<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Access Manager Configuration EAP-TLS in Cloud Networking Platform</title>
    <link>https://community.cisco.com/t5/cloud-networking-platform/access-manager-configuration-eap-tls/m-p/5454922#M12749</link>
    <description>&lt;P&gt;Take a look at this access manager + cloud pki guide&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.hypershift.com/blog/meraki-intune-cloud-pki" target="_blank" rel="nofollow noopener noreferrer"&gt;https://www.hypershift.com/blog/meraki-intune-cloud-pki&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 20 Aug 2025 23:22:06 GMT</pubDate>
    <dc:creator>gary5555</dc:creator>
    <dc:date>2025-08-20T23:22:06Z</dc:date>
    <item>
      <title>Access Manager Configuration EAP-TLS</title>
      <link>https://community.cisco.com/t5/cloud-networking-platform/access-manager-configuration-eap-tls/m-p/5454916#M12743</link>
      <description>&lt;P&gt;Hi folks,&lt;/P&gt;&lt;P&gt;we want to use the Access Manager for a customer deployment for local 802.1X Authentication.&lt;/P&gt;&lt;P&gt;We have hybrid Win 11 notebooks with Microsoft Cloud PKI over intune. We deliver computer certificates to the clients. Now we want to authenticate with this certificate against the access Manager. &lt;/P&gt;&lt;P&gt;We build a policy that says if in the cert ist XXX than allow access. We do not want to lookup to Entra ID, we only want to get access for client with certificate present in the first step.&lt;/P&gt;&lt;P&gt;If we deploy the config to the switch, we see in the log that the field with the computername is extracted from the local cert. But than the Access Manager throws an error:&lt;/P&gt;&lt;P&gt;Session Id&lt;/P&gt;&lt;P&gt;bf302f75-ee18-4c48-9731-6aa6ea894261&lt;/P&gt;&lt;P&gt;Time&lt;/P&gt;&lt;P&gt;Mar 21 06:57:38&lt;/P&gt;&lt;P&gt;Status&lt;/P&gt;&lt;P&gt;Failed&lt;/P&gt;&lt;P&gt;Failure/ Rejection info&lt;/P&gt;&lt;P&gt;Reason&lt;/P&gt;&lt;P&gt;There was an internal server error occured in authentication flow.&lt;/P&gt;&lt;P&gt;Suggested action&lt;/P&gt;&lt;P&gt;Please verify configurations and retry. We are taking a look. Please report if this issue is not fixed.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;User&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Username&lt;/P&gt;&lt;P&gt;host/XXX-19291600753&lt;/P&gt;&lt;P&gt;Has anyone the same issue?&lt;/P&gt;&lt;P&gt;Notice:&lt;/P&gt;&lt;P&gt;If we use MAB Auth the Access Manager works as well.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Mar 2025 07:04:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-networking-platform/access-manager-configuration-eap-tls/m-p/5454916#M12743</guid>
      <dc:creator>tobias.hoffmann</dc:creator>
      <dc:date>2025-03-21T07:04:52Z</dc:date>
    </item>
    <item>
      <title>Re: Access Manager Configuration EAP-TLS</title>
      <link>https://community.cisco.com/t5/cloud-networking-platform/access-manager-configuration-eap-tls/m-p/5454917#M12744</link>
      <description>&lt;P&gt;Not on topic, but I think a new Techincal forum should be created just for Access Manager.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Mar 2025 09:52:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-networking-platform/access-manager-configuration-eap-tls/m-p/5454917#M12744</guid>
      <dc:creator>Thomas Obbekaer Thomsen</dc:creator>
      <dc:date>2025-03-21T09:52:28Z</dc:date>
    </item>
    <item>
      <title>Re: Access Manager Configuration EAP-TLS</title>
      <link>https://community.cisco.com/t5/cloud-networking-platform/access-manager-configuration-eap-tls/m-p/5454918#M12745</link>
      <description>&lt;P&gt;At the moment very few orgs have access to AM as it’s an early preview and not even rolled out fully to the Early Access page.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;You may need to contact support to get an answer. If you do please share the resolution.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Mar 2025 13:55:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-networking-platform/access-manager-configuration-eap-tls/m-p/5454918#M12745</guid>
      <dc:creator>mloraditch</dc:creator>
      <dc:date>2025-03-21T13:55:02Z</dc:date>
    </item>
    <item>
      <title>Re: Access Manager Configuration EAP-TLS</title>
      <link>https://community.cisco.com/t5/cloud-networking-platform/access-manager-configuration-eap-tls/m-p/5454919#M12746</link>
      <description>&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;after i started the conversation here, the log from the access manager changed. Now it seems that the authetication works for me. ihave also opened a ticket but there was no answer yet. Since i got a answer, i will post ist here.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Sun, 23 Mar 2025 08:31:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-networking-platform/access-manager-configuration-eap-tls/m-p/5454919#M12746</guid>
      <dc:creator>tobias.hoffmann</dc:creator>
      <dc:date>2025-03-23T08:31:03Z</dc:date>
    </item>
    <item>
      <title>Re: Access Manager Configuration EAP-TLS</title>
      <link>https://community.cisco.com/t5/cloud-networking-platform/access-manager-configuration-eap-tls/m-p/5454920#M12747</link>
      <description>&lt;P&gt;I don't have access to Access Manager yet ...&lt;/P&gt;&lt;P&gt;Try configuring the Windows 802.1x policy to only do user authentication (then it won't present computer certificates), and delivering user certificates to the users.&lt;/P&gt;</description>
      <pubDate>Sun, 23 Mar 2025 22:55:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-networking-platform/access-manager-configuration-eap-tls/m-p/5454920#M12747</guid>
      <dc:creator>Philip D'Ath</dc:creator>
      <dc:date>2025-03-23T22:55:24Z</dc:date>
    </item>
    <item>
      <title>Re: Access Manager Configuration EAP-TLS</title>
      <link>https://community.cisco.com/t5/cloud-networking-platform/access-manager-configuration-eap-tls/m-p/5454921#M12748</link>
      <description>&lt;P&gt;Not exactly the same but similar enough. I ran into the same error when using 802.1x EAP-TLS with an Intune Cloud PKI issued user (not device) certificate.&lt;BR /&gt;&lt;BR /&gt;My error below:&lt;/P&gt;&lt;DIV class=""&gt;Failure/ Rejection info:&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;STRONG&gt;Reason&lt;/STRONG&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;P class=""&gt;There was an internal server error occurred in authentication flow.&lt;/P&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;STRONG&gt;Suggested action&lt;/STRONG&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;P class=""&gt;Please verify configurations and retry. We are taking a look. Please report if this issue is not fixed.&lt;BR /&gt;&lt;BR /&gt;In my case, the Subject Common Name of the certificate was using the email address of the Entra ID user and Access Manager was set to use Subject Common Name as the user identity attribute. &lt;/P&gt;&lt;P class=""&gt; &lt;/P&gt;&lt;P class=""&gt;After verifying my Access Manager and endpoint configuration against the documentation:&lt;/P&gt;&lt;P class=""&gt;&lt;A href="https://documentation.meraki.com/Access_Manager/Access_Manager_Configuration_Guides/Access_Manager_Certificate_Based_Authentication_-_EAP-TLS_with_Entra_ID_Lookup" target="_blank" rel="noopener nofollow noreferrer"&gt;Access Manager Certificate Based Authentication - EAP-TLS with Entra ID Lookup - Cisco Meraki Documentation&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://documentation.meraki.com/Access_Manager/Access_Manager_Configuration_Guides/Access_Manager_-_EAP-TLS_Client_Configuration_(Windows%2C_macOS_and_iOS)" target="_blank" rel="noopener nofollow noreferrer"&gt;Access Manager - EAP-TLS Client Configuration (Windows, macOS and iOS) - Cisco Meraki Documentation&lt;/A&gt;&lt;/P&gt;&lt;P class=""&gt; &lt;/P&gt;&lt;P class=""&gt;I could not determine the cause of the error.&lt;/P&gt;&lt;P class=""&gt;&lt;BR /&gt;I raised a support case and the engineer suggested that because the Access Manager user identity is an email address which is also used by a Meraki Dashboard SAML administrator, that there is a potential issue/conflict here, wording from support below:&lt;/P&gt;&lt;P class=""&gt; &lt;/P&gt;&lt;P class=""&gt;"&lt;SPAN&gt;I have analysed backend logs from this organization and could not see any issues or errors being reported about the Access Manager process.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt; &lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;However, the account that is used to authenticate, is also a SAML administrator in Dashboard. Since SAML administrator account email cannot be used for a Client VPN or Meraki Cloud Authentication (RADIUS) user accounts, we might be running into the same issue here."&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;I was able to resolve this in my case by changing the Subject Common Name on my user certificate to OnPremisesSamAccountName, authentications with this configuration are working as expected. &lt;BR /&gt;&lt;BR /&gt;As this was only a PoC/testing for me, I have not tested my original configuration (Subject Common Name using Entra ID user's email address) with a user who is not a Meraki Dashboard SAML admin. &lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 08 Apr 2025 09:02:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-networking-platform/access-manager-configuration-eap-tls/m-p/5454921#M12748</guid>
      <dc:creator>ShaunBirrell</dc:creator>
      <dc:date>2025-04-08T09:02:26Z</dc:date>
    </item>
    <item>
      <title>Re: Access Manager Configuration EAP-TLS</title>
      <link>https://community.cisco.com/t5/cloud-networking-platform/access-manager-configuration-eap-tls/m-p/5454922#M12749</link>
      <description>&lt;P&gt;Take a look at this access manager + cloud pki guide&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.hypershift.com/blog/meraki-intune-cloud-pki" target="_blank" rel="nofollow noopener noreferrer"&gt;https://www.hypershift.com/blog/meraki-intune-cloud-pki&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Aug 2025 23:22:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-networking-platform/access-manager-configuration-eap-tls/m-p/5454922#M12749</guid>
      <dc:creator>gary5555</dc:creator>
      <dc:date>2025-08-20T23:22:06Z</dc:date>
    </item>
    <item>
      <title>Re: Access Manager Configuration EAP-TLS</title>
      <link>https://community.cisco.com/t5/cloud-networking-platform/access-manager-configuration-eap-tls/m-p/5454923#M12750</link>
      <description>&lt;P&gt;Following the thread..&lt;/P&gt;</description>
      <pubDate>Thu, 30 Oct 2025 01:47:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-networking-platform/access-manager-configuration-eap-tls/m-p/5454923#M12750</guid>
      <dc:creator>Nits4stockland</dc:creator>
      <dc:date>2025-10-30T01:47:46Z</dc:date>
    </item>
  </channel>
</rss>

