<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PEAP User + Machine Authentication in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/peap-user-machine-authentication/m-p/1837965#M19596</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Correct... That's the issue when you have two rules instead on just having one. If you remove the rule for machine and change the rule for user and take out was machine authenticated, then that's how you authenticate user only.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scott Fella&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from my iPhone&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 18 Jan 2012 13:44:06 GMT</pubDate>
    <dc:creator>Scott Fella</dc:creator>
    <dc:date>2012-01-18T13:44:06Z</dc:date>
    <item>
      <title>PEAP User + Machine Authentication</title>
      <link>https://community.cisco.com/t5/wireless/peap-user-machine-authentication/m-p/1837917#M19548</link>
      <description>&lt;P&gt;Hi ;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; I tried PEAP machine and user authentication together with acs 5.3.&amp;nbsp; But if we are selecting only computer authentication in the client side , we are able to connect without even prompting for the username and password.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there any way to enforce both authentications.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards&lt;/P&gt;&lt;P&gt;Sreejith R&lt;/P&gt;</description>
      <pubDate>Sun, 04 Jul 2021 04:19:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-user-machine-authentication/m-p/1837917#M19548</guid>
      <dc:creator>sreejith_r</dc:creator>
      <dc:date>2021-07-04T04:19:19Z</dc:date>
    </item>
    <item>
      <title>PEAP User + Machine Authentication</title>
      <link>https://community.cisco.com/t5/wireless/peap-user-machine-authentication/m-p/1837918#M19549</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are you using windows 7... if so, you can, but I know that windows xp only can do user.&amp;nbsp; Also this depends on how you setup your policy in ACS 5.3.&amp;nbsp; Post some screen shots so we can take a look.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Jan 2012 14:22:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-user-machine-authentication/m-p/1837918#M19549</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2012-01-03T14:22:39Z</dc:date>
    </item>
    <item>
      <title>Re: PEAP User + Machine Authentication</title>
      <link>https://community.cisco.com/t5/wireless/peap-user-machine-authentication/m-p/1837919#M19550</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you also post screen shots of the failed attempts using the username also. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Jan 2012 14:26:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-user-machine-authentication/m-p/1837919#M19550</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2012-01-03T14:26:04Z</dc:date>
    </item>
    <item>
      <title>PEAP User + Machine Authentication</title>
      <link>https://community.cisco.com/t5/wireless/peap-user-machine-authentication/m-p/1837920#M19551</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; I am trying with windows 7. There are three options&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. User or Compuer Authentication: Its working as expected. I can see the both successful authentication in the Logs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. User Authentication : Its working as expected. Because of the was machine authenticated attribute the authentications fails.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3. Computer Authentication: Once the computer passed the authentication the client successfully connecting to wireless without the username and password.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i did the following steps&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Enable machine authentication&lt;/P&gt;&lt;P&gt;2. Enabled MAR with 1 hour&lt;/P&gt;&lt;P&gt;3. Added the computer and user grups in the ACS&lt;/P&gt;&lt;P&gt;4. Added the protocol, External groups &amp;amp; Was machine authenticated in the authorization list.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please let me know if any changes has to be done or is this the way the machine authentication works.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards&lt;/P&gt;&lt;P&gt;Sreejith R&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Jan 2012 14:29:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-user-machine-authentication/m-p/1837920#M19551</guid>
      <dc:creator>sreejith_r</dc:creator>
      <dc:date>2012-01-03T14:29:44Z</dc:date>
    </item>
    <item>
      <title>PEAP User + Machine Authentication</title>
      <link>https://community.cisco.com/t5/wireless/peap-user-machine-authentication/m-p/1837921#M19552</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;On the client side you need to choose:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. User or Compuer Authentication&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now can you post a screen shot of your failed attemps in ACS.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Jan 2012 14:33:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-user-machine-authentication/m-p/1837921#M19552</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2012-01-03T14:33:43Z</dc:date>
    </item>
    <item>
      <title>PEAP User + Machine Authentication</title>
      <link>https://community.cisco.com/t5/wireless/peap-user-machine-authentication/m-p/1837922#M19553</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is a customer requirement. We cannot force the client to use only user or computer authentication.&amp;nbsp; The client may try with usre authentication, Computer autnetication &amp;amp; User or compuer authentication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We need to configure ACS in such a way that only the user or computer authentication will work out.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sorry, i dont have the screenshots with me.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Jan 2012 14:36:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-user-machine-authentication/m-p/1837922#M19553</guid>
      <dc:creator>sreejith_r</dc:creator>
      <dc:date>2012-01-03T14:36:50Z</dc:date>
    </item>
    <item>
      <title>PEAP User + Machine Authentication</title>
      <link>https://community.cisco.com/t5/wireless/peap-user-machine-authentication/m-p/1837923#M19554</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I know it works, because I have done that in the past. It must be hwo the policy is configured on ACS.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Jan 2012 14:38:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-user-machine-authentication/m-p/1837923#M19554</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2012-01-03T14:38:42Z</dc:date>
    </item>
    <item>
      <title>PEAP User + Machine Authentication</title>
      <link>https://community.cisco.com/t5/wireless/peap-user-machine-authentication/m-p/1837924#M19555</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;i didnt see any option in the policy. Could you please share the information on how we need to configure the policy to enforce both the authentications.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Jan 2012 14:41:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-user-machine-authentication/m-p/1837924#M19555</guid>
      <dc:creator>sreejith_r</dc:creator>
      <dc:date>2012-01-03T14:41:24Z</dc:date>
    </item>
    <item>
      <title>PEAP User + Machine Authentication</title>
      <link>https://community.cisco.com/t5/wireless/peap-user-machine-authentication/m-p/1837925#M19556</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I will try to dig something up, but being able to see the failed logs helps since there are various ways to setup policies.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Jan 2012 14:43:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-user-machine-authentication/m-p/1837925#M19556</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2012-01-03T14:43:10Z</dc:date>
    </item>
    <item>
      <title>PEAP User + Machine Authentication</title>
      <link>https://community.cisco.com/t5/wireless/peap-user-machine-authentication/m-p/1837926#M19557</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I will also try to get the logs by tomorrow. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But if you are selecting the computer authentication in the client side you will not see any failed logs in the ACS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you are selecting the user authentication in the client side, in the failed logs you will see that the machine was not authenticated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you are selecting the user or computer authentication in the client side, then also you will not see any failed logs.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Jan 2012 14:49:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-user-machine-authentication/m-p/1837926#M19557</guid>
      <dc:creator>sreejith_r</dc:creator>
      <dc:date>2012-01-03T14:49:36Z</dc:date>
    </item>
    <item>
      <title>PEAP User + Machine Authentication</title>
      <link>https://community.cisco.com/t5/wireless/peap-user-machine-authentication/m-p/1837927#M19558</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;But if you are selecting the computer authentication in the client side you will not see any failed logs in the ACS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;That is because the policy configured in ACS right now is only working for machine authentication&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you are selecting the user authentication in the client side, in the failed logs you will see that the machine was not authenticated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;This is because the user authentication part is failing or not configured correctly.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you are selecting the user or computer authentication in the client side, then also you will not see any failed logs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;This is because of the "OR" on the client side.&amp;nbsp; You specify to send both user and machine, but your policy is only looking for machine not user.&lt;/STRONG&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Jan 2012 14:55:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-user-machine-authentication/m-p/1837927#M19558</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2012-01-03T14:55:08Z</dc:date>
    </item>
    <item>
      <title>PEAP User + Machine Authentication</title>
      <link>https://community.cisco.com/t5/wireless/peap-user-machine-authentication/m-p/1837928#M19559</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No the user authentication is failing beacuse of the was machine authenticated attribute in the policy. If the client is selecting only the user authentication acs will block the access beacuse of the was machine authenticated attribute. If are removing that attribute it will work for user authentication as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If we are selecting user or computer authentication , both authentication works. We can see the logs in the acs that both user and machine authentication passed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What is happening is that&amp;nbsp; since machine authentication happens prior to the user authentication, once the machineauthentication passed acs grants access to the clients without checking any other rules. How we can override this.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Jan 2012 15:06:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-user-machine-authentication/m-p/1837928#M19559</guid>
      <dc:creator>sreejith_r</dc:creator>
      <dc:date>2012-01-03T15:06:59Z</dc:date>
    </item>
    <item>
      <title>Re: PEAP User + Machine Authentication</title>
      <link>https://community.cisco.com/t5/wireless/peap-user-machine-authentication/m-p/1837929#M19560</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Have you tried using AD1:ExternalGroups: "contains all" in your authorization policy and listed specfic AD group and included the computer group.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Jan 2012 15:13:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-user-machine-authentication/m-p/1837929#M19560</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2012-01-03T15:13:55Z</dc:date>
    </item>
    <item>
      <title>Re: PEAP User + Machine Authentication</title>
      <link>https://community.cisco.com/t5/wireless/peap-user-machine-authentication/m-p/1837930#M19561</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Okay.... I decided to lab this up and here is how to set this up.&amp;nbsp; After you have set this up, make sure you reboot the client device (Windows 7) so that ACS knows that this device has authenticated using machine authentication.&amp;nbsp; These policies are customizable, so here is the basic that you have to do.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also note, when you first connect, you will see the machine and user being authenticated, then if you disconnect and reconnect, you will only see the username come through, because it is cached due to the Aging Time you will set in ACS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Attached is a PDF so hopefully this helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Jan 2012 03:23:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-user-machine-authentication/m-p/1837930#M19561</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2012-01-04T03:23:56Z</dc:date>
    </item>
    <item>
      <title>PEAP User + Machine Authentication</title>
      <link>https://community.cisco.com/t5/wireless/peap-user-machine-authentication/m-p/1837931#M19562</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Let me know if the doc doesn't help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Jan 2012 22:46:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-user-machine-authentication/m-p/1837931#M19562</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2012-01-04T22:46:09Z</dc:date>
    </item>
    <item>
      <title>PEAP User + Machine Authentication</title>
      <link>https://community.cisco.com/t5/wireless/peap-user-machine-authentication/m-p/1837932#M19563</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; i will try with this document by today and will let you know about the status.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jan 2012 08:49:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-user-machine-authentication/m-p/1837932#M19563</guid>
      <dc:creator>sreejith_r</dc:creator>
      <dc:date>2012-01-05T08:49:12Z</dc:date>
    </item>
    <item>
      <title>Re: PEAP User + Machine Authentication</title>
      <link>https://community.cisco.com/t5/wireless/peap-user-machine-authentication/m-p/1837933#M19564</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sounds good.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scott Fella&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from my iPhone&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jan 2012 13:02:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-user-machine-authentication/m-p/1837933#M19564</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2012-01-05T13:02:37Z</dc:date>
    </item>
    <item>
      <title>Re: PEAP User + Machine Authentication</title>
      <link>https://community.cisco.com/t5/wireless/peap-user-machine-authentication/m-p/1837934#M19565</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Were you able to try it?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Jan 2012 12:01:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-user-machine-authentication/m-p/1837934#M19565</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2012-01-06T12:01:21Z</dc:date>
    </item>
    <item>
      <title>Re: PEAP User + Machine Authentication</title>
      <link>https://community.cisco.com/t5/wireless/peap-user-machine-authentication/m-p/1837935#M19566</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Any update if this worked for you?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Jan 2012 12:50:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-user-machine-authentication/m-p/1837935#M19566</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2012-01-11T12:50:21Z</dc:date>
    </item>
    <item>
      <title>Re: PEAP User + Machine Authentication</title>
      <link>https://community.cisco.com/t5/wireless/peap-user-machine-authentication/m-p/1837936#M19567</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Didn't get any update from the customer. Will update you once i get the feedback from the customer.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Jan 2012 13:36:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-user-machine-authentication/m-p/1837936#M19567</guid>
      <dc:creator>sreejith_r</dc:creator>
      <dc:date>2012-01-11T13:36:26Z</dc:date>
    </item>
  </channel>
</rss>

