cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
508
Views
0
Helpful
6
Replies

ISE and machine authentication

nicanor00
Level 1
Level 1

Hi

I have ISE 1.1  : user authentication is working fine

Now I need to implement machine authentication

But I have 2 requirement

1- User must remove and plug his network cable as he want (without close windows session or restart his computer) and his computer should be authenticated evry time as with user authentication

2- I must not install any software or client applicatin on the computer

Is there any method of machine authentication that respect thise 2 requirements above

Regards

6 Replies 6

Jatin Katyal
Cisco Employee
Cisco Employee

So are you looking for ONLY machine authentication or you want machine to be authenticated first place followed by a user authentication.

~BR
Jatin Katyal

**Do rate helpful posts**

~Jatin

Yes I want machine to be authenticated first place followed by a user authentication

I guess you need to review the below listed thread as we are discussing the same thing. You have to create an authorization rule highlighted in the screen shot.

https://supportforums.cisco.com/message/4044276#4044276

~BR
Jatin Katyal

**Do rate helpful posts**

~Jatin

harvisin
Level 3
Level 3

Hello,

The link below will definetely help you out:-

https://supportforums.cisco.com/docs/DOC-21825

rikkoenig
Level 1
Level 1

Best way would be to run a MS CA, use GPO to push certs to the computers and set up the local supplicant (again via GPO) to use EAP TLS. It's not bad if you're all Win7. If you have some XP machines, a separate policy will be required.

We did this and it ran pretty well, for both wired and wireless.

kaaftab
Level 4
Level 4

Kindly check the following link for MAB configuration and working

http://www.cisco.com/application/pdf/en/us/guest/netsol/ns171/c649/ccmigration_09186a008087ad6f.pdf

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: