cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
398
Views
0
Helpful
2
Replies

ISE machine authentication - only plug in to the network after booting

Tai Eric
Level 1
Level 1

Hi experts.

I have recently deployed ISE with machine authentication. 

However, when the machine is already plugged in to the switch before booting, the machine does not authenticate automatically. It isn't until I log on, using a local computer account, that 802.1X authentication occurs. Using wireshark, I have verified again that this authentication is MACHINE authentication, not user-authentication.
Is there a way to solve this problem, other than having my users unplug their computer and only plug in to the network after booting?

Eric

2 Replies 2

Venkatesh Attuluri
Cisco Employee
Cisco Employee

Are you using EAP-Chaining (EAP-TEAP) or using machine access restriction)?

Hi Vattulu,

 

  The method of machine access restriction will be used, because there is no a plan to use anyconnect NAM on the client environment, since the prerequisite for EAP-chaining is to use anyconnect.

Regards,

Eric