<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Not a problem!  in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/802-1x-eap-tls-vs-peap-eap-tls/m-p/2901250#M39163</link>
    <description>&lt;P&gt;Not a problem!&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 27 Apr 2017 03:18:05 GMT</pubDate>
    <dc:creator>alburger</dc:creator>
    <dc:date>2017-04-27T03:18:05Z</dc:date>
    <item>
      <title>802.1x EAP-TLS vs PEAP-EAP-TLS</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-eap-tls-vs-peap-eap-tls/m-p/2901246#M39158</link>
      <description>&lt;DIV class="usertext-body may-blank-within md-container "&gt;
&lt;DIV class="md"&gt;
&lt;P&gt;Can anyone please explain the advantage (if any!) of using PEAP-EAP-TLS as opposed to just EAP-TLS for wired 802.1x deployments.&lt;/P&gt;
&lt;P&gt;We are deploying wired 802.1x machine based authentication and have a PKI infrastructure, I was under the impression that we just need to use EAP-TLS since we have a working PKI deployment and all machines have a certificate.&lt;/P&gt;
&lt;P&gt;The server guys seem to think we need to use PEAP with EAP-TLS, but cant really explain to me why, this just seems like extra work, is there any advantage ? I can understand using PEAP for things like MS-CHAP authentication, but since we are using EAP-TLS anyway this seems pointless.&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Mon, 11 Mar 2019 06:54:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-eap-tls-vs-peap-eap-tls/m-p/2901246#M39158</guid>
      <dc:creator>craig.cartlidge1</dc:creator>
      <dc:date>2019-03-11T06:54:56Z</dc:date>
    </item>
    <item>
      <title>Hi</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-eap-tls-vs-peap-eap-tls/m-p/2901247#M39160</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Eap-tls is based on client certificate authentication while peap-eap-tls is based on server side certificate authentication.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;With peap-eap-tls, the 1st phase will be the encrypted tunnel with server side authentication and then all user sensitive information are encrypted. With&amp;nbsp;this method, no user certificate will be required. It's peap v1.&lt;/P&gt;
&lt;P&gt;With eap-tls, you will need a user certificate to authenticate.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I attach an image that show you differences. Take &amp;nbsp;a look at column 2 and 4.&lt;/P&gt;
&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;
&lt;P&gt;PS: Please don't forget to rate and mark as correct answer if this solved your issue&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Jul 2016 11:46:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-eap-tls-vs-peap-eap-tls/m-p/2901247#M39160</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2016-07-07T11:46:53Z</dc:date>
    </item>
    <item>
      <title>This is incorrect. PEAP-EAP</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-eap-tls-vs-peap-eap-tls/m-p/2901248#M39161</link>
      <description>&lt;P&gt;This is incorrect. PEAP-EAP-TLS encrypts the EAP-TLS certificate transfer with a PEAP Tunnel. Certificates are still required on both the client and server. There is just added security of a TLS tunnel prior to certificate exchange. PEAP-EAP-MSCHAPv2 only requires a server side certificate while the rest of the authentication is performed as user/pass.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Apr 2017 02:28:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-eap-tls-vs-peap-eap-tls/m-p/2901248#M39161</guid>
      <dc:creator>alburger</dc:creator>
      <dc:date>2017-04-27T02:28:35Z</dc:date>
    </item>
    <item>
      <title>Yes your right and I'm sorry.</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-eap-tls-vs-peap-eap-tls/m-p/2901249#M39162</link>
      <description>&lt;P&gt;Yes your right and I'm sorry. I'm thinking why i answered this when the question was peap-eap-tls.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Maybe i thought (I red to quickly) it was asked eap-ttls on which client authentication isn't required.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks for having corrected the answer.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Apr 2017 03:01:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-eap-tls-vs-peap-eap-tls/m-p/2901249#M39162</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2017-04-27T03:01:55Z</dc:date>
    </item>
    <item>
      <title>Not a problem! </title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-eap-tls-vs-peap-eap-tls/m-p/2901250#M39163</link>
      <description>&lt;P&gt;Not a problem!&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Apr 2017 03:18:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-eap-tls-vs-peap-eap-tls/m-p/2901250#M39163</guid>
      <dc:creator>alburger</dc:creator>
      <dc:date>2017-04-27T03:18:05Z</dc:date>
    </item>
  </channel>
</rss>

