08-08-2014 04:09 AM - edited 03-10-2019 09:55 PM
Hi Guys,
Whilst I’m well aware of the limitations of the built in the windows Wireless 802.1x supplicant. Is there a way, using the NAM client to authenticate both a computer and a user simultaneously, when used for authentication to wireless networks?
As has been posted many times before on this forum, this isn’t possible due to windows not authenticating with the 'computer account' whilst the user is logged in, but with the NAM client it seems possible to do both user and computer authentication based on the options it gives you with EAP-Fast and 'EAP Chaining'.
Can anyone validate this is possible? I have the design guide for exactly this for Cisco ISE but i need it to work on ACS (5.x).
Thanks in advance.
SteveH
Solved! Go to Solution.
01-14-2016 01:39 PM
EAP Chaining with AnyConnect 3+ NAM is unique to ISE.
No plan to add it in ACS so ACS customers not moving to ISE would use MAR, instead; that is, use computer auth while the user not logged-in and use user auth after the user logged-in.
01-14-2016 01:39 PM
EAP Chaining with AnyConnect 3+ NAM is unique to ISE.
No plan to add it in ACS so ACS customers not moving to ISE would use MAR, instead; that is, use computer auth while the user not logged-in and use user auth after the user logged-in.
01-14-2016 01:46 PM
Thanks hslai,
You are correct, ISE only unfortunately.
SteveH
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide