<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE with LDAP using PEAP or MSCHAPv2 in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-with-ldap-using-peap-or-mschapv2/m-p/3884965#M496930</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/66138"&gt;@ldanny&lt;/a&gt;&amp;nbsp; what do you mean by ""its a matter of planning and Priority".i have a similar scenario which a big client who wants global implementation for ISE and have been trying to find the solution&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/211394"&gt;@gugonza2&lt;/a&gt;&amp;nbsp; how did you solve your situation&lt;/P&gt;</description>
    <pubDate>Thu, 04 Jul 2019 21:15:55 GMT</pubDate>
    <dc:creator>tandemike</dc:creator>
    <dc:date>2019-07-04T21:15:55Z</dc:date>
    <item>
      <title>ISE with LDAP using PEAP or MSCHAPv2</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-with-ldap-using-peap-or-mschapv2/m-p/3540023#M496922</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a customer using LDAP and RADIUS using PEAP and MSCHAPv2 protocols.&lt;/P&gt;&lt;P&gt;They are evaluating ISE but, using ISE with LDAP is not supported PEAP or MSCHAPv2.&lt;/P&gt;&lt;P&gt;The customer is asking us for a reason,&amp;nbsp; what is the reason why ISE does´t support this protocols ?&lt;/P&gt;&lt;P&gt;Is in roadmap this ?&amp;nbsp;&amp;nbsp; is going ISE to support them ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please your help in this question.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Jun 2018 12:05:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-with-ldap-using-peap-or-mschapv2/m-p/3540023#M496922</guid>
      <dc:creator>gugonza2</dc:creator>
      <dc:date>2018-06-18T12:05:23Z</dc:date>
    </item>
    <item>
      <title>Re: ISE with LDAP using PEAP or MSCHAPv2</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-with-ldap-using-peap-or-mschapv2/m-p/3540024#M496923</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am not sure ,where you read that LDAP and these protocols are not supported ??&lt;/P&gt;&lt;P&gt;I am not tested this but i think it might work just you must create a &lt;SPAN class="nested xwtBreadcrumb"&gt;&lt;SPAN class="xwtBreadcrumbText xwtBreadcrumbLast"&gt;New Identity Source Sequence&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="nested xwtBreadcrumb"&gt;&lt;SPAN class="xwtBreadcrumbText xwtBreadcrumbLast"&gt;Where you will use AD and LDAP_AD&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="nested xwtBreadcrumb"&gt;&lt;SPAN class="xwtBreadcrumbText xwtBreadcrumbLast"&gt;&lt;IMG __jive_id="117707" alt="" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/117707_pastedImage_0.png" style="max-width: 1200px; max-height: 900px;" /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="117708" alt="" class="jive-image image-2" src="https://community.cisco.com/legacyfs/online/fusion/117708_pastedImage_1.png" style="max-width: 1200px; max-height: 900px;" /&gt;&lt;/P&gt;&lt;P&gt;And use it in authorization policy . In authentication use protocols that you need for your deployment.&lt;/P&gt;&lt;P&gt;And i saw one more thing &lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCul55352/?rfs=iqvred" title="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCul55352/?rfs=iqvred"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCul55352/?rfs=iqvred&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Jun 2018 12:15:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-with-ldap-using-peap-or-mschapv2/m-p/3540024#M496923</guid>
      <dc:creator>ognyan.totev</dc:creator>
      <dc:date>2018-06-18T12:15:34Z</dc:date>
    </item>
    <item>
      <title>Re: ISE with LDAP using PEAP or MSCHAPv2</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-with-ldap-using-peap-or-mschapv2/m-p/3540025#M496924</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry for confusion in the note,&amp;nbsp; ISE support LDAP, but ISE will not support PEAP and MSCHAPv2 with LDAP, you can see the Table 2 "Authentication Protocols and Supported External Identity Sources" in the following link:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/admin_guide/b_ise_admin_guide_24/b_ise_admin_guide_24_new_chapter_01110.html#concept_BD3A270FEC0C411DA10FB808C14B48D5" title="https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/admin_guide/b_ise_admin_guide_24/b_ise_admin_guide_24_new_chapter_01110.html#concept_BD3A270FEC0C411DA10FB808C14B48D5"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/admin_guide/b_ise_admin_guide_24/b_ise_admin_guide_24_new_chapter…&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The customer´s question is Why and if we have any roadmap for that ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Jun 2018 12:22:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-with-ldap-using-peap-or-mschapv2/m-p/3540025#M496924</guid>
      <dc:creator>gugonza2</dc:creator>
      <dc:date>2018-06-18T12:22:13Z</dc:date>
    </item>
    <item>
      <title>Re: ISE with LDAP using PEAP or MSCHAPv2</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-with-ldap-using-peap-or-mschapv2/m-p/3540026#M496925</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;we do not discuss roadmaps in this forum.&lt;/P&gt;&lt;P&gt;please contact your Cisco representative for additional information.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Jun 2018 12:32:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-with-ldap-using-peap-or-mschapv2/m-p/3540026#M496925</guid>
      <dc:creator>ldanny</dc:creator>
      <dc:date>2018-06-18T12:32:05Z</dc:date>
    </item>
    <item>
      <title>Re: ISE with LDAP using PEAP or MSCHAPv2</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-with-ldap-using-peap-or-mschapv2/m-p/3540027#M496926</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Danny, sorry for roadmap question,&amp;nbsp; But, is there any reason why ISE don't´s support specific Authentication protocols such as PEAP and MSCHAPv2 ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Jun 2018 12:34:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-with-ldap-using-peap-or-mschapv2/m-p/3540027#M496926</guid>
      <dc:creator>gugonza2</dc:creator>
      <dc:date>2018-06-18T12:34:50Z</dc:date>
    </item>
    <item>
      <title>Re: ISE with LDAP using PEAP or MSCHAPv2</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-with-ldap-using-peap-or-mschapv2/m-p/3540028#M496927</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The way I understand it, it's a technical limitation of how the passwords are stored in the LDAP "database".&lt;/P&gt;&lt;P&gt;You can perform ASCII/PAP authentication to an LDAP directory (because the password that is sent in the auth request is simply a string comparison with the plain text password stored in the LDAP directory). But you cannot perform CHAP etc because there is neither a simple password sent by the client, nor is there a simple password stored on the external directory.&amp;nbsp; E.g. in AD, the client and server perform a handshake protocol, hence the name &lt;STRONG&gt;Challenge&lt;/STRONG&gt;-Handshake &lt;STRONG&gt;Authentication Protocol&lt;/STRONG&gt;&amp;nbsp; (I don't completely understand it - google it) and this is where the complexity comes in.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have a read of this too&lt;/P&gt;&lt;P&gt;&lt;A href="http://deployingradius.com/documents/protocols/compatibility.html" title="http://deployingradius.com/documents/protocols/compatibility.html"&gt;Deploying RADIUS: Protocol and Password Compatibility&lt;/A&gt;&lt;/P&gt;&lt;P&gt;If you want the real gory details (actually an excellent explanation by a somewhat militant sounding Alan de Kok (FreeRadius dev) then check this out &lt;A href="http://freeradius.1045715.n5.nabble.com/Chap-auhtentication-against-LDAP-td2781170.html" title="http://freeradius.1045715.n5.nabble.com/Chap-auhtentication-against-LDAP-td2781170.html"&gt;Users - Chap auhtentication against LDAP&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Having said that, Aruba Clearpass appears to support this. &lt;A href="https://www.arubanetworks.com/techdocs/ClearPass/Aruba_DeployGd_HTML/Content/LDAP%20&amp;amp;%20SQL%20Auth%20Sources/LDAP_Auth_Source.htm" title="https://www.arubanetworks.com/techdocs/ClearPass/Aruba_DeployGd_HTML/Content/LDAP%20&amp;amp;%20SQL%20Auth%20Sources/LDAP_Auth_Source.htm"&gt;LDAP Authentication Source Configuration&lt;/A&gt; - so maybe the technical argument is an old one. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It's confusing for sure &lt;IMG src="https://community.cisco.com/legacyfs/online/emoticons/confused.png" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Jun 2018 22:26:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-with-ldap-using-peap-or-mschapv2/m-p/3540028#M496927</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2018-06-18T22:26:48Z</dc:date>
    </item>
    <item>
      <title>Re: ISE with LDAP using PEAP or MSCHAPv2</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-with-ldap-using-peap-or-mschapv2/m-p/3540029#M496928</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Its mainly due to planning and priority.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Jun 2018 10:59:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-with-ldap-using-peap-or-mschapv2/m-p/3540029#M496928</guid>
      <dc:creator>ldanny</dc:creator>
      <dc:date>2018-06-19T10:59:18Z</dc:date>
    </item>
    <item>
      <title>Re: ISE with LDAP using PEAP or MSCHAPv2</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-with-ldap-using-peap-or-mschapv2/m-p/3540030#M496929</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Arne, Danny for your answers.&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Jun 2018 09:01:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-with-ldap-using-peap-or-mschapv2/m-p/3540030#M496929</guid>
      <dc:creator>gugonza2</dc:creator>
      <dc:date>2018-06-21T09:01:57Z</dc:date>
    </item>
    <item>
      <title>Re: ISE with LDAP using PEAP or MSCHAPv2</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-with-ldap-using-peap-or-mschapv2/m-p/3884965#M496930</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/66138"&gt;@ldanny&lt;/a&gt;&amp;nbsp; what do you mean by ""its a matter of planning and Priority".i have a similar scenario which a big client who wants global implementation for ISE and have been trying to find the solution&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/211394"&gt;@gugonza2&lt;/a&gt;&amp;nbsp; how did you solve your situation&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jul 2019 21:15:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-with-ldap-using-peap-or-mschapv2/m-p/3884965#M496930</guid>
      <dc:creator>tandemike</dc:creator>
      <dc:date>2019-07-04T21:15:55Z</dc:date>
    </item>
    <item>
      <title>Re: ISE with LDAP using PEAP or MSCHAPv2</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-with-ldap-using-peap-or-mschapv2/m-p/3884971#M496931</link>
      <description>&lt;P&gt;See&amp;nbsp;&lt;A href="https://community.cisco.com/t5/security-documents/how-to-ask-the-community-for-help/ta-p/3704356#toc-hId-519934988" target="_blank"&gt;No Comment on Roadmaps or Fixes&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jul 2019 21:49:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-with-ldap-using-peap-or-mschapv2/m-p/3884971#M496931</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2019-07-04T21:49:10Z</dc:date>
    </item>
  </channel>
</rss>

