<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Wireless and Wired Network  enforce user authentication with ACS in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/wireless-and-wired-network-enforce-user-authentication-with-acs/m-p/2317297#M97558</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks &lt;A _jive_internal="true" href="https://community.cisco.com/people/jkatyal" id="jive-2073119985258089200495"&gt;Jatin Katyal&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I see the link but according TAC is not possible to force the second authentication in the acs v5.3&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this true?. Exist any paper or pdf where explain it?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ivan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 25 Sep 2013 03:58:14 GMT</pubDate>
    <dc:creator>ivan.martin</dc:creator>
    <dc:date>2013-09-25T03:58:14Z</dc:date>
    <item>
      <title>Wireless and Wired Network  enforce user authentication with ACS after computer authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/wireless-and-wired-network-enforce-user-authentication-with-acs/m-p/2317291#M97552</link>
      <description>&lt;P&gt;Hi my name is Ivan, i have an issue of control access in the wired and wireless network&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is possible to enforce computer authentication + user authentication with the ACS 5.3 after the computer authentication?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a network 802.1x eap peap to authenticate user and computer in the wired and wireless network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The ACS has two policies to authenticate computers and users. We have 3 cases:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Case 1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When the user configures 802.1X SSID parameter specifying user or computer authentication, ACS successfully validated the computer and the user's account. This works very well&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Case 2&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When the user configures 802.1X SSID parameter specifying single user authentication, the ACS validates the computer prior to and after the user credential. This works fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Case 3&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But when the user configures the SSID 802.1X parameters, specifying the computer authentication, ACS successfully validated only the computer, not the user account. When the computer was authenticated, the computer access to internet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Need in the third case, the ACS validates both the computer and the user, when the user specifies the computer authentication and after the authentication of the computer&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The case 1 and 2 works very good in the wireless and wired network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is possible to do it in the ACS?-&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 03:55:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wireless-and-wired-network-enforce-user-authentication-with-acs/m-p/2317291#M97552</guid>
      <dc:creator>ivan.martin</dc:creator>
      <dc:date>2019-03-11T03:55:54Z</dc:date>
    </item>
    <item>
      <title>Wireless and Wired Network  enforce user authentication with ACS</title>
      <link>https://community.cisco.com/t5/network-access-control/wireless-and-wired-network-enforce-user-authentication-with-acs/m-p/2317292#M97553</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I put something together a while ago and its in this thread.&amp;nbsp; You have to use MARS and have two policies defined.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://community.cisco.com/message/3525141#3525141"&gt;https://supportforums.cisco.com/message/3525141#3525141&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, &lt;BR /&gt; &lt;BR /&gt;Scott &lt;BR /&gt; &lt;BR /&gt;Help out other by using the rating system and marking answered questions as "Answered"&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Sep 2013 02:51:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wireless-and-wired-network-enforce-user-authentication-with-acs/m-p/2317292#M97553</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2013-09-25T02:51:16Z</dc:date>
    </item>
    <item>
      <title>Wireless and Wired Network  enforce user authentication with ACS</title>
      <link>https://community.cisco.com/t5/network-access-control/wireless-and-wired-network-enforce-user-authentication-with-acs/m-p/2317293#M97554</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Ivan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Not sure if you have gone through this link.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://community.cisco.com/thread/2123696"&gt;https://supportforums.cisco.com/thread/2123696&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think your issue is detailed in there.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Najaf&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;Please rate when applicable or helpful !!!&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Sep 2013 02:55:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wireless-and-wired-network-enforce-user-authentication-with-acs/m-p/2317293#M97554</guid>
      <dc:creator>kcnajaf</dc:creator>
      <dc:date>2013-09-25T02:55:50Z</dc:date>
    </item>
    <item>
      <title>Wireless and Wired Network  enforce user authentication with ACS</title>
      <link>https://community.cisco.com/t5/network-access-control/wireless-and-wired-network-enforce-user-authentication-with-acs/m-p/2317294#M97555</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Scott&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your answer. MAR is enabled, I set the aging time in one month. but I need to enforce authentication of user after the authentication of the computer in the ACS 5.3&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is possible to do it?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Sep 2013 02:56:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wireless-and-wired-network-enforce-user-authentication-with-acs/m-p/2317294#M97555</guid>
      <dc:creator>ivan.martin</dc:creator>
      <dc:date>2013-09-25T02:56:46Z</dc:date>
    </item>
    <item>
      <title>Wireless and Wired Network  enforce user authentication with ACS</title>
      <link>https://community.cisco.com/t5/network-access-control/wireless-and-wired-network-enforce-user-authentication-with-acs/m-p/2317295#M97556</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&amp;nbsp; &lt;A _jive_internal="true" href="https://community.cisco.com/people/kcnajaf@25070" id="jive-6510969981664700310223"&gt;Najaf KC&lt;/A&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your answer. In the link say:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV&gt; Jan 18, 2012 6:29 AM &lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;STRONG&gt; &lt;A _jive_internal="true" href="https://community.cisco.com/message/3537629#3537629"&gt; &lt;/A&gt; &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV&gt;&lt;P&gt; Hi All;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Finally cisco TAC confirmed that there is no way that we can enforce user authentication with ACS.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. when authenticate as computer option is selected on the laptop , and machine authentication on the ACS enabled.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;what&amp;nbsp; happens the laptop goes through machine authentication and it gains&amp;nbsp; access, the customer wants to get prompted for a username and password&amp;nbsp; if no user name or not correct username.pass provided then he wants to&amp;nbsp; deny access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ANS&amp;nbsp; : With MAR we can enforce machine authentication, however in the ACS it&amp;nbsp; is not possible to enforce user authentication, only machine&amp;nbsp; authentication.&lt;/P&gt;&lt;P&gt;So you can't enforce the user auth to be the one&amp;nbsp; who decides if the client is going to gain access or not after machine&amp;nbsp; auth succeeds.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks &amp;amp; Regards&lt;/P&gt;&lt;P&gt;Sreejith R&lt;/P&gt;&lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Exists any paper, pdf or link where explain this issue in the ACS?.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your advice.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Sep 2013 03:02:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wireless-and-wired-network-enforce-user-authentication-with-acs/m-p/2317295#M97556</guid>
      <dc:creator>ivan.martin</dc:creator>
      <dc:date>2013-09-25T03:02:04Z</dc:date>
    </item>
    <item>
      <title>Wireless and Wired Network  enforce user authentication with ACS</title>
      <link>https://community.cisco.com/t5/network-access-control/wireless-and-wired-network-enforce-user-authentication-with-acs/m-p/2317296#M97557</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ivan, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In ACS 5.3, you can do machine authentication followed by a user authentication.&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-wiki-small" href="https://community.cisco.com/docs/DOC-21825"&gt;https://supportforums.cisco.com/docs/DOC-21825&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;~BR &lt;BR /&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt;**Do rate helpful posts**&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Sep 2013 03:14:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wireless-and-wired-network-enforce-user-authentication-with-acs/m-p/2317296#M97557</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-09-25T03:14:18Z</dc:date>
    </item>
    <item>
      <title>Wireless and Wired Network  enforce user authentication with ACS</title>
      <link>https://community.cisco.com/t5/network-access-control/wireless-and-wired-network-enforce-user-authentication-with-acs/m-p/2317297#M97558</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks &lt;A _jive_internal="true" href="https://community.cisco.com/people/jkatyal" id="jive-2073119985258089200495"&gt;Jatin Katyal&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I see the link but according TAC is not possible to force the second authentication in the acs v5.3&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this true?. Exist any paper or pdf where explain it?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ivan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Sep 2013 03:58:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wireless-and-wired-network-enforce-user-authentication-with-acs/m-p/2317297#M97558</guid>
      <dc:creator>ivan.martin</dc:creator>
      <dc:date>2013-09-25T03:58:14Z</dc:date>
    </item>
    <item>
      <title>Wireless and Wired Network  enforce user authentication with ACS</title>
      <link>https://community.cisco.com/t5/network-access-control/wireless-and-wired-network-enforce-user-authentication-with-acs/m-p/2317298#M97559</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;that's not true.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please check the below listed link:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_system/5.3/user/guide/eap_pap_phase.html#wp1014866"&gt;http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_system/5.3/user/guide/eap_pap_phase.html#wp1014866&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_system/5.3/user/guide/users_id_stores.html#wp1171007"&gt;http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_system/5.3/user/guide/users_id_stores.html#wp1171007&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;~BR &lt;BR /&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt;**Do rate helpful posts**&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Sep 2013 04:04:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wireless-and-wired-network-enforce-user-authentication-with-acs/m-p/2317298#M97559</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-09-25T04:04:19Z</dc:date>
    </item>
    <item>
      <title>Wireless and Wired Network  enforce user authentication with ACS</title>
      <link>https://community.cisco.com/t5/network-access-control/wireless-and-wired-network-enforce-user-authentication-with-acs/m-p/2317299#M97560</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Did that help you understanding the machine and user authentication (MAR) concept with ACS 5.x?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;~BR &lt;BR /&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt;**Do rate helpful posts**&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Sep 2013 04:51:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wireless-and-wired-network-enforce-user-authentication-with-acs/m-p/2317299#M97560</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-09-26T04:51:36Z</dc:date>
    </item>
    <item>
      <title>Wireless and Wired Network  enforce user authentication with ACS</title>
      <link>https://community.cisco.com/t5/network-access-control/wireless-and-wired-network-enforce-user-authentication-with-acs/m-p/2317300#M97561</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hola Jatin buen dia, para coincidir con el detalle del problema lo detallo en español.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;El problema es el siguiente:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;El usuario configura su tarjeta de red inalambrica para utilizar autenticacion de solo computadora.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cuando el usuario realiza esto, la computadora envia su credencial de laptop del dominio, y el acs observa el call station id de la computadora del dominio, busca en su base de datos externa la cual es el Directorio Activo, y dado que esta coincide como objeto del dominio, se autentica a la red inalambrica. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pero el acs en ningun momento pide la autenticacion de usuario, o el prompt de autenticacion de usuario, porque la computadora ya se autentico y autorizo como objeto del dominio.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Lo que se desea es que cualesquier configuracion que el usuario realize en la tarjeta de red inalambrica para que la autenticacion sea como computadora, usuario o computadora o solo usuario, el acs siempre valide autentique la computadora y la cuenta de usuario.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Que la politica de autenticacion sea un estamente Y y no un O. Cuando el usuario configura su tarjeta de red inalambrica como usuario o computadora, el acs si ejecuta la politica de autentica para usuario y computadora porque exige al usuario validar en primer lugar la computadora.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Nuestro problema es el descrito lineas abajo Politica de Autenticacion de Computadora + Usuario, siempre el ACS debe pedir el prompt de autenticacion para usuario, asi el atributo sea de solo computadora del lado del cliente.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Saludos.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ivan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Sep 2013 16:22:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wireless-and-wired-network-enforce-user-authentication-with-acs/m-p/2317300#M97561</guid>
      <dc:creator>ivan.martin</dc:creator>
      <dc:date>2013-09-26T16:22:02Z</dc:date>
    </item>
    <item>
      <title>Wireless and Wired Network  enforce user authentication with ACS</title>
      <link>https://community.cisco.com/t5/network-access-control/wireless-and-wired-network-enforce-user-authentication-with-acs/m-p/2317301#M97562</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Could you please post the same thing in english &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;~BR &lt;BR /&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt;**Do rate helpful posts**&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Sep 2013 23:51:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wireless-and-wired-network-enforce-user-authentication-with-acs/m-p/2317301#M97562</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-09-30T23:51:01Z</dc:date>
    </item>
    <item>
      <title>Wireless and Wired Network  enforce user authentication with ACS</title>
      <link>https://community.cisco.com/t5/network-access-control/wireless-and-wired-network-enforce-user-authentication-with-acs/m-p/2317302#M97563</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Jatin, the post in english&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jatin Hi good day, to match the detail of the problem as I detail in Spanish.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem is as follows:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The user configure his&amp;nbsp; wireless network card to use computer-only authentication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When the user does this, the computer sends the domain credential laptop, and look at the call station acs id domain computer, looking at its external database which is the Active Directory, and since this is the same as domain object, it authenticates the wireless network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But the acs at any time ask for user authentication, or user authentication prompt because the computer already authenticate and authorize as domain object.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What is desired is that any settings that the user Realize the wireless network card for the authentication either as computer user or single-user computer, provided validate acs authenticate the computer and user account.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let be an authentication policy and not a estamente And O. When the user configures your wireless network card as a user or computer, acs policy by running the user authenticates to computer because it requires the user to validate the computer first.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Our problem is the lines described below Computer Policy + User Authentication, ACS always should ask for user authentication prompt, so the attribute is the only client-side computer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Greetings.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ivan&lt;SPAN id="mce_marker"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN id="result_box" lang="en"&gt;&lt;SPAN class="hps"&gt;Jatin&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;Hi&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;good day,&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;to match the&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;detail&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;of the problem as&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;I detail in&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;Spanish&lt;/SPAN&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt; &lt;BR /&gt;&lt;SPAN class="hps"&gt;The problem&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;is as follows:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt; &lt;BR /&gt;&lt;SPAN class="hps"&gt;You configure&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;your&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;wireless&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;network card&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;to use&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;computer&lt;/SPAN&gt;&lt;SPAN&gt;-only&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;authentication&lt;/SPAN&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt; &lt;BR /&gt;&lt;SPAN class="hps"&gt;When the user&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;does this&lt;/SPAN&gt;&lt;SPAN&gt;, the computer&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;sends&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;the&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;domain&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;credential&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;laptop&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;and&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;look at the&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;call&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;station&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;acs&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;id&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;domain&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;computer&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;looking&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;at its&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;external database&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;which is the&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;Active&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;Directory&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;and since this&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;is the same as&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;domain object&lt;/SPAN&gt;&lt;SPAN&gt;, it&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;authenticates&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;the wireless network.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt; &lt;BR /&gt;&lt;SPAN class="hps"&gt;But the&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;acs&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;at any time&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;ask for&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;user&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;authentication&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;or&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;user&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;authentication&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;prompt&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;because&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;the computer&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;already&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;authenticate&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;and authorize&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;as&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;domain object&lt;/SPAN&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt; &lt;BR /&gt;&lt;SPAN class="hps"&gt;What is desired&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;is that&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;any&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;settings&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;that the user&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;Realize&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;the&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;wireless&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;network card&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;for the&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;authentication&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;either as&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;computer&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;user&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;or&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;single-user&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;computer&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;provided&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;validate&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;acs&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;authenticate&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;the&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;computer and&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;user account.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt; &lt;BR /&gt;&lt;SPAN class="hps"&gt;Let&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;be an&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;authentication&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;policy&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;and not a&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;estamente&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;And&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;O.&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;When the user&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;configures your&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;wireless&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;network card&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;as a user&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;or&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;computer,&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;acs&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;policy&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;by running the&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;user&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;authenticates&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;to&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;computer&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;because it requires&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;the user to validate&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;the computer&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;first&lt;/SPAN&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt; &lt;BR /&gt;&lt;SPAN class="hps"&gt;Our problem&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;is the&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;lines&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;described&lt;/SPAN&gt; &lt;A&gt;&lt;/A&gt;abive &lt;SPAN class="hps"&gt;Computer&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;Policy&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;+&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;User&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;Authentication&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;ACS&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;always&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;should ask&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;for&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;user&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;authentication&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;prompt&lt;/SPAN&gt;&lt;SPAN&gt;, so&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;the attribute is&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;the&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;only&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;client-side&lt;/SPAN&gt; &lt;SPAN class="hps"&gt;computer&lt;/SPAN&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt; &lt;BR /&gt;&lt;SPAN class="hps"&gt;Greetings&lt;/SPAN&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt; &lt;BR /&gt;&lt;SPAN class="hps"&gt;Ivan&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 01 Oct 2013 04:41:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wireless-and-wired-network-enforce-user-authentication-with-acs/m-p/2317302#M97563</guid>
      <dc:creator>ivan.martin</dc:creator>
      <dc:date>2013-10-01T04:41:59Z</dc:date>
    </item>
  </channel>
</rss>

