<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic I want the ISE 802.1x  to only PEAP-MSCHAP-V2 without provisioni in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/i-want-the-ise-802-1x-to-only-peap-mschap-v2-without/m-p/2364772#M88652</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I saw your message in a different post so this is an android device. Basically the CNA app for the android is needed to pull the peap profile, but if you are using peap already and are looking to bypass the CWA after entering peap credentials, we need to set your authorization policy so that if the device is registered, and PEAP is used you can then get through without redirection.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you are relying on profiling i.e. Android + PEAP + Registered + AD Domain Group, you may not be matching the endpoint profile or identity group and are probably skipping this rule. See if you can modify the Android to Registered..(drawing a blank to the proper name of the endpoint group for registered devices).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyways give that a shot or post your authorization policy so I can double check how the flow is working on your end. Also send a screenshot of the endpoint after it is registered as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 18 Jan 2014 06:09:03 GMT</pubDate>
    <dc:creator>Tarik Admani</dc:creator>
    <dc:date>2014-01-18T06:09:03Z</dc:date>
    <item>
      <title>I want the ISE 802.1x  to only PEAP-MSCHAP-V2 without provisioning</title>
      <link>https://community.cisco.com/t5/network-access-control/i-want-the-ise-802-1x-to-only-peap-mschap-v2-without/m-p/2364771#M88651</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm using an ISE v1.2 to authenticate corporate users connecting to a Corporate SSID with WPA2-Entreprise (802.1x). The client isn't planning to implement a PKI Infraestructure to use EAP-TLS, so they want to authenticate using only PEAP-MS-CHAPV2 with user credentials. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is working right now but I don't want the ISE to redirect Android phones to Google Play (Because the Network Setup Assistant is not needed, there are no certificate enrollment needed, in fact when I open the application it doesn't even communicate with the ISE). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The following is the procedure when I connect my Android device:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Enter user credentials &amp;lt;--- ok&lt;/P&gt;&lt;P&gt;2) Redirect to my devices Portal &amp;lt;--- ok&lt;/P&gt;&lt;P&gt;3) Register the device&amp;nbsp; &amp;lt;--- ok&lt;/P&gt;&lt;P&gt;4) Redirect to Google Play&amp;nbsp; &amp;lt;--- not needed&lt;/P&gt;&lt;P&gt;5) I cancel and connect succesfully &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What I want is the user to register their mobile devices using "My devices Portal" and with that CoA grant access but without provisioning. When I set it that way(no client provisioning policies) the ISE cannot get the Device ID(MAC-Address) to register at my devices portal (even setting the "Native Supplicant Provisioning Policy Unavailable=Allow Network Access")&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've attached two screenshots from the Android Device:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NO ID.jpg = ISE cannot get the MAC-Address.&lt;/P&gt;&lt;P&gt;NSA.png = Network Setup Assistant cannot find ISE.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you need any screenshot of the ISE config let me know.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 04:17:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/i-want-the-ise-802-1x-to-only-peap-mschap-v2-without/m-p/2364771#M88651</guid>
      <dc:creator>jverdesca</dc:creator>
      <dc:date>2019-03-11T04:17:44Z</dc:date>
    </item>
    <item>
      <title>I want the ISE 802.1x  to only PEAP-MSCHAP-V2 without provisioni</title>
      <link>https://community.cisco.com/t5/network-access-control/i-want-the-ise-802-1x-to-only-peap-mschap-v2-without/m-p/2364772#M88652</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I saw your message in a different post so this is an android device. Basically the CNA app for the android is needed to pull the peap profile, but if you are using peap already and are looking to bypass the CWA after entering peap credentials, we need to set your authorization policy so that if the device is registered, and PEAP is used you can then get through without redirection.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you are relying on profiling i.e. Android + PEAP + Registered + AD Domain Group, you may not be matching the endpoint profile or identity group and are probably skipping this rule. See if you can modify the Android to Registered..(drawing a blank to the proper name of the endpoint group for registered devices).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyways give that a shot or post your authorization policy so I can double check how the flow is working on your end. Also send a screenshot of the endpoint after it is registered as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 18 Jan 2014 06:09:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/i-want-the-ise-802-1x-to-only-peap-mschap-v2-without/m-p/2364772#M88652</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2014-01-18T06:09:03Z</dc:date>
    </item>
    <item>
      <title>I want the ISE 802.1x  to only PEAP-MSCHAP-V2 without provisioni</title>
      <link>https://community.cisco.com/t5/network-access-control/i-want-the-ise-802-1x-to-only-peap-mschap-v2-without/m-p/2364773#M88653</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN&gt;Hi &lt;SPAN&gt;Tarik&lt;/SPAN&gt;,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your answers,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I've attached my configured &lt;SPAN&gt;AuthZ&lt;/SPAN&gt; rules and &lt;SPAN&gt;AuthZ&lt;/SPAN&gt; profile for provisioning,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I want the process to be the same for &lt;SPAN&gt;iPhone&lt;/SPAN&gt;, Android and Windows.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;1) Connect to the &lt;SPAN&gt;SSID&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2) Login using your AD credentials &lt;SPAN&gt;PEAP&lt;/SPAN&gt;-MS-CHAP-v2&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;3) Redirect to device registration portal (So I can set a limit of 3 devices per employee)&lt;/P&gt;&lt;P&gt;4) As soon as the client click "register" no more redirects and PERMIT-ALL&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I think that I don't need to rely on profiling because In terms of &lt;SPAN&gt;AuthZ&lt;/SPAN&gt; policies it should be something like this:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;1) if WIRELESS802.1x and &lt;SPAN&gt;PEAP&lt;/SPAN&gt;-MS-CHAPV2 and &lt;SPAN&gt;BYODREGISTRATION&lt;/SPAN&gt;=!YES(Unknown or not &lt;SPAN&gt;reg&lt;/SPAN&gt;) then "Redirect to device registration(that is &lt;SPAN&gt;NSP&lt;/SPAN&gt; right?)"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;2) if WIRELESS802.1x and PEAP-MS-CHAPV2 then PERMIT-ALL(no redirection)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3) everything else = DENY-ALL&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;But the &lt;SPAN&gt;NSP&lt;/SPAN&gt; looks for Client Provisioning policies, so if I don't configure any policy it should &lt;SPAN&gt;Allow Network Access&lt;/SPAN&gt;(See attachment photo3.&lt;SPAN&gt;png&lt;/SPAN&gt;) but as I said on the post it shows that cannot retrieve the MAC-Address&lt;/SPAN&gt; so the client can't register his device and don't have access to the network. (To grant access I've configured provisioning policies, that way the clients can register their devices but they are redirected to google play or are forced to install the profile at iOS and this is what I don't want because it is not necessary) &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What screenshoot do you need after the registration? the Auth report? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you very much for your time!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/legacy/4/9/5/177594-AuthZ%20Rules.png" alt="AuthZ Rules.png" class="jive-image-thumbnail jive-image" onclick="" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/legacy/4/7/5/177574-AuthZ%20Profile.png" alt="AuthZ Profile.png" class="jive-image-thumbnail jive-image" onclick="" width="450" /&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/legacy/3/9/5/177593-photo3.png" alt="photo3.png" class="jive-image-thumbnail jive-image" onclick="" width="450" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 18 Jan 2014 20:29:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/i-want-the-ise-802-1x-to-only-peap-mschap-v2-without/m-p/2364773#M88653</guid>
      <dc:creator>jverdesca</dc:creator>
      <dc:date>2014-01-18T20:29:15Z</dc:date>
    </item>
  </channel>
</rss>

