05-21-2018 01:50 PM
We just upgraded to ISE 2.4 from 2.3. A client computer is authenticating with computer credentials. It shows up as USERNAME/USERNAME. The authentication fails.
I thought I would share this to see if anyone is having the same issue. I also have a TAC case open so I can provide an update from there as well.
Thanks,
Alex
Solved! Go to Solution.
05-21-2018 04:38 PM
ISE 2.4 is masking out invalid usernames. To see them, please use the option [ ] Disclose invalid usernames.
05-21-2018 04:38 PM
ISE 2.4 is masking out invalid usernames. To see them, please use the option [ ] Disclose invalid usernames.
05-22-2018 09:47 AM
Is this something that is usually corrected with Identity Rewrite, driver issue, etc.?
05-22-2018 09:55 AM
I believe the reason we are suppressing such user names is that the end users accidentally put their passwords as the usernames some times.
CSCvh91118 is an enhancement filed during ISE 2.4 beta to make the option more flexible. I just added the release notes enclosure so it would take a couple of days of Cisco internal review before becoming external visible.
05-22-2018 09:57 AM
In this case, it would be a host. Can you comment on host authentications?
05-22-2018 10:05 AM
Please use the option to disclose the real host subject for 30 minutes and then update ISE configurations accordingly.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide