Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
LAN adapter showing Authentication Failed even when it is failed back to MAB. At least this is i am seeing for Windows 11 machine.
User machine has Windows LAN Supplicant enabled ( Wired AutoConfig ) and certificate options are selected from the LAN...
I do not see hostname field for some of the endpoints. these endpoint IP's are assigned statically no there is no DHCP involved.
probe wise I have radius and nmap enabled. Do I require DNS Probe to enabled ?
what is the requirement from ISE perspec...
Hi - Is there a way to find which profiling Rules are matching in ISE Profiling ? For example if certainty factor is 30 which rules will be contributing to 30 wanted to know.
Hi - Can you suggest If I want to do ISE Profiling using SNMP , Radius Probe what will be Firewall Rule Flow ? I mean what will be SRC and DST for SNMP , Radius Profiling ?
@thomas
Hello Greg,
@Greg Gibbs
This looks interesting to me. For Authz rule it never matches the 1st rule. After device is booted and before user logged in i see at ISE EAP Chaining result is User Failed but Machine Succeeded & it matches the 2nd Authz ru...
@ahollifield ok you are saying if required certs are installed and then being wired auto config enabled ( even supplicant settings is not accurate ) then it will not show the auth failed error from LAN Interfaces as I explained ?
Reason I ask is - I ...
@ahollifield Since It is a new deployment , Plan is , required LAN Settings ( Authentication TAB from LAN Adapter ) will be enabled for dot1x as part of the pre migration plan for dot1x but during this period before cert is installed users should fal...
@Greg Gibbs after removing the Entra AD Group it matches user succeeded and machine succeeded policy when user logs in. Interesting is if I call an Old AD Group where the same user is it matches the user user succeeded and machine succeeded policy.
...