<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ACS 5.4 and machine authentication in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-5-4-and-machine-authentication/m-p/2388992#M89007</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Shivaji,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Remove Was machine authenticated= TRUE.&lt;/P&gt;&lt;P&gt;The reason is because how will Machine authentication request itself check if machine auth has passed in past.&lt;/P&gt;&lt;P&gt;Was machine authenticated is used for User authentication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;**Share your knowledge. It’s a way to achieve immortality. &lt;BR /&gt;--Dalai Lama** &lt;BR /&gt; &lt;BR /&gt;Please Rate if helpful. &lt;BR /&gt;Regards &lt;BR /&gt;Ed&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 03 Jan 2014 16:56:15 GMT</pubDate>
    <dc:creator>edwjames</dc:creator>
    <dc:date>2014-01-03T16:56:15Z</dc:date>
    <item>
      <title>ACS 5.4 and machine authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-4-and-machine-authentication/m-p/2388989#M89002</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am installing ACS 5.4 for WiFI user and using EAP-TLS/ certificate based authentication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have Authorization profile created as shown in attachement.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Under authorization profile i have selcted "Was Machine Authenticated=True"Condition.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Somehow clients are not able to connect. When I looked at logs on ACS it shows that the requests are not matching this rule bu default rule.&lt;/P&gt;&lt;P&gt;As soon as I disable this condition, user gets connected&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have already selected "Enable Machine Authentication" under AD &amp;amp; "Process host Lookup" in allowed protocol.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any Suggesions?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Shivaji&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 04:14:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-4-and-machine-authentication/m-p/2388989#M89002</guid>
      <dc:creator>central_bank</dc:creator>
      <dc:date>2019-03-11T04:14:00Z</dc:date>
    </item>
    <item>
      <title>ACS 5.4 and machine authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-4-and-machine-authentication/m-p/2388990#M89003</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Shivaji,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you go to the reporting section, open details (magnifying glass) on that report, there is a print to PDF on the top left?&lt;/P&gt;&lt;P&gt;Could you attach that PDF report over here?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;**Share your knowledge. It’s a way to achieve immortality. &lt;BR /&gt;--Dalai Lama** &lt;BR /&gt; &lt;BR /&gt;Please Rate if helpful. &lt;BR /&gt;Regards &lt;BR /&gt;Ed&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Jan 2014 12:41:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-4-and-machine-authentication/m-p/2388990#M89003</guid>
      <dc:creator>edwjames</dc:creator>
      <dc:date>2014-01-03T12:41:53Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 5.4 and machine authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-4-and-machine-authentication/m-p/2388991#M89005</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Ed, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Attached is the log, since original logs contains sensitive infor, I have replaced domain names, IP add etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;P&gt;Shivaji&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Jan 2014 15:39:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-4-and-machine-authentication/m-p/2388991#M89005</guid>
      <dc:creator>central_bank</dc:creator>
      <dc:date>2014-01-03T15:39:28Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 5.4 and machine authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-4-and-machine-authentication/m-p/2388992#M89007</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Shivaji,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Remove Was machine authenticated= TRUE.&lt;/P&gt;&lt;P&gt;The reason is because how will Machine authentication request itself check if machine auth has passed in past.&lt;/P&gt;&lt;P&gt;Was machine authenticated is used for User authentication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;**Share your knowledge. It’s a way to achieve immortality. &lt;BR /&gt;--Dalai Lama** &lt;BR /&gt; &lt;BR /&gt;Please Rate if helpful. &lt;BR /&gt;Regards &lt;BR /&gt;Ed&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Jan 2014 16:56:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-4-and-machine-authentication/m-p/2388992#M89007</guid>
      <dc:creator>edwjames</dc:creator>
      <dc:date>2014-01-03T16:56:15Z</dc:date>
    </item>
    <item>
      <title>ACS 5.4 and machine authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-4-and-machine-authentication/m-p/2388993#M89009</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hello Ed,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I need this condition, I know when I disable this WiFi works but my objective is to make it work using "was machine authenticated" feature.&lt;/P&gt;&lt;P&gt;My clients have 2 types of certs on their machine one is user specific and other is machine specific. In case I do not use&amp;nbsp; "was machine authenticated" condition, user can connect using user specific cert only which I dont want.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I want machine to be authenticated and not user before it is connected to WiFI&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Shivaji&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 05 Jan 2014 11:01:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-4-and-machine-authentication/m-p/2388993#M89009</guid>
      <dc:creator>central_bank</dc:creator>
      <dc:date>2014-01-05T11:01:33Z</dc:date>
    </item>
    <item>
      <title>ACS 5.4 and machine authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-4-and-machine-authentication/m-p/2388994#M89011</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Shivaji,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The purpose of the "wasmachineauthenticated" attribute is for user authentication, this is your typical "chicken or the egg" scenario since machine authentication needs to be performed without this attribute for successful authentication. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When successful machine authentication occurs there is a MAR cache within ACS uses to track the mac address of the device. In your case you are forcing ACS to look for a "WasMachineAuthenticated" during the initial machine authentication which will not succeed. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In my experience it is best to set this in environments where users' can only authenticate through registered workstations (typically machines that are joined to AD), so when a user attempts to use their 802.1x credentials on a smart phone or non-registered asset, they get denied since the device does not have machine credentials to join the network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope this bring some clarification to Edward's recommendation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 05 Jan 2014 17:54:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-4-and-machine-authentication/m-p/2388994#M89011</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2014-01-05T17:54:11Z</dc:date>
    </item>
    <item>
      <title>ACS 5.4 and machine authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-4-and-machine-authentication/m-p/2388995#M89014</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hello Tarik,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You are absolutely correct. I have to make sure that users are joining using laptops which are in domain and should not join using smart phones or non domain machine&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Shivaji&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Jan 2014 08:17:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-4-and-machine-authentication/m-p/2388995#M89014</guid>
      <dc:creator>central_bank</dc:creator>
      <dc:date>2014-01-06T08:17:07Z</dc:date>
    </item>
    <item>
      <title>ACS 5.4 and machine authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-4-and-machine-authentication/m-p/2388996#M89015</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I got it now, there is a seperate tab in ACS 5.4 for Machine Access Restriction under User and Identity stores--&amp;gt; Active Directory&lt;/P&gt;&lt;P&gt;which has to be enabled.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your inputs guys&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Shivaji&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Jan 2014 11:34:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-4-and-machine-authentication/m-p/2388996#M89015</guid>
      <dc:creator>central_bank</dc:creator>
      <dc:date>2014-01-06T11:34:47Z</dc:date>
    </item>
  </channel>
</rss>

