<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: TEAP Failed User in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/teap-failed-user/m-p/5365114#M599636</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/317733"&gt;@Leonardo Santana&lt;/a&gt;&amp;nbsp;If main aaa.com is an alias for domain xyz.com, you need to use ISE Identity Rewrite feature for user authentication with SAN in format &lt;A href="mailto:user@aaa,con" target="_blank"&gt;user@aaa.com&amp;nbsp;&amp;nbsp;&lt;/A&gt;to be successful. See here starting with page 668:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/3-3/admin_guide/b_ise_admin_3_3.pdf" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/3-3/admin_guide/b_ise_admin_3_3.pdf&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Cristian.&lt;/P&gt;</description>
    <pubDate>Sun, 25 Jan 2026 19:26:09 GMT</pubDate>
    <dc:creator>Cristian Matei</dc:creator>
    <dc:date>2026-01-25T19:26:09Z</dc:date>
    <item>
      <title>TEAP Failed User</title>
      <link>https://community.cisco.com/t5/network-access-control/teap-failed-user/m-p/5360322#M599504</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Our customer is using 2xCisco ISE 3.4 P3 integrated with AD.&lt;/P&gt;
&lt;P&gt;They have two domains xyz.com and aaa.com.&lt;/P&gt;
&lt;P&gt;Cisco ISE is configured at the domain xyz.com&lt;/P&gt;
&lt;P&gt;We are using TEAP for dot1x and the computer authentication is working. Only the user authentication is failling.&lt;/P&gt;
&lt;P&gt;The computer certificate is using the as SAN the name.zyz.com and the user certificate is using the other domain &lt;A href="mailto:user@aaa.com" target="_blank" rel="noopener"&gt;user@aaa.com&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;The user domain is an alias.&lt;/P&gt;
&lt;P&gt;How ISE will look this? Because the user authentication is failling. The domain must be the same for users and computers?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Jan 2026 17:33:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/teap-failed-user/m-p/5360322#M599504</guid>
      <dc:creator>Leonardo Santana</dc:creator>
      <dc:date>2026-01-09T17:33:34Z</dc:date>
    </item>
    <item>
      <title>Re: TEAP Failed User</title>
      <link>https://community.cisco.com/t5/network-access-control/teap-failed-user/m-p/5360346#M599506</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp; The two domains, xyzzy.com and aaa.com are totally separate domains, or part of a forest with trust in between?&lt;/P&gt;
&lt;P&gt;&amp;nbsp; ISE is integrated only with domain xyz.com?&lt;/P&gt;
&lt;P&gt;&amp;nbsp; The user certificate SAN is &lt;A href="mailto:user@aaa.com?" target="_blank"&gt;user@aaa.com?&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; SAN / Identity of computer and user don't need to be part of the same domain or have the same domain extension, it's a matter of proper integration and configuration on ISE side. &amp;nbsp;Can you post a print-screen with the authentication failure message from ISE?&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Cristian.&lt;/P&gt;</description>
      <pubDate>Fri, 09 Jan 2026 19:27:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/teap-failed-user/m-p/5360346#M599506</guid>
      <dc:creator>Cristian Matei</dc:creator>
      <dc:date>2026-01-09T19:27:56Z</dc:date>
    </item>
    <item>
      <title>Re: TEAP Failed User</title>
      <link>https://community.cisco.com/t5/network-access-control/teap-failed-user/m-p/5360434#M599517</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;The two domains, xyzzy.com and aaa.com are totally separate domains, or part of a forest with trust in between?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The xyz.com is a domain and aaa.com is just an alias.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;ISE is integrated only with domain xyz.com? Yes&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The user certificate SAN is&amp;nbsp;&lt;A href="mailto:user@aaa.com?" target="_blank" rel="nofollow noopener noreferrer"&gt;user@aaa.com?&lt;/A&gt;&amp;nbsp;Yes&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;The aaa.com is not under allowed domains at Cisco ISE.&lt;/P&gt;</description>
      <pubDate>Sat, 10 Jan 2026 17:25:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/teap-failed-user/m-p/5360434#M599517</guid>
      <dc:creator>Leonardo Santana</dc:creator>
      <dc:date>2026-01-10T17:25:18Z</dc:date>
    </item>
    <item>
      <title>Re: TEAP Failed User</title>
      <link>https://community.cisco.com/t5/network-access-control/teap-failed-user/m-p/5365114#M599636</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/317733"&gt;@Leonardo Santana&lt;/a&gt;&amp;nbsp;If main aaa.com is an alias for domain xyz.com, you need to use ISE Identity Rewrite feature for user authentication with SAN in format &lt;A href="mailto:user@aaa,con" target="_blank"&gt;user@aaa.com&amp;nbsp;&amp;nbsp;&lt;/A&gt;to be successful. See here starting with page 668:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/3-3/admin_guide/b_ise_admin_3_3.pdf" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/3-3/admin_guide/b_ise_admin_3_3.pdf&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Cristian.&lt;/P&gt;</description>
      <pubDate>Sun, 25 Jan 2026 19:26:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/teap-failed-user/m-p/5365114#M599636</guid>
      <dc:creator>Cristian Matei</dc:creator>
      <dc:date>2026-01-25T19:26:09Z</dc:date>
    </item>
  </channel>
</rss>

