05-11-2011 10:12 AM - edited 07-03-2021 08:11 PM
We have
ACS 5.2, WLC 5500, and we have been unable to limit our access service to
machine authentication against AD. This is resulting in other
unintended devices being allowed access to the WLAN, users simply accept the cert and are allowed access. How can I prevent
non-domain devices? or test the device for domain membership?
Thanks
Solved! Go to Solution.
11-18-2011 05:18 AM
Are you doing anything else on ACS or is it just wireless. If it doesn't match any rule, it should be denied.
Sent from my iPhone
11-18-2011 06:12 AM
It is just wireless. I don't want to set the default rule to deny otherwise users will not be able to access the network. The autorization rule should get matched but can't put my finger as to why it doesn't.
11-18-2011 06:13 AM
you said your condition had 2 items "was machien authenticated" and a group condition too
What if you just put "was machine authenticated", would it then hit ? if not, then it's the "was machine authenticated" that is the problem
11-18-2011 07:49 AM
Could you take a screen shot of your policy and also the passed authentication on your default policy.
Sent from my iPhone
11-18-2011 10:19 AM
you guys have ny luck, i am also hitting the same rock...i.e. the message is
24423 ACS has not been able to confirm previous successful machine authentication for user in Active Directory
User authentication works fine, but when i enable both UA/MA, it does not budge.
11-18-2011 10:55 AM
Do you see the machine sending machine credentials when it fails? In Windows 7 you need to setup the client with User and Machine. In windows XP you need to do a registry hack to send machine auth.
http://support.microsoft.com/kb/929847
Sent from my iPhone
11-18-2011 11:25 AM
Hi Scott,
had tried that registry hack earlier, with values of 0,1,2 all..no success
Also when i disable the MAR (Machine Access Restrictions) and just check for Machine Authentication, it does not give me an error mentioned above, but it still is no go.
Wondering if it is something to do on AD (but user auth works) or missing something in ACS..also will check up with Windows 7 , hope it works there.
Trying to figure out the way to interactivily debug the ACS logs and see what is it doing during these auth. sessions
Thanks
11-18-2011 11:30 AM
Can you post a screen shot of your policy? I know it works because I tested it out an deployed it a while ago.
Sent from my iPhone
11-21-2011 04:14 AM
Hi
Many thanks for your help so far. Below are the rules used.
The service selection rule
The authorization rules for the "Wireless Access" access service
Initially I was using authorization rules 1 and 2 then I disabled them and now that I am using only rule 3 that has only "Was Authenticated = True", as suggested by Nicolas, I can now hit the rule. I guess the "contains any" conditions in rules 1 and 2 did not match anything in AD (by the way I could not select these in Directory Groups and entered them manually).
But, does the fact that I can now hit authorization rule 3 mean that I am doing Machine Authentication against the entire of AD as no Directory Group is used?
Thanks
Raoul
11-21-2011 05:06 AM
You would need to look at the pass authentication log to see what rules and how the user is being granted access. Your service selection rules are pretty wide open, so take a look at your log.
11-21-2011 05:20 AM
Hi Scott
That is precisely what I have been trying to do but for the life of me I cannot find where to access this on ACS.
This is the type of log I am after
11-21-2011 05:42 AM
On the left side, there is something that says monitor and reports or something like that. Wen you click on that, it will open another browser. You will find the logs there.
Sent from my iPhone
11-21-2011 05:45 AM
I have been using the "Monitoring and Report Viewer" but can't find on ACS5.1 where to display the log in the formay above.
11-21-2011 07:03 AM
I can look later... Not in front of my ACS at the moment.
Sent from my iPhone
11-21-2011 08:47 AM
Hi Scott, thanks for your concern, i checked it with the similar config and access for Window 7 and it works fine, but still nowhere with XP. Windows XP is even not sending anything in ACS logs that says machine accounts/authentication.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide