<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic peap authententication in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/peap-authententication/m-p/1702102#M75771</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Thanks for your reply..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;so if i enable peap machine authentication, are you saying no non domain laptops can access the network even if it has the certificates? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;in short, i would like to know what is peap authentication and will it work on non domain laptops with or without certifcates ? and what is MAR and how does it work&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sorry just being confused with this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 21 Jun 2011 09:41:58 GMT</pubDate>
    <dc:creator>Network Pro</dc:creator>
    <dc:date>2011-06-21T09:41:58Z</dc:date>
    <item>
      <title>peap authententication</title>
      <link>https://community.cisco.com/t5/wireless/peap-authententication/m-p/1702096#M75765</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;what does Enable PEAP machine authentication mean on the ACS server ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we are having a training center where we use certificates for any laptop (domain laptops) to join our wireless network. just wondering&amp;nbsp; is there any possiblitly for any laptop (not on domain) to join without having the certificates ? say for example any android or iphone, is it possible to join the wireless network without having hte certificates ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Sun, 04 Jul 2021 03:18:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-authententication/m-p/1702096#M75765</guid>
      <dc:creator>Network Pro</dc:creator>
      <dc:date>2021-07-04T03:18:18Z</dc:date>
    </item>
    <item>
      <title>peap authententication</title>
      <link>https://community.cisco.com/t5/wireless/peap-authententication/m-p/1702097#M75766</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; any thoughts on the above ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Jun 2011 09:03:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-authententication/m-p/1702097#M75766</guid>
      <dc:creator>Network Pro</dc:creator>
      <dc:date>2011-06-13T09:03:50Z</dc:date>
    </item>
    <item>
      <title>peap authententication</title>
      <link>https://community.cisco.com/t5/wireless/peap-authententication/m-p/1702098#M75767</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Sorry, I can't speak for ACS as that's outside my knowledge base...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but certificates are optional on PEAP.... so my answer would be "yes", a PEAP client without a certificate would be able to authenticate to the network...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Perhaps that is what the ACS option is for - to force using a certificate.. again, just a guess on my part &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Jun 2011 20:09:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-authententication/m-p/1702098#M75767</guid>
      <dc:creator>Dennis Kline</dc:creator>
      <dc:date>2011-06-13T20:09:07Z</dc:date>
    </item>
    <item>
      <title>peap authententication</title>
      <link>https://community.cisco.com/t5/wireless/peap-authententication/m-p/1702099#M75768</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;One way round this is to enable Machiine Access Restrictions. This will prevent any device that does not have a Windows Domain machine account (non-domain laptops, iPhones, iPads, etc) from authenticating even if it has a valid certificate and user credentials. You can enable this under the External Databases, Windows User Database Configuration. It's a tick box in the Windows EAP Settings section.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Jun 2011 14:36:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-authententication/m-p/1702099#M75768</guid>
      <dc:creator>andrew.brazier</dc:creator>
      <dc:date>2011-06-14T14:36:02Z</dc:date>
    </item>
    <item>
      <title>peap authententication</title>
      <link>https://community.cisco.com/t5/wireless/peap-authententication/m-p/1702100#M75769</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Thanks for the replies...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;so could you please let me know how can i use a non domain device to join the wireless network without a certificate?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;@andrew.brazier - i was told this option for not allowing iphones or ipads to join the network by using Machine Access Restictions - can you please let me know more about this feature and how it works&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;so in theory i would like to know how to join a non domain laptop to a wireless netowrk without certificates and how to prevent this as well (using MAR)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Jun 2011 15:53:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-authententication/m-p/1702100#M75769</guid>
      <dc:creator>Network Pro</dc:creator>
      <dc:date>2011-06-14T15:53:49Z</dc:date>
    </item>
    <item>
      <title>peap authententication</title>
      <link>https://community.cisco.com/t5/wireless/peap-authententication/m-p/1702101#M75770</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;" &lt;STRONG&gt;Peap machine authentication&lt;/STRONG&gt; " - it means that ACS will authenticate those machine [host machines], which are a part of domain. The Iphone or Ipads cannot be a part of domain, therefore, they do not fall under machine-authentication. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If peap machine authentication is enabled on ACS server, then no non-domain laptop can access network. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For better security of wireless network, both machine and certificate authentication is enabled on ACS server. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if it helps. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;Devashree&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Jun 2011 06:58:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-authententication/m-p/1702101#M75770</guid>
      <dc:creator>Devashree Chakrabarti</dc:creator>
      <dc:date>2011-06-21T06:58:26Z</dc:date>
    </item>
    <item>
      <title>peap authententication</title>
      <link>https://community.cisco.com/t5/wireless/peap-authententication/m-p/1702102#M75771</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Thanks for your reply..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;so if i enable peap machine authentication, are you saying no non domain laptops can access the network even if it has the certificates? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;in short, i would like to know what is peap authentication and will it work on non domain laptops with or without certifcates ? and what is MAR and how does it work&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sorry just being confused with this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Jun 2011 09:41:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-authententication/m-p/1702102#M75771</guid>
      <dc:creator>Network Pro</dc:creator>
      <dc:date>2011-06-21T09:41:58Z</dc:date>
    </item>
    <item>
      <title>peap authententication</title>
      <link>https://community.cisco.com/t5/wireless/peap-authententication/m-p/1702103#M75772</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you enable PEAP authentication non-domain PCs can authenticate to the network provided they have the correct root cert installed (if you buy a cert from most providers this shouldn't be a problem).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Enabling MAR will prevent PCs that are not domain members from authenticating to the network, period.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Jun 2011 12:54:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-authententication/m-p/1702103#M75772</guid>
      <dc:creator>andrew.brazier</dc:creator>
      <dc:date>2011-06-21T12:54:47Z</dc:date>
    </item>
    <item>
      <title>peap authententication</title>
      <link>https://community.cisco.com/t5/wireless/peap-authententication/m-p/1702104#M75773</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; thanks for the explanation...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you please also expain how to implement MARS. i know there is an option on the ACS to check this. do you have to do anything other than this ? and what meant by aging time that is specified with MAR..&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Jun 2011 13:17:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-authententication/m-p/1702104#M75773</guid>
      <dc:creator>Network Pro</dc:creator>
      <dc:date>2011-06-21T13:17:36Z</dc:date>
    </item>
    <item>
      <title>peap authententication</title>
      <link>https://community.cisco.com/t5/wireless/peap-authententication/m-p/1702105#M75774</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;External User Database, Database Configuration, Windows Database, Configure. Scroll down to Windows EAP settings and check the "Enable machine access restrictions".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It looks like I was slightly incorrect when I said a machine that is blocked by MAR has no access, if the user credentials are valid but the machine would be blocked by MAR then access can be granted by using the Group Map.... drop down to select an ACS group. The access the user then gets is controlled by the access permissions of that group so you should be able to make it pretty granular ad have it so an authenticated user on an authenticated machine = full access, authenticated user on an MAR-blocked machine = limited access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is also possible to create machine accounts in Windows AD for machines that don't normally have one such as Apple MACs, this then allows them to pass the MAR check.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From the ACS help system:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;Aging time (hours)&lt;/STRONG&gt;—The number of hours that Cisco Secure ACS&amp;nbsp; caches a successful machine authentication. For as long as successful&amp;nbsp; machine authentication is retained in the cache, the machine access&amp;nbsp; restrictions feature can use it to determine whether to limit a user to&amp;nbsp; the group specified in the group mapping list, below. &lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Group map for successful user authentication without machine authentication&lt;/STRONG&gt;—When&amp;nbsp; the machine access restrictions feature is enabled, this list specifies&amp;nbsp; the user group whose authorizations are applied to an EAP-TLS or&amp;nbsp; Microsoft PEAP user who passes authentication but uses a computer that&amp;nbsp; failed machine authentication. &lt;/LI&gt;&lt;/UL&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Jun 2011 14:00:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-authententication/m-p/1702105#M75774</guid>
      <dc:creator>andrew.brazier</dc:creator>
      <dc:date>2011-06-21T14:00:22Z</dc:date>
    </item>
    <item>
      <title>peap authententication</title>
      <link>https://community.cisco.com/t5/wireless/peap-authententication/m-p/1702106#M75775</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; thanks for the reply &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" height="16" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif" width="16"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Jun 2011 14:13:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/peap-authententication/m-p/1702106#M75775</guid>
      <dc:creator>Network Pro</dc:creator>
      <dc:date>2011-06-21T14:13:49Z</dc:date>
    </item>
  </channel>
</rss>

