09-02-2025
11:46 PM
- last edited on
09-03-2025
02:04 AM
by
shaiksh
Hello, we have ISE as AAA server and is configured to authenticate network users using user certificates issued by our local CA server. Successfully authenticated users, which are AD users are placed on Corps VLAN otherwise guest vlan. I have an issue lately, the certificates for some of the users expired and now are on the guest vlan. The problem is I cannot renew the certificates directly from the client as they cannot reach the CA, due to being on the guest. I get the error that it cannot reach the server. How do I go about such an issue. How do I renew the certificates for other users. Thank you
09-03-2025 12:20 AM
either you need to manually update the certs or make arrangement to push using GPO to end clients (so next time you will not have this issue)
is the ISE acting as CA Server or you have PKI infrastructure ?
=====️ Preenayamo Vasudevam ️=====
***** Rate All Helpful Responses *****
09-03-2025 04:37 AM
We have a dedicated PKI server which is Windows and is integrated to AD
09-05-2025 12:10 AM
then you should able to push GPO and also client side try GP update.
=====️ Preenayamo Vasudevam ️=====
***** Rate All Helpful Responses *****
09-03-2025 12:25 AM
Under these user port config
Access switchport mode vlan x
Disable 802.1x under port
After user re-new cert
Remove vlan and enable 802.1x again
MHM
09-03-2025 04:45 AM
The environment is SDN based therefore I can see dot1x auth failures from the specific switch and also ports users are connected
09-03-2025 12:34 AM
@Dkiptoo temporarily to resolve this issue, allow expired certificates to allow the devices network access:-
Navigate to Policy > Policy Elements > Results > Authentication > Allowed Protocols > Default Network Access (custom name) and checking the box for “Allow Authentication of expired certificates to allow certificate renewal in Authorization Policy”.
Then amend you GPOs to automatically renew certificates before the expire.
Once certificates have been renewed, then disable the expired certificates.
09-03-2025 12:49 AM
This good idea
But then he never know what user have expired cert (authc failed) and user dont have expired cert
Let ISE failed authc to make him know that.
MHM
09-03-2025 12:56 AM
You can determine what devices do have expired certifciates, create a new authorisation rule matching on CERTIFICATE Is Expired True. You can allow those devices just enough access to renew certificates. You will be able to run reports on what devices match this rule. All done centrally via ISE.
09-03-2025 12:57 AM
That more better'
MHM
09-03-2025 05:21 AM
Thank you Rob, let me try this option. GPO to renew and auto enroll is already in place though
09-04-2025 11:47 AM
Hi @Rob Ingram, tried following your workaround,however interestingly, I woke today with all devices on the network not able to authenticate and even reach DHCP server to get access to Internet. Unfortunately, Advantage Licence expired 19 days ago and we're in the process of renewing. I fixed it temporarily by enabling the Essential Licence after realising that it was disabled. But again despite all devices getting Internet, they are all placed on the guest. From the ISE license tiers, the Essential tier should provide basic AAA including dot1x authentication. Am trying to understand what could be the issue that all devices are on the guest, even domain joined Workstations with valid certificates and users. I would really appreciate for your input
09-04-2025 11:55 AM
@Dkiptoo What features are configured in your authorisation rules? What rules are being matched or is authentication/authorising failing? Provide a screenshot of the live log of an example.
09-05-2025 04:14 AM
Hi Rob,
I was able to trace the issue to AD synchronization issue and therefore could not authenticate users, defaulting them to guest. Authentication & Authorization policies are fine. I would however l like however to get to know how do I apply the policy that will renew the certificated as earlier stated. Seems the policy in place didn't renew the user cert after making changes here "Policy > Policy Elements > Results > Authentication > Allowed Protocols > Default Network Access (custom name) and checking the box for “Allow Authentication of expired certificates to allow certificate renewal in Authorization Policy”."
09-05-2025 12:52 PM
@Dkiptoo well first you need to make the changes on ISE to allow expired certificates, that will allow the computers on to the network. Once they have network connectivity if the GPO configuration for certificate enrollment is working, then the computers should renew their certificates.
It's the windows GPO settings that will renew the certifictaes, example:- https://lostintransit.se/2024/11/07/leveraging-gpo-to-distribute-user-and-computer-certificate/
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide