<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE and Two distinct Windows Domains in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ise-and-two-distinct-windows-domains/m-p/2087808#M433650</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here's the list of which methods are supported when using different kinds of user databases :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/ise/1.0/user_guide/ise10_man_id_stores.html#wp1053140"&gt;http://www.cisco.com/en/US/docs/security/ise/1.0/user_guide/ise10_man_id_stores.html#wp1053140&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 05 Dec 2012 20:24:58 GMT</pubDate>
    <dc:creator>jan.nielsen</dc:creator>
    <dc:date>2012-12-05T20:24:58Z</dc:date>
    <item>
      <title>ISE and Two distinct Windows Domains</title>
      <link>https://community.cisco.com/t5/network-security/ise-and-two-distinct-windows-domains/m-p/2087806#M433648</link>
      <description>&lt;P&gt;All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a customer who wants to integrate ISE with two seperate Windows Domains, they have no trust releationship. We can integrate with one of the domains and can make use of LDAP for the other but can only get Machine Authentication working with the domain with the full integration. Machine authentication will not work with LDAP, only user authentication. The problem is the config of the switches places the client in the guest network as they fail machine auth and then client auth is not recognised by the switch. I'm thinking about either not going direct to MAB if a user fails machine auth or diabling guest all together as the porblem is a guest with a dot1x suplication is not given guest access in a timely mannor without this command. Another option I have thought about is to use the radius token external identity store to talk to a Cisco ACS server attached to the other domain.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help would be greatly appreciated&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Simon&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 12:47:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ise-and-two-distinct-windows-domains/m-p/2087806#M433648</guid>
      <dc:creator>nowcommsupport</dc:creator>
      <dc:date>2020-02-21T12:47:52Z</dc:date>
    </item>
    <item>
      <title>ISE and Two distinct Windows Domains</title>
      <link>https://community.cisco.com/t5/network-security/ise-and-two-distinct-windows-domains/m-p/2087807#M433649</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When you use LDAP for AD authentication, you are limited to using EAP-TLS (certificates) or EAP-GTC (plain text passwords), so if you are at all concerned about security you will use EAP-TLS.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Dec 2012 20:23:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ise-and-two-distinct-windows-domains/m-p/2087807#M433649</guid>
      <dc:creator>jan.nielsen</dc:creator>
      <dc:date>2012-12-05T20:23:49Z</dc:date>
    </item>
    <item>
      <title>ISE and Two distinct Windows Domains</title>
      <link>https://community.cisco.com/t5/network-security/ise-and-two-distinct-windows-domains/m-p/2087808#M433650</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here's the list of which methods are supported when using different kinds of user databases :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/ise/1.0/user_guide/ise10_man_id_stores.html#wp1053140"&gt;http://www.cisco.com/en/US/docs/security/ise/1.0/user_guide/ise10_man_id_stores.html#wp1053140&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Dec 2012 20:24:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ise-and-two-distinct-windows-domains/m-p/2087808#M433650</guid>
      <dc:creator>jan.nielsen</dc:creator>
      <dc:date>2012-12-05T20:24:58Z</dc:date>
    </item>
  </channel>
</rss>

