<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Disconnecting from LAN and connect to Wi-Fi caused AD lockouts in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/disconnecting-from-lan-and-connect-to-wi-fi-caused-ad-lockouts/m-p/5467724#M291563</link>
    <description>&lt;P&gt;I am almost sure that is a Windows Server issue.&lt;/P&gt;&lt;P&gt;&lt;A href="https://support.microsoft.com/en-us/topic/the-nps-server-locks-a-user-account-after-four-tries-on-a-windows-server-2008-r2-based-computer-that-performs-authentication-for-radius-clients-4c5c5b82-ce96-0233-be7a-20985795aa84" target="_blank" rel="nofollow noopener noreferrer"&gt;https://support.microsoft.com/en-us/topic/the-nps-server-locks-a-user-account-after-four-tries-on-a-windows-server-2008-r2-based-computer-that-performs-authentication-for-radius-clients-4c5c5b82-ce96-0233-be7a-20985795aa84&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 10 Nov 2023 12:21:10 GMT</pubDate>
    <dc:creator>aleabrahao</dc:creator>
    <dc:date>2023-11-10T12:21:10Z</dc:date>
    <item>
      <title>Disconnecting from LAN and connect to Wi-Fi caused AD lockouts</title>
      <link>https://community.cisco.com/t5/wireless/disconnecting-from-lan-and-connect-to-wi-fi-caused-ad-lockouts/m-p/5467723#M291562</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;We are in the middle of a deployment of Cisco Meraki APs. We are migrating from Cisco WLC with radius authentication via ISE for Corporate LAN access via an SSID.&lt;/P&gt;&lt;P&gt;We are experiencing an issue where some users (not all) disconnect from the LAN to go to a meeting a connect to Wi-Fi. They should automatically connect the corporate LAN via an SSID. This would for about 80% of users. For about 20% of users they cannot connect to the LAN via an SSID as this locks out their AD account.&lt;/P&gt;&lt;P&gt;We have configured NAC on the AP port and it authenticates successfully on the network via ISE (3.1 Patch 3). The AP is also configured as a NAD on ISE. The users have an EAP-TLS for Wired Dot1x and PEAP for Wireless Dot1x. Retries for "&lt;EM&gt;Allow PEAP&lt;/EM&gt;" and "&lt;EM&gt;Allow TEAP&lt;/EM&gt;" for "&lt;EM&gt;Allow Password Change Retries&lt;/EM&gt;" is "&lt;EM&gt;3&lt;/EM&gt;".&lt;/P&gt;&lt;P&gt;Any ideas on what could solve these AD Lockout issues? &lt;SPAN class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PEAP" style="width: 544px;"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="image.jpeg"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/272782i98ADB3FBF22CCBE9/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.jpeg" alt="image.jpeg" /&gt;&lt;/span&gt;&lt;SPAN class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;PEAP&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="EAP-TLS" style="width: 604px;"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="image.jpeg"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/272774i8B723A9D7EE75F74/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.jpeg" alt="image.jpeg" /&gt;&lt;/span&gt;&lt;SPAN class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;EAP-TLS&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Nov 2023 09:37:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/disconnecting-from-lan-and-connect-to-wi-fi-caused-ad-lockouts/m-p/5467723#M291562</guid>
      <dc:creator>Anthony O'Reilly</dc:creator>
      <dc:date>2023-11-10T09:37:16Z</dc:date>
    </item>
    <item>
      <title>Re: Disconnecting from LAN and connect to Wi-Fi caused AD lockouts</title>
      <link>https://community.cisco.com/t5/wireless/disconnecting-from-lan-and-connect-to-wi-fi-caused-ad-lockouts/m-p/5467724#M291563</link>
      <description>&lt;P&gt;I am almost sure that is a Windows Server issue.&lt;/P&gt;&lt;P&gt;&lt;A href="https://support.microsoft.com/en-us/topic/the-nps-server-locks-a-user-account-after-four-tries-on-a-windows-server-2008-r2-based-computer-that-performs-authentication-for-radius-clients-4c5c5b82-ce96-0233-be7a-20985795aa84" target="_blank" rel="nofollow noopener noreferrer"&gt;https://support.microsoft.com/en-us/topic/the-nps-server-locks-a-user-account-after-four-tries-on-a-windows-server-2008-r2-based-computer-that-performs-authentication-for-radius-clients-4c5c5b82-ce96-0233-be7a-20985795aa84&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Nov 2023 12:21:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/disconnecting-from-lan-and-connect-to-wi-fi-caused-ad-lockouts/m-p/5467724#M291563</guid>
      <dc:creator>aleabrahao</dc:creator>
      <dc:date>2023-11-10T12:21:10Z</dc:date>
    </item>
  </channel>
</rss>

