05-29-2023 02:21 AM
Hello Dears
We are planning to impelment Cisco ISE with 802.1x and we have the following quiestions :
1-is it possible to connect ISE with Microsoft AD so the login user for 802.1x is done with AD username/password?
2-is 802.1x is working without issue with windows 10 and windows 11?
Best Regards
05-29-2023 02:30 AM
Hi
1 - it is. You can check this guide
2 - without issue is too optmistic but Yes, they work. Just check the compatibilty with ISE version
05-29-2023 05:20 AM
AD integration is not only possible, as @Flavio Miranda noted, but is used in almost all ISE deployments when we are securing wired or wireless networks.
It works fine with all current Windows versions.
It is worth mentioning that recently Microsoft has begun to deprecate MS-CHAPv2 so we need to account for that in our ISE deployment. https://community.cisco.com/t5/network-access-control/windows-11-22h2-credential-guard-enforcement/td-p/4695655
05-30-2023 12:24 AM
Hello Dears and thnx for reply
could we authenticate 802.1x without ISE certification
i am need the user just checking by username/password not using any authenication method anyone can help ?
05-30-2023 01:42 AM
Checking username and password IS authentication.
We can configure Windows to work with 802.1x so that the supplicant (Windows built-in software program settings that work with wired or wireless networks) automatically provides ISE the username and password. No user certificate is required. ISE uses a certificate but it doesn't not have to be CA-issued not does the client necessarily have to validate/trust it. Those are optional supplicant settings.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide