<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Authtication policy can't use EAP-TLS in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/authtication-policy-can-t-use-eap-tls/m-p/3708264#M507696</link>
    <description>&lt;P&gt;in EAP-TLS each client should have their own certificate.&amp;nbsp; You shouldn't be trying to export a certificate from ISE and trying to get the client's to use it to authenticate EAP-TLS.&amp;nbsp; Further more if you are trying something like this you need to export both the cert/private key and ensure the certificate has EKU client auth enabled.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 17 Sep 2018 17:55:09 GMT</pubDate>
    <dc:creator>paul</dc:creator>
    <dc:date>2018-09-17T17:55:09Z</dc:date>
    <item>
      <title>Authtication policy can't use EAP-TLS</title>
      <link>https://community.cisco.com/t5/network-access-control/authtication-policy-can-t-use-eap-tls/m-p/3708209#M507598</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have a problem in the configuration of the Authentification Policy, im selecting EAP-TLS in order to force clients to use the certification that i exported from the ISE, but the endpoint can only authenticate using "&lt;SPAN&gt;PEAP (EAP-MSCHAPv2)" even if there is no rule for this protocol.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks to help us.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Sep 2018 16:12:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authtication-policy-can-t-use-eap-tls/m-p/3708209#M507598</guid>
      <dc:creator>hamzazidane</dc:creator>
      <dc:date>2018-09-17T16:12:08Z</dc:date>
    </item>
    <item>
      <title>Re: Authtication policy can't use EAP-TLS</title>
      <link>https://community.cisco.com/t5/network-access-control/authtication-policy-can-t-use-eap-tls/m-p/3708236#M507599</link>
      <description>have you tried using the default authentication ruleset and simple relying on authorization rules?&lt;BR /&gt;&lt;BR /&gt;Simple examples here in the BYOD guide (you don’t need the BYOD rules) just the one with cert auth minus registration state&lt;BR /&gt;&lt;BR /&gt;See page 25 remove the BYOD is registered and that should work&lt;BR /&gt;&lt;A href="https://community.cisco.com/t5/security-documents/cisco-ise-byod-deployment-guide/ta-p/3641867" target="_blank"&gt;https://community.cisco.com/t5/security-documents/cisco-ise-byod-deployment-guide/ta-p/3641867&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Mon, 17 Sep 2018 16:58:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authtication-policy-can-t-use-eap-tls/m-p/3708236#M507599</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-09-17T16:58:35Z</dc:date>
    </item>
    <item>
      <title>Re: Authtication policy can't use EAP-TLS</title>
      <link>https://community.cisco.com/t5/network-access-control/authtication-policy-can-t-use-eap-tls/m-p/3708264#M507696</link>
      <description>&lt;P&gt;in EAP-TLS each client should have their own certificate.&amp;nbsp; You shouldn't be trying to export a certificate from ISE and trying to get the client's to use it to authenticate EAP-TLS.&amp;nbsp; Further more if you are trying something like this you need to export both the cert/private key and ensure the certificate has EKU client auth enabled.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Sep 2018 17:55:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authtication-policy-can-t-use-eap-tls/m-p/3708264#M507696</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2018-09-17T17:55:09Z</dc:date>
    </item>
  </channel>
</rss>

