<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Unable to use EAP-FAST with Windows10. in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/unable-to-use-eap-fast-with-windows10/m-p/3828981#M474365</link>
    <description>Can you share the radius live log detailed steps? Good luck with the upgrade.</description>
    <pubDate>Fri, 29 Mar 2019 16:21:31 GMT</pubDate>
    <dc:creator>Mike.Cifelli</dc:creator>
    <dc:date>2019-03-29T16:21:31Z</dc:date>
    <item>
      <title>Unable to use EAP-FAST with Windows10.</title>
      <link>https://community.cisco.com/t5/network-access-control/unable-to-use-eap-fast-with-windows10/m-p/3828803#M474360</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I recently set up a Cisco ISE 2.4 install for my company. We are using Cisco Anyconnect 4.7 (with NAM component) on WIndows10.&lt;/P&gt;&lt;P&gt;PEAP(EAP-MSCHAPv2) and EAP-TLS are working well but if I try to use EAP-FAST(EAP-MSCHAPv2) it fails. I tried with User Auth only and with Eap-Chaining but both failed. I keep having the following error message:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"&lt;STRONG&gt;12116 Client sent Result TLV indicating failure&lt;/STRONG&gt;"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Capture du 2019-03-29 11-50-51.png" style="width: 675px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/33215i0D90B3E3725A386D/image-size/large?v=v2&amp;amp;px=999" role="button" title="Capture du 2019-03-29 11-50-51.png" alt="Capture du 2019-03-29 11-50-51.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Did you allready meet this issue ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;</description>
      <pubDate>Mon, 01 Apr 2019 09:28:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/unable-to-use-eap-fast-with-windows10/m-p/3828803#M474360</guid>
      <dc:creator>pbesset</dc:creator>
      <dc:date>2019-04-01T09:28:45Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to use EAP-FAST with Windows10.</title>
      <link>https://community.cisco.com/t5/network-access-control/unable-to-use-eap-fast-with-windows10/m-p/3828845#M474361</link>
      <description>Did you properly configure your configuration.xml file that is used with NAM using the NAM profile editor? Are you using PACs? If not, double check that your general EAP-FAST settings in ISE allow pac-less session resume (Administration-&amp;gt;Settings-&amp;gt;Protocols-&amp;gt;EAP-FAST-&amp;gt;EAP-FAST Settings. Can you run a few debug commands on your NAD for the host you are testing and share as well?&lt;BR /&gt;debug aaa authentication&lt;BR /&gt;debug radius authentication</description>
      <pubDate>Fri, 29 Mar 2019 12:49:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/unable-to-use-eap-fast-with-windows10/m-p/3828845#M474361</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2019-03-29T12:49:38Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to use EAP-FAST with Windows10.</title>
      <link>https://community.cisco.com/t5/network-access-control/unable-to-use-eap-fast-with-windows10/m-p/3828879#M474362</link>
      <description>&lt;P&gt;Hi Mike,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I used the NAM profile editor and made this configuration, I use PACs:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Capture.PNG" style="width: 657px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/33219i0FD9E4E32E028E7B/image-size/large?v=v2&amp;amp;px=999" role="button" title="Capture.PNG" alt="Capture.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The EAP-FAST configuration is the following (I enabled "pac-less resume" but I do not think I need it):&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Capture2.png" style="width: 826px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/33221i2D353B3604D7DAF9/image-size/large?v=v2&amp;amp;px=999" role="button" title="Capture2.png" alt="Capture2.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The logs from the NAD are not very handy, here is the switch output:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;Mar 29 14:26:20 GMT: %DOT1X-5-FAIL: Switch 1 R0/0: sessmgrd: Authentication failed for client (XXXX.XXXX.XXXX) with reason (Cred Fail) on Interface Gi1/0/2 AuditSessionID 10FEFE0A00000114C9A1077E
Mar 29 14:26:27 GMT: %DOT1X-5-FAIL: Switch 1 R0/0: sessmgrd: Authentication failed for client (XXXX.XXXX.XXXX) with reason (Cred Fail) on Interface Gi1/0/2 AuditSessionID 10FEFE0A00000114C9A1077E
Mar 29 14:26:35 GMT: %DOT1X-5-FAIL: Switch 1 R0/0: sessmgrd: Authentication failed for client (XXXX.XXXX.XXXX) with reason (Cred Fail) on Interface Gi1/0/2 AuditSessionID 10FEFE0A00000114C9A1077E
Mar 29 14:26:35 GMT: %SESSION_MGR-5-FAIL: Switch 1 R0/0: sessmgrd: Authorization failed or unapplied for client (XXXX.XXXX.XXXX) on Interface GigabitEthernet1/0/2 AuditSessionID 10FEFE0A00000114C9A1077E. Failure reason: Authc fail. Authc failure reason: Cred Fail.&lt;/PRE&gt;&lt;P&gt;Regards.&lt;/P&gt;</description>
      <pubDate>Fri, 29 Mar 2019 13:33:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/unable-to-use-eap-fast-with-windows10/m-p/3828879#M474362</guid>
      <dc:creator>pbesset</dc:creator>
      <dc:date>2019-03-29T13:33:39Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to use EAP-FAST with Windows10.</title>
      <link>https://community.cisco.com/t5/network-access-control/unable-to-use-eap-fast-with-windows10/m-p/3828903#M474363</link>
      <description>Since you are using PACs you are correct. You do not need the pac-less session resume. Can you share your ISE authentication policy and allowed protocols profile being used there. If you goal is to enable fast reconnect then enable fast reconnect in your configuration.xml and test again.</description>
      <pubDate>Fri, 29 Mar 2019 14:18:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/unable-to-use-eap-fast-with-windows10/m-p/3828903#M474363</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2019-03-29T14:18:09Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to use EAP-FAST with Windows10.</title>
      <link>https://community.cisco.com/t5/network-access-control/unable-to-use-eap-fast-with-windows10/m-p/3828967#M474364</link>
      <description>&lt;P&gt;Mike,&lt;/P&gt;&lt;DIV class="lia-message-body lia-component-body-signature-highlight-escalation"&gt;&lt;DIV class="lia-message-body-content"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="lia-message-body-content"&gt;Here is my authentication policy:&lt;/DIV&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="ScreenShot025.jpg" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/33228i1880E1D5B6E9096C/image-size/large?v=v2&amp;amp;px=999" role="button" title="ScreenShot025.jpg" alt="ScreenShot025.jpg" /&gt;&lt;/span&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;BR /&gt;&lt;DIV class="lia-message-body-content"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="lia-message-body-content"&gt;The allowed protocols profile is pretty simple too:&lt;/DIV&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Capture3.png" style="width: 689px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/33227i603D44CAAAA99347/image-size/large?v=v2&amp;amp;px=999" role="button" title="Capture3.png" alt="Capture3.png" /&gt;&lt;/span&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;BR /&gt;&lt;DIV class="lia-message-body-content"&gt;I tried with Fast-Reconnect enabled but the issue remains the same.&lt;/DIV&gt;&lt;DIV class="lia-message-body-content"&gt;My final goal is to use Eap-Chaining but since user authentication is failing using EAP-Fast I debug step by step so I disabled EAP Chaining for the moment.&lt;/DIV&gt;&lt;DIV class="lia-message-body-content"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="lia-message-body-content"&gt;I am running ISE 2.4 so I will update to 2.4 Patch6 because it seems that the following bugs could be my issue:&lt;/DIV&gt;&lt;DIV class="lia-message-body-content"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="Capture du 2019-03-29 16-46-21.png" style="width: 586px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/33231iC817AB8FC9BEFEE6/image-size/large?v=v2&amp;amp;px=999" role="button" title="Capture du 2019-03-29 16-46-21.png" alt="Capture du 2019-03-29 16-46-21.png" /&gt;&lt;/span&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="Capture du 2019-03-29 16-47-55.png" style="width: 673px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/33233i3345EC28E428033B/image-dimensions/673x29?v=v2" width="673" height="29" role="button" title="Capture du 2019-03-29 16-47-55.png" alt="Capture du 2019-03-29 16-47-55.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;DIV class="lia-message-body-content"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="lia-message-body-content"&gt;Regards.&lt;/DIV&gt;&lt;DIV class="lia-message-body-content"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Fri, 29 Mar 2019 15:50:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/unable-to-use-eap-fast-with-windows10/m-p/3828967#M474364</guid>
      <dc:creator>pbesset</dc:creator>
      <dc:date>2019-03-29T15:50:20Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to use EAP-FAST with Windows10.</title>
      <link>https://community.cisco.com/t5/network-access-control/unable-to-use-eap-fast-with-windows10/m-p/3828981#M474365</link>
      <description>Can you share the radius live log detailed steps? Good luck with the upgrade.</description>
      <pubDate>Fri, 29 Mar 2019 16:21:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/unable-to-use-eap-fast-with-windows10/m-p/3828981#M474365</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2019-03-29T16:21:31Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to use EAP-FAST with Windows10.</title>
      <link>https://community.cisco.com/t5/network-access-control/unable-to-use-eap-fast-with-windows10/m-p/3829394#M474366</link>
      <description>&lt;P&gt;CSCvm03681 most likely. See&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/field-notices/703/fn70357.html" target="_blank"&gt;Field Notice: FN - 70357 - Identity Services Engine and AnyConnect Secure Mobility Client 4.7 Fail to Authenticate When Using EAP-FAST with TLS 1.2 - Software Upgrade Recommended - Cisco&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;The other bug is for network devices (e.g. a Cisco IOS switch) to retrieve TrustSec policies from ISE.&lt;/P&gt;</description>
      <pubDate>Sat, 30 Mar 2019 21:54:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/unable-to-use-eap-fast-with-windows10/m-p/3829394#M474366</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2019-03-30T21:54:23Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to use EAP-FAST with Windows10.</title>
      <link>https://community.cisco.com/t5/network-access-control/unable-to-use-eap-fast-with-windows10/m-p/3829789#M474367</link>
      <description>&lt;P&gt;Hi Mike, Hslai,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After upgrading to 2.4 Patch 6, EAP-Fast and EAP-Chaining are now working well.&lt;/P&gt;&lt;P&gt;Thank you for your help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;</description>
      <pubDate>Mon, 01 Apr 2019 09:27:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/unable-to-use-eap-fast-with-windows10/m-p/3829789#M474367</guid>
      <dc:creator>pbesset</dc:creator>
      <dc:date>2019-04-01T09:27:31Z</dc:date>
    </item>
  </channel>
</rss>

