ā10-09-2019 03:19 PM
ā11-12-2019 12:05 PM
Hi Martin.
Regarding HA:
Regarding supplicant:
Regards
ā11-12-2019 11:38 AM
Hi Z,
Thanks for posting back.
That was the exact method I was trying to accomplish but didnāt know how or even if it was possible, didnāt think about workflows! First time Iāve seen a real practical use for it.
That would though make XMC a critical component in the process though right, so redundancy for XMC would need to be considered?
That said, I have a customer that is already using certs and wanted to use dynamic policy based on username without being dependent on a user cert, mainly because of the back-end complications in accomplishing that.
I canāt switch the supplicant from EAP-TLS to PEAP, but wondered if there was another way of doing it, like using Kerberos snooping for exampleā¦. the problem is the āAuthenticationā element, it has to be one or the other, so think Iām stuck without a custom supplicant?
Thanks,
Martin
ā11-12-2019 10:51 AM
Hi Martin.
consider following approach:
If the above is acceptable then "User authenticated on domain computer" is the solution for you.
ā10-15-2019 10:21 AM
Martin,
Weāve verified that changing the name does not work when we set this up some time ago. It looks at more than just the hostname when it checks AD.
The best thing to do is to test this for yourself in a test environment, or to see it in action.