<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE and EAP-TLS + EAP-MD5 in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-and-eap-tls-eap-md5/m-p/2991451#M38456</link>
    <description>&lt;P&gt;Dear all,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've issue with Cisco ISE 2.0.1.130.&lt;/P&gt;
&lt;P&gt;All computers are joined to the Active Direcory domain (2008 2), and I make authentication for all devices (Cisco IP phones and Windows computers and for printers).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I’ve issue with Cisco ISE because I’ve 3 rules on my authentication policy :&lt;/P&gt;
&lt;UL style="list-style-type: circle;"&gt;
&lt;LI&gt;Printers : MAB&lt;/LI&gt;
&lt;LI&gt;IP Phones : EAP-MD5&lt;/LI&gt;
&lt;LI&gt;Computers : EAP-TLS&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt; My problem is that when I add rules EAP-MD5 + EAP-TLS it’s not working:&lt;/P&gt;
&lt;UL style="list-style-type: circle;"&gt;
&lt;LI&gt;EAP-MD5 at the first and EAP-TLS at the second place&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Result: my IP phones are working but my computers are not working because &lt;SPAN&gt;my computers try to authenticate with eap-md5 and not eap-tls&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL style="list-style-type: circle;"&gt;
&lt;LI&gt;EAP-TLS at the first and EAP-MD5 at the second place&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Result: my IP phones are not working but my computers are working because &lt;SPAN&gt;my IP Phones try to authenticate with eap-tls and not eap-md5.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;SPAN class="file"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;My rules :&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL style="list-style-type: circle;"&gt;
&lt;LI&gt;&lt;SPAN&gt;EAP-MD5-CiscoPhones =&amp;gt; Wired_802.1X =&amp;gt; Allowed protocol : EAP-MD5 =&amp;gt; internal Users&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;EAP-TLS CiscoPhones =&amp;gt; Wired_802.1X =&amp;gt; Allowed protocol : EAP-TLS =&amp;gt; Authentication with Certificate in AD&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class="file"&gt;&lt;A href="https://supportforums.cisco.com/sites/default/files/attachments/discussion/authentication_policy_0.jpg" type="image/jpeg; length=72664" target="_blank"&gt;authentication_policy.jpg&lt;/A&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class="file"&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/attachments/discussion/authentication_policy_1.jpg" alt="authentication policy" width="1214" height="473" /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class="file"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;And the result :&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="file"&gt;&lt;A href="https://supportforums.cisco.com/sites/default/files/attachments/discussion/result.jpg" type="image/jpeg; length=53501" target="_blank"&gt;result.jpg&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="file"&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/attachments/discussion/result_0.jpg" alt="result" width="1201" height="168" /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="file"&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="file"&gt;As you can see the computer is not authenticated and not used EAP-TLS.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="file"&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="file"&gt;Have you any idea to solved the issue ?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="file"&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="file"&gt;Thanks in advance for your help.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="file"&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="file"&gt;Best regard&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 07:03:24 GMT</pubDate>
    <dc:creator>support-reseaux-filiales</dc:creator>
    <dc:date>2019-03-11T07:03:24Z</dc:date>
    <item>
      <title>ISE and EAP-TLS + EAP-MD5</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-and-eap-tls-eap-md5/m-p/2991451#M38456</link>
      <description>&lt;P&gt;Dear all,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've issue with Cisco ISE 2.0.1.130.&lt;/P&gt;
&lt;P&gt;All computers are joined to the Active Direcory domain (2008 2), and I make authentication for all devices (Cisco IP phones and Windows computers and for printers).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I’ve issue with Cisco ISE because I’ve 3 rules on my authentication policy :&lt;/P&gt;
&lt;UL style="list-style-type: circle;"&gt;
&lt;LI&gt;Printers : MAB&lt;/LI&gt;
&lt;LI&gt;IP Phones : EAP-MD5&lt;/LI&gt;
&lt;LI&gt;Computers : EAP-TLS&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt; My problem is that when I add rules EAP-MD5 + EAP-TLS it’s not working:&lt;/P&gt;
&lt;UL style="list-style-type: circle;"&gt;
&lt;LI&gt;EAP-MD5 at the first and EAP-TLS at the second place&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Result: my IP phones are working but my computers are not working because &lt;SPAN&gt;my computers try to authenticate with eap-md5 and not eap-tls&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL style="list-style-type: circle;"&gt;
&lt;LI&gt;EAP-TLS at the first and EAP-MD5 at the second place&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Result: my IP phones are not working but my computers are working because &lt;SPAN&gt;my IP Phones try to authenticate with eap-tls and not eap-md5.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;SPAN class="file"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;My rules :&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL style="list-style-type: circle;"&gt;
&lt;LI&gt;&lt;SPAN&gt;EAP-MD5-CiscoPhones =&amp;gt; Wired_802.1X =&amp;gt; Allowed protocol : EAP-MD5 =&amp;gt; internal Users&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;EAP-TLS CiscoPhones =&amp;gt; Wired_802.1X =&amp;gt; Allowed protocol : EAP-TLS =&amp;gt; Authentication with Certificate in AD&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class="file"&gt;&lt;A href="https://supportforums.cisco.com/sites/default/files/attachments/discussion/authentication_policy_0.jpg" type="image/jpeg; length=72664" target="_blank"&gt;authentication_policy.jpg&lt;/A&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class="file"&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/attachments/discussion/authentication_policy_1.jpg" alt="authentication policy" width="1214" height="473" /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class="file"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;And the result :&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="file"&gt;&lt;A href="https://supportforums.cisco.com/sites/default/files/attachments/discussion/result.jpg" type="image/jpeg; length=53501" target="_blank"&gt;result.jpg&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="file"&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/attachments/discussion/result_0.jpg" alt="result" width="1201" height="168" /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="file"&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="file"&gt;As you can see the computer is not authenticated and not used EAP-TLS.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="file"&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="file"&gt;Have you any idea to solved the issue ?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="file"&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="file"&gt;Thanks in advance for your help.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="file"&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="file"&gt;Best regard&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 07:03:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-and-eap-tls-eap-md5/m-p/2991451#M38456</guid>
      <dc:creator>support-reseaux-filiales</dc:creator>
      <dc:date>2019-03-11T07:03:24Z</dc:date>
    </item>
    <item>
      <title>Your computers are ending up</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-and-eap-tls-eap-md5/m-p/2991452#M38458</link>
      <description>&lt;P&gt;Your computers are ending up in the phone authentication rule, because you only use wired_dot1x as your condition for what will matche the rule. Instead you need to have one authentication rule, and then allow both EAP-MD5 and EAP-TLS in that rule, then use a identity source sequence, to select the identity stores you wan't to look in (internal user, ad, and so on). The Allowed protocols setting is not used to select the rule its the result of the conditions.&lt;/P&gt;</description>
      <pubDate>Sat, 03 Sep 2016 18:48:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-and-eap-tls-eap-md5/m-p/2991452#M38458</guid>
      <dc:creator>jan.nielsen</dc:creator>
      <dc:date>2016-09-03T18:48:14Z</dc:date>
    </item>
    <item>
      <title>Hello,</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-and-eap-tls-eap-md5/m-p/2991453#M38460</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;thanks i just add an radius attribute on my Authentication Compound Conditions .&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thnaks again.&lt;/P&gt;</description>
      <pubDate>Mon, 05 Sep 2016 13:04:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-and-eap-tls-eap-md5/m-p/2991453#M38460</guid>
      <dc:creator>support-reseaux-filiales</dc:creator>
      <dc:date>2016-09-05T13:04:41Z</dc:date>
    </item>
  </channel>
</rss>

