CCIE Sec/OT: Cisco ISE and windows sleep login problem

From: Charlie_CA <spycharlies_at_gmail.com>
Date: Thu, 14 Mar 2013 08:33:52 -0600

Hi Experts,

I have been playing with ISE over the last few days, and noticed a problem
when windows goes to sleep...

I have a few policies including

1.If a machine authenticates via Active Directory, it is granted full access
2.If a user authenticates via AD (with Machine already authenticated) =
grants full access
3.All other 802.1x is granted partial access = Guest vlan

The issue is when windows goes to sleep, authenticated AD users and machine
are put on Guest vlan; when I log back in, it still remains on Guest VLan.
My temporary solution was to completely log of the computer and log back in
so windows can re-authenticate.

If this was in production, it will be a mess getting everyone to log off
and log back inhave you witness this? How did you solve it?

Thanks

~

Charlie

Blogs and organic groups at http://www.ccie.net
Received on Thu Mar 14 2013 - 08:33:52 ART

This archive was generated by hypermail 2.2.0 : Wed Apr 03 2013 - 19:06:19 ART