<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Windows computers are not authenticating to network in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/windows-computers-are-not-authenticating-to-network/m-p/860823#M20225</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is it possible to have the machine authenticate, but then not check the user authentication?   In our setup we want to base wireless access on computers, not users.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 17 Oct 2007 01:59:03 GMT</pubDate>
    <dc:creator>mhurley131</dc:creator>
    <dc:date>2007-10-17T01:59:03Z</dc:date>
    <item>
      <title>Windows computers are not authenticating to network</title>
      <link>https://community.cisco.com/t5/wireless/windows-computers-are-not-authenticating-to-network/m-p/860819#M20221</link>
      <description>&lt;P&gt;We are using 802.1x/PEAP with IAS 2003 server.  We are having problems with computers not being authenticated to network.  If a user has already has a profile on the computer they are authenticated, however if they log off and the next user does not have a profile they cannot get logged in.  They receive a message "Domain is not available".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After doing some debugs off our 4404 contoller I've come to see that there is an issue between the computer and the IAS server.  Attached is the debug out put.  Any help would be great&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 03 Jul 2021 21:37:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/windows-computers-are-not-authenticating-to-network/m-p/860819#M20221</guid>
      <dc:creator>fynskisb16</dc:creator>
      <dc:date>2021-07-03T21:37:45Z</dc:date>
    </item>
    <item>
      <title>Re: Windows computers are not authenticating to network</title>
      <link>https://community.cisco.com/t5/wireless/windows-computers-are-not-authenticating-to-network/m-p/860820#M20222</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;See if this tracks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; If the computer has "cached credentials" then the user can login with no problems.  However if it is a new user then you receive a " Domain is Not Available" message.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; I am having the very same issue,&amp;amp; believe it to be because we need to be using hardware (or Computer)authentication into Active Directory.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Without using Computer Authentication, the PC doesn't enable the wireless card or connect to the SSID until after the user successfully logs into the PC.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm searching for documents on how to properly Cconfigure this with ACS v3.3, WCS, WLC 4404, and Active Directory Domain Controller.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; I hope this helps, and I'll check back here to see if you found the directions. If I find them, I'll post them here.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; DCM&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 15 Sep 2007 23:44:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/windows-computers-are-not-authenticating-to-network/m-p/860820#M20222</guid>
      <dc:creator>dcmueller</dc:creator>
      <dc:date>2007-09-15T23:44:22Z</dc:date>
    </item>
    <item>
      <title>Re: Windows computers are not authenticating to network</title>
      <link>https://community.cisco.com/t5/wireless/windows-computers-are-not-authenticating-to-network/m-p/860821#M20223</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That is exaclty what I'm seeing.  If a user has a profile on the machine they are able to login fine.  New user, not able to login.  &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 17 Sep 2007 13:21:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/windows-computers-are-not-authenticating-to-network/m-p/860821#M20223</guid>
      <dc:creator>fynskisb16</dc:creator>
      <dc:date>2007-09-17T13:21:04Z</dc:date>
    </item>
    <item>
      <title>Re: Windows computers are not authenticating to network</title>
      <link>https://community.cisco.com/t5/wireless/windows-computers-are-not-authenticating-to-network/m-p/860822#M20224</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Got it!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;?	Login to the computer as Local Administrator&lt;/P&gt;&lt;P&gt;?	Get into the Wireless Connection Configuration through Start, Settings, Network?&lt;/P&gt;&lt;P&gt;?	Under Preferred Networks, Click ADD&lt;/P&gt;&lt;P&gt;?	type in your SSID Name  - Ours is XX-Secure&lt;/P&gt;&lt;P&gt;?	Under Network Authentication, select WPA&lt;/P&gt;&lt;P&gt;?	Under Data Encryption, select TKIP&lt;/P&gt;&lt;P&gt;Click on the Authentication Tab and go to the next step&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;Under the Authentication tab, Select ?Protected EAP (PEAP)? as the EAP type.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Make sure that the Authenticate as computer when computer information is available has a check-mark next to it.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You will receive an error message when you try to login that the Domain is not available if this is not checked  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is what allows the computer to authenticate against the Domain BEFORE the user logs in.  If this is not checked, then un-cached user accounts will not be able to login on the PC.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Click on the Properties button to change the EAP/PEAP Properties&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When you click on the Properties button The Protected EAP (PEAP) properties page opens up.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I did not check the "Validate server certificates" box here&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check mark in enable fast reconnect&lt;/P&gt;&lt;P&gt;select secured Password (EAP-MSCHAPv2)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;click on the Configure button next to Secured password (EAP-MSCHAPv2)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here, make sure there is a check-mark in the box for ?Automatically use my Windows logon name and password (and domain if any).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This allows for the user to automatically authenticate to the Wireless LAN and your Domain by passing the username and password that they logged into the computer with.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the ACS Server, do this&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Click on External User Databased&lt;/P&gt;&lt;P&gt;Click on Database Configuration&lt;/P&gt;&lt;P&gt;Click Windows Database&lt;/P&gt;&lt;P&gt;Click Configure&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;MSCHAP Settings&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Checkbox in Enable Password Changes using MS-CHAP-version 2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Windows EAP Settings&lt;/P&gt;&lt;P&gt;Checkbox for Enable Password changes inside PEAP or EAP-FAST&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Machine Authentication&lt;/P&gt;&lt;P&gt;Checkbox for Enable PEAP Machine Authentication&lt;/P&gt;&lt;P&gt;Checkbox for Enable EAP-TLS and Authentication &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;EAP-TLS and PEAP Machine Authentication name prefix = host/&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Leave the rest as default&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That did it for me.  When the computers are configured as above, and they boot up, you'll see that they register in the Passed Authentications log under Reports and Activities.  The steps should be that the Computer authenticates, then the user.  For logouts, the user logs out, then the computer de-authenticates.  This shows that the computer is pulling AD Computer Policies, then the user based policies for startup/login and logout/shutdown&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;let me know if you're successful&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;DCM&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Sep 2007 15:12:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/windows-computers-are-not-authenticating-to-network/m-p/860822#M20224</guid>
      <dc:creator>dcmueller</dc:creator>
      <dc:date>2007-09-18T15:12:15Z</dc:date>
    </item>
    <item>
      <title>Re: Windows computers are not authenticating to network</title>
      <link>https://community.cisco.com/t5/wireless/windows-computers-are-not-authenticating-to-network/m-p/860823#M20225</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is it possible to have the machine authenticate, but then not check the user authentication?   In our setup we want to base wireless access on computers, not users.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Oct 2007 01:59:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/windows-computers-are-not-authenticating-to-network/m-p/860823#M20225</guid>
      <dc:creator>mhurley131</dc:creator>
      <dc:date>2007-10-17T01:59:03Z</dc:date>
    </item>
    <item>
      <title>Re: Windows computers are not authenticating to network</title>
      <link>https://community.cisco.com/t5/wireless/windows-computers-are-not-authenticating-to-network/m-p/860824#M20226</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Using certificates on the wireless clients, I'm sure this would work.  You would be authenticating the computer against active directory computer objects, the same as I am doing, however you would not need to perform user authentication.  Go through the steps in the links I posted above and see if that doesn't help you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Oct 2007 15:47:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/windows-computers-are-not-authenticating-to-network/m-p/860824#M20226</guid>
      <dc:creator>dcmueller</dc:creator>
      <dc:date>2007-10-17T15:47:29Z</dc:date>
    </item>
    <item>
      <title>Re: Windows computers are not authenticating to network</title>
      <link>https://community.cisco.com/t5/wireless/windows-computers-are-not-authenticating-to-network/m-p/860825#M20227</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I too am having this same problem, however it appears that the suggestion above is written for someone using XP to manage their wireless and not the Cisco client software.  With the Cisco client, I can find nearly all of the options listed above, however I do not see an equivalent to the "Authenticate as computer when computer information is available" option in the Cisco client for the AIR-CB21AG card.  I have followed the instructions otherwise, but obviously this one setting is key.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Nov 2007 17:34:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/windows-computers-are-not-authenticating-to-network/m-p/860825#M20227</guid>
      <dc:creator>neilhall</dc:creator>
      <dc:date>2007-11-12T17:34:12Z</dc:date>
    </item>
  </channel>
</rss>

