<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Windows 10 devices can't connect to an 802.1X environment in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/windows-10-devices-can-t-connect-to-an-802-1x-environment/m-p/3599540#M511852</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The Microsoft support help pages might be either giving confusing or incorrect info.&lt;/P&gt;&lt;P&gt;ISE 2.0 FCS without patches is impacted. ISE 2.0 Patch 1 is the one providing the fix for this issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;See &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-0/release_notes/ise20_rn.html#pgfId-633243"&gt;Resolved Issues in Cisco ISE Version 2.0.0.306—Cumulative Patch 1&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Table 12 Cisco ISE Patch Version 2.0.0.306—Patch 1 Resolved Caveats&amp;nbsp; &lt;/P&gt;&lt;TABLE border="1"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TH&gt;&lt;P class="pCH1_CellHead1"&gt; &lt;A name="pgfId-618796"&gt;&lt;/A&gt;Caveat&lt;/P&gt;&lt;/TH&gt;&lt;TH&gt;&lt;P class="pCH1_CellHead1"&gt; &lt;A name="pgfId-618798"&gt;&lt;/A&gt;Description&lt;/P&gt;&lt;/TH&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P class="pB1_Body1"&gt; &lt;A name="pgfId-618800"&gt;&lt;/A&gt;CSCuw88770&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P class="pB1_Body1"&gt; &lt;A name="pgfId-618802"&gt;&lt;/A&gt;ISE 2.0 PEAP TLS 1.2 wireless authentication fails with Android 6 and Win 10.&lt;/P&gt;&lt;P class="pB1_Body1"&gt; &lt;A name="pgfId-618803"&gt;&lt;/A&gt;This issue occurred because in TLS 1.2, the mechanism of MPPE keys generation has been changed for EAP-TLS, PEAP, and EAP-TTLS. EAP-FAST is not affected.&lt;/P&gt;&lt;P class="pB1_Body1"&gt; &lt;A name="pgfId-618804"&gt;&lt;/A&gt;Symptom: Authentication reports from logs show that the authentication is successful; however, the state on the WLC of the client session is dot1x required. Wireless packet captures reveal that 4-way handshakes following EAP-success are not completing, either M1 and M2 or M1 only.&lt;/P&gt;&lt;P class="pB1_Body1"&gt; &lt;A name="pgfId-618805"&gt;&lt;/A&gt;Conditions: This issue occurs when a combination of the following conditions are true:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt; &lt;A name="pgfId-618806"&gt;&lt;/A&gt;If you have Cisco ISE, Release 2.0 FCS version with no patch installed.&lt;/LI&gt;&lt;LI&gt; &lt;A name="pgfId-618807"&gt;&lt;/A&gt;Wireless LAN with L2 security configured for WPA2 Enterprise.&lt;/LI&gt;&lt;LI&gt; &lt;A name="pgfId-618808"&gt;&lt;/A&gt;A device with Android 6 or Windows 10 version 1511 tries to authenticate.&lt;/LI&gt;&lt;LI&gt; &lt;A name="pgfId-618809"&gt;&lt;/A&gt;Protocols used are PEAP or TTLS or EAP-TLS&lt;/LI&gt;&lt;/UL&gt;&amp;nbsp; &lt;A name="pgfId-618810"&gt;&lt;/A&gt;Workaround: &lt;UL&gt;&lt;LI&gt; &lt;A name="pgfId-618811"&gt;&lt;/A&gt;For Android, none. You cannot configure TLS version from Android client or Cisco ISE&lt;/LI&gt;&lt;LI&gt; &lt;A name="pgfId-618812"&gt;&lt;/A&gt;For Windows 10 clients, you may disable TLS 1.2 and enable TLS 1.0:&lt;/LI&gt;&lt;/UL&gt;&lt;P class="pBu2_Bullet2"&gt; &lt;A name="pgfId-618813"&gt;&lt;/A&gt; – Create DWORD HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RasMan\PPP\EAP\13\TlsVersion and set the associate DWORD value to C0.&lt;/P&gt;&lt;P class="pBu2_Bullet2"&gt; &lt;A name="pgfId-618814"&gt;&lt;/A&gt; – Restart EapHost service.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;H2 class="p_H_Head1"&gt; &lt;A name="pgfId-634275"&gt;&lt;/A&gt;&lt;A name="97275"&gt;&lt;/A&gt;&lt;/H2&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 05 Mar 2018 20:35:21 GMT</pubDate>
    <dc:creator>hslai</dc:creator>
    <dc:date>2018-03-05T20:35:21Z</dc:date>
    <item>
      <title>Windows 10 devices can't connect to an 802.1X environment</title>
      <link>https://community.cisco.com/t5/network-access-control/windows-10-devices-can-t-connect-to-an-802-1x-environment/m-p/3599539#M511851</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;H1 class="x-hidden-focus ng-scope article-heading c-heading-3 ng-binding"&gt;Windows 10 devices can't connect to an 802.1X environment (November Update)&lt;/H1&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://support.microsoft.com/en-gb/help/3121002/windows-10-devices-can-t-connect-to-an-802-1x-environment" title="https://support.microsoft.com/en-gb/help/3121002/windows-10-devices-can-t-connect-to-an-802-1x-environment"&gt;https://support.microsoft.com/en-gb/help/3121002/windows-10-devices-can-t-connect-to-an-802-1x-environment&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://support.microsoft.com/en-gb/help/3121002/windows-10-devices-can-t-connect-to-an-802-1x-environment" title="https://support.microsoft.com/en-gb/help/3121002/windows-10-devices-can-t-connect-to-an-802-1x-environment"&gt;https://support.microsoft.com/en-gb/help/3121002/windows-10-devices-can-t-connect-to-an-802-1x-environment&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12.0pt; font-family: 'Arial','sans-serif';"&gt;&lt;A href="https://support.microsoft.com/en-gb/help/3121002/windows-10-devices-can-t-connect-to-an-802-1x-environment"&gt;https://support.microsoft.com/en-gb/help/3121002/windows-10-devices-can-t-connect-to-an-802-1x-environment&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please advise me the fix release on Cisco ISE to mitigate above issue.&lt;/P&gt;&lt;P&gt;I am intending to upgrade to version 2.0 from version 1.4, , according to Microsoft ISE version 2.0.0.306 patch 1 is effected,&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 Mar 2018 13:22:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/windows-10-devices-can-t-connect-to-an-802-1x-environment/m-p/3599539#M511851</guid>
      <dc:creator>PNW Weer</dc:creator>
      <dc:date>2018-03-05T13:22:46Z</dc:date>
    </item>
    <item>
      <title>Re: Windows 10 devices can't connect to an 802.1X environment</title>
      <link>https://community.cisco.com/t5/network-access-control/windows-10-devices-can-t-connect-to-an-802-1x-environment/m-p/3599540#M511852</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The Microsoft support help pages might be either giving confusing or incorrect info.&lt;/P&gt;&lt;P&gt;ISE 2.0 FCS without patches is impacted. ISE 2.0 Patch 1 is the one providing the fix for this issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;See &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-0/release_notes/ise20_rn.html#pgfId-633243"&gt;Resolved Issues in Cisco ISE Version 2.0.0.306—Cumulative Patch 1&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Table 12 Cisco ISE Patch Version 2.0.0.306—Patch 1 Resolved Caveats&amp;nbsp; &lt;/P&gt;&lt;TABLE border="1"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TH&gt;&lt;P class="pCH1_CellHead1"&gt; &lt;A name="pgfId-618796"&gt;&lt;/A&gt;Caveat&lt;/P&gt;&lt;/TH&gt;&lt;TH&gt;&lt;P class="pCH1_CellHead1"&gt; &lt;A name="pgfId-618798"&gt;&lt;/A&gt;Description&lt;/P&gt;&lt;/TH&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P class="pB1_Body1"&gt; &lt;A name="pgfId-618800"&gt;&lt;/A&gt;CSCuw88770&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P class="pB1_Body1"&gt; &lt;A name="pgfId-618802"&gt;&lt;/A&gt;ISE 2.0 PEAP TLS 1.2 wireless authentication fails with Android 6 and Win 10.&lt;/P&gt;&lt;P class="pB1_Body1"&gt; &lt;A name="pgfId-618803"&gt;&lt;/A&gt;This issue occurred because in TLS 1.2, the mechanism of MPPE keys generation has been changed for EAP-TLS, PEAP, and EAP-TTLS. EAP-FAST is not affected.&lt;/P&gt;&lt;P class="pB1_Body1"&gt; &lt;A name="pgfId-618804"&gt;&lt;/A&gt;Symptom: Authentication reports from logs show that the authentication is successful; however, the state on the WLC of the client session is dot1x required. Wireless packet captures reveal that 4-way handshakes following EAP-success are not completing, either M1 and M2 or M1 only.&lt;/P&gt;&lt;P class="pB1_Body1"&gt; &lt;A name="pgfId-618805"&gt;&lt;/A&gt;Conditions: This issue occurs when a combination of the following conditions are true:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt; &lt;A name="pgfId-618806"&gt;&lt;/A&gt;If you have Cisco ISE, Release 2.0 FCS version with no patch installed.&lt;/LI&gt;&lt;LI&gt; &lt;A name="pgfId-618807"&gt;&lt;/A&gt;Wireless LAN with L2 security configured for WPA2 Enterprise.&lt;/LI&gt;&lt;LI&gt; &lt;A name="pgfId-618808"&gt;&lt;/A&gt;A device with Android 6 or Windows 10 version 1511 tries to authenticate.&lt;/LI&gt;&lt;LI&gt; &lt;A name="pgfId-618809"&gt;&lt;/A&gt;Protocols used are PEAP or TTLS or EAP-TLS&lt;/LI&gt;&lt;/UL&gt;&amp;nbsp; &lt;A name="pgfId-618810"&gt;&lt;/A&gt;Workaround: &lt;UL&gt;&lt;LI&gt; &lt;A name="pgfId-618811"&gt;&lt;/A&gt;For Android, none. You cannot configure TLS version from Android client or Cisco ISE&lt;/LI&gt;&lt;LI&gt; &lt;A name="pgfId-618812"&gt;&lt;/A&gt;For Windows 10 clients, you may disable TLS 1.2 and enable TLS 1.0:&lt;/LI&gt;&lt;/UL&gt;&lt;P class="pBu2_Bullet2"&gt; &lt;A name="pgfId-618813"&gt;&lt;/A&gt; – Create DWORD HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RasMan\PPP\EAP\13\TlsVersion and set the associate DWORD value to C0.&lt;/P&gt;&lt;P class="pBu2_Bullet2"&gt; &lt;A name="pgfId-618814"&gt;&lt;/A&gt; – Restart EapHost service.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;H2 class="p_H_Head1"&gt; &lt;A name="pgfId-634275"&gt;&lt;/A&gt;&lt;A name="97275"&gt;&lt;/A&gt;&lt;/H2&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 Mar 2018 20:35:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/windows-10-devices-can-t-connect-to-an-802-1x-environment/m-p/3599540#M511852</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-03-05T20:35:21Z</dc:date>
    </item>
  </channel>
</rss>

