<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Well i guess you would need a in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ise-wireless-anyconnect/m-p/2514072#M1003327</link>
    <description>&lt;P&gt;Well i guess you would need a wired port with no dot1x for first time logins, or you could give the pc access to the AD servers it needs when the machine is authenticated, but not compliant yet.&lt;/P&gt;</description>
    <pubDate>Mon, 29 Sep 2014 04:07:11 GMT</pubDate>
    <dc:creator>jan.nielsen</dc:creator>
    <dc:date>2014-09-29T04:07:11Z</dc:date>
    <item>
      <title>ISE - Wireless Anyconnect</title>
      <link>https://community.cisco.com/t5/network-security/ise-wireless-anyconnect/m-p/2514070#M1003306</link>
      <description>&lt;P style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;&lt;FONT color="#000000"&gt;Hello! we have a doutb regarding our ISE installation. We have created a new SSID with EAP Chaninng validation (user + machine validation using Anyconnect client) through ISE, and NAC posture.&amp;nbsp;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;&lt;FONT color="#000000"&gt;The problem is that when a user has never logged in a PC and tries to log for the first time through this wireless, is not working. The facts are like this:&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;&lt;FONT color="#000000"&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;&lt;FONT color="#000000"&gt;- User introduces user/pass for the first time to computer&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;&lt;FONT color="#000000"&gt;- Computer needs to contact AD to download the profile&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;&lt;FONT color="#000000"&gt;- Computer associates with the network&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;&lt;FONT color="#000000"&gt;- ISE puts the user "on-hold" until it's NAC compliant&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;&lt;FONT color="#000000"&gt;- Computer never launches NAC process, so it's never compliant&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;&lt;FONT color="#000000"&gt;- ISE doesn't give access to network&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;&lt;FONT color="#000000"&gt;- User cannot login to computer.&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;&lt;FONT color="#000000"&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;&lt;FONT color="#000000"&gt;This only happens the first time a user tries to access the network because it needs to download the profile, if the user has logged in before, this is not a problem. Do you think there is any solution for this problem?&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 13:15:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ise-wireless-anyconnect/m-p/2514070#M1003306</guid>
      <dc:creator>Oscar Cardiel</dc:creator>
      <dc:date>2020-02-21T13:15:02Z</dc:date>
    </item>
    <item>
      <title>Use EAP Chaining with EAP</title>
      <link>https://community.cisco.com/t5/network-security/ise-wireless-anyconnect/m-p/2514071#M1003319</link>
      <description>&lt;P&gt;Use EAP Chaining with EAP-FAST v2. In the auth attempt, the supplicant provides the authentication server (ISE) both the machine and user credentials for each auth attempt.&amp;nbsp; Supported by the Cisco AnyConnect 3.1 client/supplicant . In ISE to enable its support (Policy-&amp;gt;Policy Elements-&amp;gt;Results-&amp;gt;Authentication-&amp;gt;Allowed Protocols-&amp;gt;Default Network Access &amp;lt;for example&amp;gt;-&amp;gt;Allow EAP-FAST).&lt;/P&gt;</description>
      <pubDate>Thu, 11 Sep 2014 22:42:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ise-wireless-anyconnect/m-p/2514071#M1003319</guid>
      <dc:creator>Saurav Lodh</dc:creator>
      <dc:date>2014-09-11T22:42:32Z</dc:date>
    </item>
    <item>
      <title>Well i guess you would need a</title>
      <link>https://community.cisco.com/t5/network-security/ise-wireless-anyconnect/m-p/2514072#M1003327</link>
      <description>&lt;P&gt;Well i guess you would need a wired port with no dot1x for first time logins, or you could give the pc access to the AD servers it needs when the machine is authenticated, but not compliant yet.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Sep 2014 04:07:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ise-wireless-anyconnect/m-p/2514072#M1003327</guid>
      <dc:creator>jan.nielsen</dc:creator>
      <dc:date>2014-09-29T04:07:11Z</dc:date>
    </item>
  </channel>
</rss>

