Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
i have ISE setup for wired users . EAP-chaining using machine certificate and user credentials form active directory . the requirements is when the active directory is down we need the ISE to fall back to internal database and maintain the operation ...
i understand your point . but what happen is sometimes there is instability in the domain that affects the authentication process all over the network . customer asked for fall back scenario that can be made manual , and effective .
if the machine...
in the EAP chaining authorization policy if i use :
condition : member of "domain computers" and network access> EAP tunnel > eap-fast and network access> eap chaining results = "user failed but machine succeeded"
in this case will this require ...
thanks for your reply . actually the case is all machines will be members of the domain (domain computers) and no group membership will be used , so no problem here for the computer authentication . the problem is in the user as my authorization pol...