<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic AAA Test command for EAP-TLS authentication for wireless users in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/aaa-test-command-for-eap-tls-authentication-for-wireless-users/m-p/1674591#M238533</link>
    <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can anyone suggest me the test command to verify the eap-tls authentication for wireless in Cisco WAP's.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If it is a leap authetication we can use the below command to test the connection&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Testwap-01#test aaa group radius &lt;A href="mailto:xyzabc@abc.com" target="_blank"&gt;xyzabc@abc.com&lt;/A&gt; o4&amp;amp;yJ)NoL$%0 new-code &lt;BR /&gt;Trying to authenticate with Servergroup radius&lt;BR /&gt;User successfully authenticated&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But eap-tls doesn't comes with the password. It insist only for the username.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are trying it for remote location so we have to test it remotely before putting in to production.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So anyone pls help in this if we have any test command or debug command to test this authentication.&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 01:02:42 GMT</pubDate>
    <dc:creator>nkarthikeyan</dc:creator>
    <dc:date>2019-03-11T01:02:42Z</dc:date>
    <item>
      <title>AAA Test command for EAP-TLS authentication for wireless users</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-test-command-for-eap-tls-authentication-for-wireless-users/m-p/1674591#M238533</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can anyone suggest me the test command to verify the eap-tls authentication for wireless in Cisco WAP's.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If it is a leap authetication we can use the below command to test the connection&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Testwap-01#test aaa group radius &lt;A href="mailto:xyzabc@abc.com" target="_blank"&gt;xyzabc@abc.com&lt;/A&gt; o4&amp;amp;yJ)NoL$%0 new-code &lt;BR /&gt;Trying to authenticate with Servergroup radius&lt;BR /&gt;User successfully authenticated&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But eap-tls doesn't comes with the password. It insist only for the username.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are trying it for remote location so we have to test it remotely before putting in to production.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So anyone pls help in this if we have any test command or debug command to test this authentication.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 01:02:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-test-command-for-eap-tls-authentication-for-wireless-users/m-p/1674591#M238533</guid>
      <dc:creator>nkarthikeyan</dc:creator>
      <dc:date>2019-03-11T01:02:42Z</dc:date>
    </item>
    <item>
      <title>Re: AAA Test command for EAP-TLS authentication for wireless use</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-test-command-for-eap-tls-authentication-for-wireless-users/m-p/1674592#M238534</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;EAP-TLS requires a client certificate. How do you want to have an easy command testing that without loading any certificate on the router/switch ? There's not. That's why eap-tls is not considered an easy eap method to deploy : because it can go wrong on several levels.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The test aaa command does a PAP authentication, so it tests basic radius connectivity and username/password.&lt;/P&gt;&lt;P&gt;If that works, the only thing that can break for eap-tls are certificates, so only the radius server will be able to tell you if something goes worng.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 May 2011 05:28:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-test-command-for-eap-tls-authentication-for-wireless-users/m-p/1674592#M238534</guid>
      <dc:creator>Nicolas Darchis</dc:creator>
      <dc:date>2011-05-02T05:28:51Z</dc:date>
    </item>
    <item>
      <title>Re: AAA Test command for EAP-TLS authentication for wireless use</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-test-command-for-eap-tls-authentication-for-wireless-users/m-p/1674593#M238535</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yeah. Nicholas that makes sense.&lt;/P&gt;&lt;P&gt; We cannot test in a simple way from Access Point.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have one more query please help me on this if you have a clue on this.&lt;/P&gt;&lt;DIV class="jive-rendered-content"&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have the Win 3.2 ACS setup in the production environment, We are migrating it with 4.2 Appliance version. We have succesfully migrated the database and other stuffs from 3.2 to 4.2. Same way we have exported the certificates from 3.2 to 4.2 and installed it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have the leap as well as eap-tls in the authentication part.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We were able to test successfully with the leap. But when it comes to eap-tls. In 4.2 version its throwing the error.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE border="0" cellpadding="0" cellspacing="0" style="width: 1299px; border-collapse: collapse;"&gt;&lt;COLGROUP span="1"&gt;&lt;COL span="9" style="width: 48pt;" width="64" /&gt;&lt;COL span="1" style="width: 62pt; mso-width-source: userset; mso-width-alt: 3035;" width="83" /&gt;&lt;COL span="10" style="width: 48pt;" width="64" /&gt;&lt;/COLGROUP&gt;&lt;TBODY&gt;&lt;TR style="height: 15pt;"&gt;&lt;TD align="right" class="xl63" height="20" style="background-color: transparent; width: 48pt; height: 15pt; border: black;" width="64"&gt;5/3/2011&lt;/TD&gt;&lt;TD align="right" class="xl64" style="background-color: transparent; width: 48pt; border: black;" width="64"&gt;23:16:38&lt;/TD&gt;&lt;TD style="background-color: transparent; width: 48pt; border: black;" width="64"&gt;Authen failed&lt;/TD&gt;&lt;TD style="background-color: transparent; width: 48pt; border: black;" width="64"&gt;&lt;A class="jive-link-email-small" href="mailto:nkarthikeyan@abc.com"&gt;nkarthikeyan@abc.com&lt;/A&gt;&lt;/TD&gt;&lt;TD style="background-color: transparent; width: 48pt; border: black;" width="64"&gt;EAP-TLS users&lt;/TD&gt;&lt;TD style="background-color: transparent; width: 48pt; border: black;" width="64"&gt;0023.1413.de18&lt;/TD&gt;&lt;TD style="background-color: transparent; width: 48pt; border: black;" width="64"&gt;(Default)&lt;/TD&gt;&lt;TD colspan="3" style="background-color: transparent; width: 158pt; mso-ignore: colspan; border: black;" width="211"&gt;EAP-TLS or PEAP authentication failed due to unknown CA certificate during SSL handshake&lt;/TD&gt;&lt;TD align="right" style="background-color: transparent; width: 48pt; border: black;" width="64"&gt;21356&lt;/TD&gt;&lt;TD colspan="2" style="background-color: transparent; width: 96pt; mso-ignore: colspan; border: black;" width="128"&gt;10.121.198.38&lt;/TD&gt;&lt;TD style="background-color: transparent; width: 48pt; border: black;" width="64"&gt;&lt;/TD&gt;&lt;TD align="right" style="background-color: transparent; width: 48pt; border: black;" width="64"&gt;13&lt;/TD&gt;&lt;TD style="background-color: transparent; width: 48pt; border: black;" width="64"&gt;EAP-TLS&lt;/TD&gt;&lt;TD style="background-color: transparent; width: 48pt; border: black;" width="64"&gt;&lt;/TD&gt;&lt;TD style="background-color: transparent; width: 48pt; border: black;" width="64"&gt;ap-1242b4 &lt;/TD&gt;&lt;TD colspan="2" style="background-color: transparent; width: 96pt; mso-ignore: colspan; border: black;" width="128"&gt;&lt;P&gt;&amp;nbsp; Bangalore APs&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have used the same certficate exported and installed in the 4.2 version. But its working in the existing 3.2 version and why it is not working with the 4.2 version.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could anyone help me out in this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Karthik&lt;/P&gt;&lt;/DIV&gt;&lt;P&gt;&lt;!-- [DocumentBodyEnd:df7baa4f-21db-4b05-b4e3-f0c04cba60f4] --&gt;&lt;!-- BEGIN attachments --&gt;&lt;/P&gt;&lt;P&gt;&lt;!-- END attachments --&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 May 2011 02:01:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-test-command-for-eap-tls-authentication-for-wireless-users/m-p/1674593#M238535</guid>
      <dc:creator>nkarthikeyan</dc:creator>
      <dc:date>2011-05-04T02:01:40Z</dc:date>
    </item>
    <item>
      <title>Re: AAA Test command for EAP-TLS authentication for wireless use</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-test-command-for-eap-tls-authentication-for-wireless-users/m-p/1674594#M238536</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How did you migrate the database?? did u do a database restore?? if yes, then the certs should also be imported.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also ensure that the CA cert is installed and trusted in the trust list.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Anisha&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;P.S.: please mark this thread as answered if you feel your query is resolved. Do rate helpful posts.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 May 2011 02:33:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-test-command-for-eap-tls-authentication-for-wireless-users/m-p/1674594#M238536</guid>
      <dc:creator>andamani</dc:creator>
      <dc:date>2011-05-04T02:33:27Z</dc:date>
    </item>
    <item>
      <title>Re: AAA Test command for EAP-TLS authentication for wireless use</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-test-command-for-eap-tls-authentication-for-wireless-users/m-p/1674595#M238538</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Anisha,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have upgraded the win 3.2 back up to win 4.2 version using the trail version of 3.2 s/w and uploaded in 4.2.15 Appliance version.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rest all other stuffs working fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have the leap authentication also migrated and leap is working fine with the restored database. But the eap-tls is not working in this case.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When we restored the certificates are not imported automatically. we did it manually. let me cross verify once and come back to you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 May 2011 04:23:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-test-command-for-eap-tls-authentication-for-wireless-users/m-p/1674595#M238538</guid>
      <dc:creator>nkarthikeyan</dc:creator>
      <dc:date>2011-05-04T04:23:33Z</dc:date>
    </item>
  </channel>
</rss>

