<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Peap and Machine authentication in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/peap-and-machine-authentication/m-p/1156151#M19977</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The MAR may be coming in to play because the machine didn't authenticate.  The error you posted, I believe, is from when a USER account was presented for authentication without the machine having been previously authenticated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check the logs - do you see anything about failed auths for MACHINE accounts (or successful machine authentications in the successful auth logs)?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 14 Aug 2009 16:36:14 GMT</pubDate>
    <dc:creator>Robert.N.Barrett_2</dc:creator>
    <dc:date>2009-08-14T16:36:14Z</dc:date>
    <item>
      <title>Peap and Machine authentication</title>
      <link>https://community.cisco.com/t5/wireless/peap-and-machine-authentication/m-p/1156143#M19966</link>
      <description>&lt;P&gt;I am attempting to come up with a secure deployment scenario. I have strong control over image on mobile devices. I am testing utilizing PEAP with ACS. I am currently running legacy 3.3 ACS server but am about to upgrade. The dillemma I have is that I only want to allow machines that are domain members to authenticate. I have configured machine authentication Rules to prevent access for users that have not machine authenticated, however I have test devices, specifically Iphone and Itouch devices that can still consistently authenticate using only user domain credentials. Is there something I am missing in setting up the Machine Access restriction? If there is, is this possibly something that is fixed in 4.X ACS?&lt;/P&gt;</description>
      <pubDate>Sun, 04 Jul 2021 00:28:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-and-machine-authentication/m-p/1156143#M19966</guid>
      <dc:creator>relsethagen</dc:creator>
      <dc:date>2021-07-04T00:28:23Z</dc:date>
    </item>
    <item>
      <title>Re: Peap and Machine authentication</title>
      <link>https://community.cisco.com/t5/wireless/peap-and-machine-authentication/m-p/1156144#M19967</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm curious.  What rules are you referring to?  ACS or the client rules?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Apr 2009 17:37:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-and-machine-authentication/m-p/1156144#M19967</guid>
      <dc:creator>rsumpter</dc:creator>
      <dc:date>2009-04-27T17:37:03Z</dc:date>
    </item>
    <item>
      <title>Re: Peap and Machine authentication</title>
      <link>https://community.cisco.com/t5/wireless/peap-and-machine-authentication/m-p/1156145#M19968</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have this running on ACS 4.2 and the only elements we need to enable on the ACS server are under the "Machine Authentication" section of "External Databases".  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tick "Enable PEAP machine authentication".&lt;/P&gt;&lt;P&gt;Tick "Enable Machine Access Restrictions".&lt;/P&gt;&lt;P&gt;Ensure that "Group map for successful user authentication without machine authentication:" is mapped to "No Access".&lt;/P&gt;&lt;P&gt;Ensure that no groups are exempt from this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If your setup in ACS3.3 is the same but does not function, then all I can say is that it works OK in v4.2!  I cannot comment on whether this is a bug in 3.3&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps,&lt;/P&gt;&lt;P&gt;Russell&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 May 2009 15:26:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-and-machine-authentication/m-p/1156145#M19968</guid>
      <dc:creator>r.bishop</dc:creator>
      <dc:date>2009-05-06T15:26:35Z</dc:date>
    </item>
    <item>
      <title>Re: Peap and Machine authentication</title>
      <link>https://community.cisco.com/t5/wireless/peap-and-machine-authentication/m-p/1156146#M19969</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Russell&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What is the config if any on the windows side to allow machine authentication?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As I am seeing the PEAP user auth pass&lt;/P&gt;&lt;P&gt;but the machine auth fail with the below log&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;host/wks1.lnd.uk  Authen failed    EAP-TLS or PEAP authentication failed during SSL handshake&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Jul 2009 13:50:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-and-machine-authentication/m-p/1156146#M19969</guid>
      <dc:creator>colin.lynch</dc:creator>
      <dc:date>2009-07-21T13:50:45Z</dc:date>
    </item>
    <item>
      <title>Re: Peap and Machine authentication</title>
      <link>https://community.cisco.com/t5/wireless/peap-and-machine-authentication/m-p/1156147#M19971</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What 802.1x supplicant are you using on the Windows side?  If you are using the one built-in to Windows XP (Wireless Zero Config), then you can simply check/tick the "Authenticate as computer when computer information is available" box on the authentication tab.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Jul 2009 12:48:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-and-machine-authentication/m-p/1156147#M19971</guid>
      <dc:creator>Robert.N.Barrett_2</dc:creator>
      <dc:date>2009-07-22T12:48:11Z</dc:date>
    </item>
    <item>
      <title>Re: Peap and Machine authentication</title>
      <link>https://community.cisco.com/t5/wireless/peap-and-machine-authentication/m-p/1156148#M19973</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Russel&lt;/P&gt;&lt;P&gt;What config if any did you have to do on the windows server / AD side?&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Colin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Jul 2009 18:20:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-and-machine-authentication/m-p/1156148#M19973</guid>
      <dc:creator>colin.lynch</dc:creator>
      <dc:date>2009-07-28T18:20:27Z</dc:date>
    </item>
    <item>
      <title>Re: Peap and Machine authentication</title>
      <link>https://community.cisco.com/t5/wireless/peap-and-machine-authentication/m-p/1156149#M19975</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Robert&lt;/P&gt;&lt;P&gt;I am using the windows XP SP2 Supplicant&lt;/P&gt;&lt;P&gt;auth as machine is ticked and ACS sends machine auth to AD and fails.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PEAP user auth works fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Colin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Jul 2009 18:29:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-and-machine-authentication/m-p/1156149#M19975</guid>
      <dc:creator>colin.lynch</dc:creator>
      <dc:date>2009-07-28T18:29:04Z</dc:date>
    </item>
    <item>
      <title>Re: Peap and Machine authentication</title>
      <link>https://community.cisco.com/t5/wireless/peap-and-machine-authentication/m-p/1156150#M19976</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am running into the same issue.  I desire to lock out devices that are not part of the AD.  We are using ACS4.2 appliances (which use the remote agents) and I beleive machine authentication works because it was enabled to allow logon scripts to run etc.&lt;/P&gt;&lt;P&gt;However - if I check the box to Enable Machine Access Restrictions and set it to No Access - no users can authenticate.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As mentioned earlier, the Itouch's and Iphones are prompted to continue without a certificate, and are able to get on by only providing the AD username and password.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is the failed attempt log when MAR is enabled:&lt;/P&gt;&lt;P&gt;Windows External DB user access was denied due to a Machine Access Restriction&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Aug 2009 13:06:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-and-machine-authentication/m-p/1156150#M19976</guid>
      <dc:creator>brian.kachel</dc:creator>
      <dc:date>2009-08-06T13:06:56Z</dc:date>
    </item>
    <item>
      <title>Re: Peap and Machine authentication</title>
      <link>https://community.cisco.com/t5/wireless/peap-and-machine-authentication/m-p/1156151#M19977</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The MAR may be coming in to play because the machine didn't authenticate.  The error you posted, I believe, is from when a USER account was presented for authentication without the machine having been previously authenticated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check the logs - do you see anything about failed auths for MACHINE accounts (or successful machine authentications in the successful auth logs)?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Aug 2009 16:36:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-and-machine-authentication/m-p/1156151#M19977</guid>
      <dc:creator>Robert.N.Barrett_2</dc:creator>
      <dc:date>2009-08-14T16:36:14Z</dc:date>
    </item>
    <item>
      <title>Re: Peap and Machine authentication</title>
      <link>https://community.cisco.com/t5/wireless/peap-and-machine-authentication/m-p/1156152#M19978</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am running into the same issue. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can authenticate as a machine and use eap-tls for machine authentication. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I cannot however get a windows computer to combine active directory authentication with machine authentication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I want a supplicant to send BOTH machine auth via eap-tls to satisfy the "MAR" then send the active directory username and password info to satisfy the peap.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;**ps: I CAN get a user cert and active directory combined to authenticate but this is not as secure as checking the machine certificate.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have tried and tried and can only do one or the other and not both. Anyone have input on how to do this? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Oct 2010 20:58:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-and-machine-authentication/m-p/1156152#M19978</guid>
      <dc:creator>iceteanolemon</dc:creator>
      <dc:date>2010-10-07T20:58:05Z</dc:date>
    </item>
  </channel>
</rss>

