11-25-2014 11:37 PM - edited 03-10-2019 10:13 PM
Version: ISE 1.2p12
Hello,
I'm doing user and machine authentication with ISE.
I use a first authorization rule to authenticate the machine against the AD. If it's part computers of the domain.
Then I use an authorization rule to check if the user's group in AD with the credential he used to open the session + "Network Access:WasMachineAuthenticated = True"
Things seems to be working and I see my switch port is "Authz Success" but shortly after the Windows 7 machine is behaving like 802.1X authentication fails. The little computer on the bottom right has a cross on it.
If I disable and enable again the network card of that windows machine it works.
Does any one of you have an idea about this problem ? something to tweak on Windows 7 like timers...
Thank you
11-30-2014 11:30 PM
Hi Neno,
just the last post in order to get back to the original question:
apart from eap chaining, do you know of any ise trick to get rid of the issues related to machine+user authentication which are referred by the document you posted?
11-30-2014 11:43 PM
Not that I am aware of. This is simply a limitation of the clients' supplicant.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide