <description>&lt;P&gt;We configured EAP chaining for TEAP and enabled certificate-based authentication for both user and machine.&lt;/P&gt;&lt;P&gt;Below are some key points:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;ISE 3.3p7&lt;/LI&gt;&lt;LI&gt;Win 11&lt;/LI&gt;&lt;LI&gt;TEAP and EAP chaining protocols are enabled&lt;/LI&gt;&lt;LI&gt;We followed this &lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/216510-eap-chaining-with-teap.html#toc-hId-1877227078" target="_self"&gt;doc&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;Below is AuthZ policy set, and actions are permit all for both (for the sake of testing only)&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2025-08-11 104258.png" style="width: 976px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/250015iC8B9F7E1FA4F49AE/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2025-08-11 104258.png" alt="Screenshot 2025-08-11 104258.png" /&gt;&lt;/span&gt;&lt;/LI&gt;&lt;LI&gt;Here is the live logs result&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="nw.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/250026i378A6497BFA86A88/image-size/large?v=v2&amp;amp;px=999" role="button" title="nw.PNG" alt="nw.PNG" /&gt;&lt;/span&gt;&lt;/LI&gt;&lt;LI&gt;Here is the adapter auth settings&lt;/LI&gt;&lt;LI&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image (2).png" style="width: 374px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/250018i141411B9906C7652/image-size/large?v=v2&amp;amp;px=999" role="button" title="image (2).png" alt="image (2).png" /&gt;&lt;/span&gt;&lt;/LI&gt;&lt;LI&gt;Correct root cert is selected in both auth methods&lt;/LI&gt;&lt;LI&gt;User and machine cert enrollment is also working fine&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;Issue:&lt;/STRONG&gt; The machine gets successfully authenticated on wired connection and hit the correct policy but when the user log in, it hits the default ACCESS_REJECT policy.&lt;/P&gt;&lt;P&gt;Live logs results:&lt;/P&gt;&lt;P&gt;During machine auth =&amp;nbsp;&lt;/P&gt;&lt;TABLE border="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;EapChainingResult&lt;/TD&gt;&lt;TD&gt;User failed and machine succeeded&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;During user auth =&amp;nbsp;&lt;/P&gt;&lt;TABLE border="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;EapChainingResult&lt;/TD&gt;&lt;TD&gt;User succeeded and machine failed&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;We are not able to achieve&amp;nbsp;User and machine succeeded result.&lt;/P&gt;&lt;P&gt;Any leads will be helpful!&lt;/P&gt;</description>
    <pubDate>Mon, 11 Aug 2025 08:19:54 GMT</pubDate>
    <dc:creator>abdullaS</dc:creator>
    <dc:date>2025-08-11T08:19:54Z</dc:date>
    <item>
      <title>TEAP (EAP-TLS) issue with user authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/teap-eap-tls-issue-with-user-authentication/m-p/5319425#M597717</link>
      <description>&lt;P&gt;We configured EAP chaining for TEAP and enabled certificate-based authentication for both user and machine.&lt;/P&gt;&lt;P&gt;Below are some key points:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;ISE 3.3p7&lt;/LI&gt;&lt;LI&gt;Win 11&lt;/LI&gt;&lt;LI&gt;TEAP and EAP chaining protocols are enabled&lt;/LI&gt;&lt;LI&gt;We followed this &lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/216510-eap-chaining-with-teap.html#toc-hId-1877227078" target="_self"&gt;doc&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;Below is AuthZ policy set, and actions are permit all for both (for the sake of testing only)&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2025-08-11 104258.png" style="width: 976px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/250015iC8B9F7E1FA4F49AE/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2025-08-11 104258.png" alt="Screenshot 2025-08-11 104258.png" /&gt;&lt;/span&gt;&lt;/LI&gt;&lt;LI&gt;Here is the live logs result&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="nw.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/250026i378A6497BFA86A88/image-size/large?v=v2&amp;amp;px=999" role="button" title="nw.PNG" alt="nw.PNG" /&gt;&lt;/span&gt;&lt;/LI&gt;&lt;LI&gt;Here is the adapter auth settings&lt;/LI&gt;&lt;LI&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image (2).png" style="width: 374px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/250018i141411B9906C7652/image-size/large?v=v2&amp;amp;px=999" role="button" title="image (2).png" alt="image (2).png" /&gt;&lt;/span&gt;&lt;/LI&gt;&lt;LI&gt;Correct root cert is selected in both auth methods&lt;/LI&gt;&lt;LI&gt;User and machine cert enrollment is also working fine&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;Issue:&lt;/STRONG&gt; The machine gets successfully authenticated on wired connection and hit the correct policy but when the user log in, it hits the default ACCESS_REJECT policy.&lt;/P&gt;&lt;P&gt;Live logs results:&lt;/P&gt;&lt;P&gt;During machine auth =&amp;nbsp;&lt;/P&gt;&lt;TABLE border="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;EapChainingResult&lt;/TD&gt;&lt;TD&gt;User failed and machine succeeded&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;During user auth =&amp;nbsp;&lt;/P&gt;&lt;TABLE border="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;EapChainingResult&lt;/TD&gt;&lt;TD&gt;User succeeded and machine failed&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;We are not able to achieve&amp;nbsp;User and machine succeeded result.&lt;/P&gt;&lt;P&gt;Any leads will be helpful!&lt;/P&gt;</description>
      <pubDate>Mon, 11 Aug 2025 08:19:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/teap-eap-tls-issue-with-user-authentication/m-p/5319425#M597717</guid>
      <dc:creator>abdullaS</dc:creator>
      <dc:date>2025-08-11T08:19:54Z</dc:date>
    </item>
    <item>
      <title>Re: TEAP (EAP-TLS) issue with user authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/teap-eap-tls-issue-with-user-authentication/m-p/5319436#M597720</link>
      <description>&lt;P&gt;Do you have such authorization policy for both suceeded?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Aug 2025 08:52:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/teap-eap-tls-issue-with-user-authentication/m-p/5319436#M597720</guid>
      <dc:creator>JPavonM</dc:creator>
      <dc:date>2025-08-11T08:52:16Z</dc:date>
    </item>
    <item>
      <title>Re: TEAP (EAP-TLS) issue with user authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/teap-eap-tls-issue-with-user-authentication/m-p/5319438#M597721</link>
      <description>&lt;P&gt;only change the order of Authz&amp;nbsp;&lt;BR /&gt;1- both success&amp;nbsp;&lt;BR /&gt;2- user failed and machine success&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;this order is write in doc you share and this what I know how you config chain&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;MHM&lt;/P&gt;</description>
      <pubDate>Mon, 11 Aug 2025 09:02:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/teap-eap-tls-issue-with-user-authentication/m-p/5319438#M597721</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-08-11T09:02:37Z</dc:date>
    </item>
    <item>
      <title>Re: TEAP (EAP-TLS) issue with user authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/teap-eap-tls-issue-with-user-authentication/m-p/5319442#M597724</link>
      <description>&lt;P&gt;Yes this one.. but i cannot see eap chain result of both succeeded in the live logs when user login&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2025-08-11 120246.png" style="width: 812px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/250030iD58B11EEB684E6FD/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2025-08-11 120246.png" alt="Screenshot 2025-08-11 120246.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Aug 2025 09:05:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/teap-eap-tls-issue-with-user-authentication/m-p/5319442#M597724</guid>
      <dc:creator>abdullaS</dc:creator>
      <dc:date>2025-08-11T09:05:33Z</dc:date>
    </item>
    <item>
      <title>Re: TEAP (EAP-TLS) issue with user authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/teap-eap-tls-issue-with-user-authentication/m-p/5319520#M597728</link>
      <description>&lt;P&gt;Update:&lt;/P&gt;&lt;P&gt;This issue was resolved. There were some mismatch attributes in SAN of the user cert after making some changings the issue was resolved.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Aug 2025 12:10:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/teap-eap-tls-issue-with-user-authentication/m-p/5319520#M597728</guid>
      <dc:creator>abdullaS</dc:creator>
      <dc:date>2025-08-11T12:10:41Z</dc:date>
    </item>
  </channel>
</rss>

