MAB Authentication with ISE using Certificates username issues
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-28-2015 07:52 PM - edited 03-10-2019 10:45 PM
Hi,
I have a switched configured for MAB authentication with Cisco ISE. ISE is configured with AD to authenticate the users and we are using device certificate for authentication.
When machine send details for authentication, many time it will send username - MAC address or host/<machine name in certificate> / <machine name>
When clients sends <machine name> as username, ISE can detect it from AD and authenticate successfully, but when it sends MAC address or host/machine name then ISE cannot.
So my question is why does client machine send MAC or host/machine name to ISE?
I have configured multi-mode authentication as machines are connected via IP Phones.
Many Thanks.
- Labels:
-
AAA
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-29-2015 06:01 AM
"So my question is why does client machine send MAC or host/machine name to ISE? "
When MAC authentication bypass used then
"username = password = MAC address"
http://www.cisco.com/c/en/us/products/collateral/ios-nx-os-software/identity-based-networking-services/config_guide_c17-663759.html#wp9000178
incase of machine authentication then host name is used
