<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic From my testing in the past, in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/user-and-computer-authentication/m-p/2673549#M140030</link>
    <description>&lt;P&gt;From my testing in the past, you can't do both.&amp;nbsp; If you look at the supplicant, it shows User OR Computer, not an AND.&amp;nbsp; If you sniff the traffic, you will see an initial machine name come through then the user credentials.&amp;nbsp; After that however, you will only see user credentials.&amp;nbsp; ACS, ISE, ClearPass, has workarounds to cache the original machine credentials, but not NPS.&amp;nbsp; Also in the NP policies, it's top down right, so if you create a policy to authenticate Computer and User, you would need two conditions.&amp;nbsp; However, if the device doesn't send the machine credentials only the user, NPS would send a reject.&amp;nbsp; If on the policy you but both on the same condition, user or computer, it will pass, because its looking for one or the other.&amp;nbsp; NPS conditions are simple, one line will do an OR, multiple conditions will be an AND.&lt;/P&gt;&lt;P&gt;Here is and some old thread:&lt;/P&gt;&lt;P&gt;https://supportforums.cisco.com/discussion/11380501/peap-user-machine-authentication&lt;/P&gt;&lt;P&gt;-Scott&lt;/P&gt;</description>
    <pubDate>Mon, 27 Jul 2015 19:21:27 GMT</pubDate>
    <dc:creator>Scott Fella</dc:creator>
    <dc:date>2015-07-27T19:21:27Z</dc:date>
    <item>
      <title>User and Computer Authentication</title>
      <link>https://community.cisco.com/t5/wireless/user-and-computer-authentication/m-p/2673546#M140027</link>
      <description>&lt;P&gt;We are trying to do Active Directory User&amp;nbsp;AND computer authentication when connecting to a specific SSID.&amp;nbsp; Using both the username and computer to authenticate, &amp;nbsp;we are trying to prevent our users from connecting personal devices (laptops and smartphones) to our&amp;nbsp;internal network.&amp;nbsp; We are using Windows 2008&amp;nbsp;NPS&amp;nbsp;to&amp;nbsp;enforce our policy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Active Directory user authentication does work using PEAP.&amp;nbsp; Computer authentication does not work.&amp;nbsp;&amp;nbsp;Can anyone&amp;nbsp;explain how to setup computer authentication and if it is possible to authentication both username and password?&amp;nbsp; How can we prevent&amp;nbsp;users from using&amp;nbsp;their AD credentials and connecting smartphones to internal network?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are running vWLC version 8.1 with 1600 LWAPPs.&amp;nbsp; Our&amp;nbsp;authentication method is PEAP.&amp;nbsp; We setup a internal CA&amp;nbsp;server and published the cert in AD.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the help.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 10:38:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/user-and-computer-authentication/m-p/2673546#M140027</guid>
      <dc:creator>prekojo</dc:creator>
      <dc:date>2021-07-05T10:38:47Z</dc:date>
    </item>
    <item>
      <title>yes it's possible ,  i know</title>
      <link>https://community.cisco.com/t5/wireless/user-and-computer-authentication/m-p/2673547#M140028</link>
      <description>&lt;P&gt;yes it's possible ,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i know that NPS can do weather computer or user for peap username authentication , but not sure for it can do both at same time , but it should do it , it's not big deal ,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i actually tried to look for some docs for configuring it on MS sites but did not find any ,&amp;nbsp;&lt;/P&gt;&lt;P&gt;you can ask same question on MS forums and they should be able to answer you ,,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;but from Cisco side no difference if the NPS is donig computre or machine auth ,&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jul 2015 18:21:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/user-and-computer-authentication/m-p/2673547#M140028</guid>
      <dc:creator>ali aqrabawi</dc:creator>
      <dc:date>2015-07-27T18:21:42Z</dc:date>
    </item>
    <item>
      <title>Hi Joe, Please check the</title>
      <link>https://community.cisco.com/t5/wireless/user-and-computer-authentication/m-p/2673548#M140029</link>
      <description>&lt;P&gt;Hi Joe,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please check the below blogs which may help&amp;nbsp; you on User and computer authentication from windows side as well as Cisco .&lt;/P&gt;&lt;P&gt;https://documentation.meraki.com/MR/Encryption_and_Authentication/Configuring_RADIUS_Authentication_with_WPA2-Enterprise&lt;/P&gt;&lt;P&gt;http://blogs.technet.com/b/networking/archive/2012/05/30/creating-a-secure-802-1x-wireless-infrastructure-using-microsoft-windows.aspx&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jul 2015 18:42:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/user-and-computer-authentication/m-p/2673548#M140029</guid>
      <dc:creator>Prakash Parvathala</dc:creator>
      <dc:date>2015-07-27T18:42:50Z</dc:date>
    </item>
    <item>
      <title>From my testing in the past,</title>
      <link>https://community.cisco.com/t5/wireless/user-and-computer-authentication/m-p/2673549#M140030</link>
      <description>&lt;P&gt;From my testing in the past, you can't do both.&amp;nbsp; If you look at the supplicant, it shows User OR Computer, not an AND.&amp;nbsp; If you sniff the traffic, you will see an initial machine name come through then the user credentials.&amp;nbsp; After that however, you will only see user credentials.&amp;nbsp; ACS, ISE, ClearPass, has workarounds to cache the original machine credentials, but not NPS.&amp;nbsp; Also in the NP policies, it's top down right, so if you create a policy to authenticate Computer and User, you would need two conditions.&amp;nbsp; However, if the device doesn't send the machine credentials only the user, NPS would send a reject.&amp;nbsp; If on the policy you but both on the same condition, user or computer, it will pass, because its looking for one or the other.&amp;nbsp; NPS conditions are simple, one line will do an OR, multiple conditions will be an AND.&lt;/P&gt;&lt;P&gt;Here is and some old thread:&lt;/P&gt;&lt;P&gt;https://supportforums.cisco.com/discussion/11380501/peap-user-machine-authentication&lt;/P&gt;&lt;P&gt;-Scott&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jul 2015 19:21:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/user-and-computer-authentication/m-p/2673549#M140030</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2015-07-27T19:21:27Z</dc:date>
    </item>
  </channel>
</rss>

