<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE 2.3 EAP message format in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-2-3-eap-message-format/m-p/3764705#M517943</link>
    <description>&lt;P&gt;I am not seeing any issue. Increment it sequentially is a suggestion.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://tools.ietf.org/html/rfc3748#section-4.1" target="_blank"&gt;rfc3748 4.1 Request and Response&lt;/A&gt;&amp;nbsp;says,&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;...&lt;/P&gt;
&lt;PRE class="newpage"&gt;Identifier
      ...
      In order to avoid confusion between new Requests and
      retransmissions, the Identifier value chosen for each new Request
      need only be different from the previous Request, but need not be
      unique within the conversation.  One way to achieve this is to
      start the Identifier at an initial value and increment it for each
      new Request.  Initializing the first Identifier with a random
      number rather than starting from zero is recommended, since it
      makes sequence attacks somewhat more difficult.&lt;BR /&gt;...&lt;/PRE&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 17 Dec 2018 02:05:27 GMT</pubDate>
    <dc:creator>hslai</dc:creator>
    <dc:date>2018-12-17T02:05:27Z</dc:date>
    <item>
      <title>ISE 2.3 EAP message format</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-eap-message-format/m-p/3443005#M517940</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have an environment where my authenticator is an IOS router and my supplicant an IoT endpoint. I'm trying to do EAP-TLS to authenticate the endpoint.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The authenticator will send the first EAP-Request to get the supplicant Identity with an EAP Id of 0x01:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt; font-family: 'courier new', courier;"&gt;128450: Feb&amp;nbsp; 7 14:17:05.329: EAPOL pak dump Tx&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier; font-size: 8pt;"&gt;128451: Feb&amp;nbsp; 7 14:17:05.329: EAPOL Version: 0x3&amp;nbsp; type: 0x0&amp;nbsp; length: 0x0005&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt; font-family: 'courier new', courier;"&gt;128452: Feb&amp;nbsp; 7 14:17:05.329: EAP code: 0x1&amp;nbsp; &lt;STRONG&gt;id: 0x1&lt;/STRONG&gt;&amp;nbsp; length: 0x0005 type: 0x1&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As expected the endpoint reply back with an EAP Response using the same Id value as stated in the RFC. This response is encapsulated into a Radius access-request packet and sent to the ISE server:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt; font-family: 'courier new', courier;"&gt;128480: Feb&amp;nbsp; 7 14:17:05.355: RADIUS(00000477): Send Access-Request to 10.10.203.253:1812 onvrf(0) id 1645/121, len 238&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier; font-size: 8pt;"&gt;128481: Feb&amp;nbsp; 7 14:17:05.355: RADIUS:&amp;nbsp; authenticator 45 B4 04 B9 E6 BB D1 6D - DA 00 98 3A 8D 20 A8 B1&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier; font-size: 8pt;"&gt;128482: Feb&amp;nbsp; 7 14:17:05.355: RADIUS:&amp;nbsp; User-Name&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [1]&amp;nbsp;&amp;nbsp; 20&amp;nbsp; "host/LabGlobalCert"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier; font-size: 8pt;"&gt;128483: Feb&amp;nbsp; 7 14:17:05.355: RADIUS:&amp;nbsp; Service-Type&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [6]&amp;nbsp;&amp;nbsp; 6&amp;nbsp;&amp;nbsp; Framed&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [2]&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier; font-size: 8pt;"&gt;128484: Feb&amp;nbsp; 7 14:17:05.355: RADIUS:&amp;nbsp; Vendor, Cisco&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [26]&amp;nbsp; 27&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier; font-size: 8pt;"&gt;128485: Feb&amp;nbsp; 7 14:17:05.355: RADIUS:&amp;nbsp;&amp;nbsp; Cisco AVpair&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [1]&amp;nbsp;&amp;nbsp; 21&amp;nbsp; "service-type=Framed"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier; font-size: 8pt;"&gt;128486: Feb&amp;nbsp; 7 14:17:05.355: RADIUS:&amp;nbsp; Framed-MTU&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [12]&amp;nbsp; 6&amp;nbsp;&amp;nbsp; 1500&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier; font-size: 8pt;"&gt;128487: Feb&amp;nbsp; 7 14:17:05.355: RADIUS:&amp;nbsp; Called-Station-Id&amp;nbsp;&amp;nbsp; [30]&amp;nbsp; 19&amp;nbsp; "01-05-00-4C-00-40"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier; font-size: 8pt;"&gt;128488: Feb&amp;nbsp; 7 14:17:05.355: RADIUS:&amp;nbsp; Calling-Station-Id&amp;nbsp; [31]&amp;nbsp; 19&amp;nbsp; "01-07-00-27-00-2C"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier; font-size: 8pt;"&gt;128489: Feb&amp;nbsp; 7 14:17:05.357: RADIUS:&amp;nbsp; &lt;STRONG&gt;EAP-Message&lt;/STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [79]&amp;nbsp; 25&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier; font-size: 8pt;"&gt;128490: Feb&amp;nbsp; 7 14:17:05.357: RADIUS:&amp;nbsp;&amp;nbsp; 02&lt;STRONG&gt; 01&lt;/STRONG&gt; 00 17 01 68 6F 73 74 2F 4C 61 62 47 6C 6F 62 61 6C 43 65&amp;nbsp; [host/LabGlobalCe]&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier; font-size: 8pt;"&gt;128491: Feb&amp;nbsp; 7 14:17:05.357: RADIUS:&amp;nbsp;&amp;nbsp; 72 74&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [ rt]&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier; font-size: 8pt;"&gt;128492: Feb&amp;nbsp; 7 14:17:05.357: RADIUS:&amp;nbsp; Message-Authenticato[80]&amp;nbsp; 18&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier; font-size: 8pt;"&gt;128493: Feb&amp;nbsp; 7 14:17:05.357: RADIUS:&amp;nbsp;&amp;nbsp; 2B A0 68 84 36 8C 42 22 20 64 BE F4 CA A5 61 FD&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [ +h6B" da]&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier; font-size: 8pt;"&gt;128494: Feb&amp;nbsp; 7 14:17:05.357: RADIUS:&amp;nbsp; EAP-Key-Name&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [102] 2&amp;nbsp;&amp;nbsp; *&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier; font-size: 8pt;"&gt;128495: Feb&amp;nbsp; 7 14:17:05.357: RADIUS:&amp;nbsp; Vendor, Cisco&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [26]&amp;nbsp; 49&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier; font-size: 8pt;"&gt;128496: Feb&amp;nbsp; 7 14:17:05.357: RADIUS:&amp;nbsp;&amp;nbsp; Cisco AVpair&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [1]&amp;nbsp;&amp;nbsp; 43&amp;nbsp; "audit-session-id=0A640C41000001D11BACE0A2"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier; font-size: 8pt;"&gt;128497: Feb&amp;nbsp; 7 14:17:05.357: RADIUS:&amp;nbsp; NAS-Port-Type&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [61]&amp;nbsp; 6&amp;nbsp;&amp;nbsp; Virtual&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [5]&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier; font-size: 8pt;"&gt;128498: Feb&amp;nbsp; 7 14:17:05.357: RADIUS:&amp;nbsp; NAS-Port&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [5]&amp;nbsp;&amp;nbsp; 6&amp;nbsp;&amp;nbsp; 1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier; font-size: 8pt;"&gt;128499: Feb&amp;nbsp; 7 14:17:05.357: RADIUS:&amp;nbsp; NAS-Port-Id&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [87]&amp;nbsp; 9&amp;nbsp;&amp;nbsp; "Wpan4/1"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt; font-family: 'courier new', courier;"&gt;128500: Feb&amp;nbsp; 7 14:17:05.357: RADIUS:&amp;nbsp; NAS-IP-Address&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [4]&amp;nbsp;&amp;nbsp; 6&amp;nbsp;&amp;nbsp; 10.100.12.65&lt;/SPAN&gt;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now when looking at ISE reply, I noticed it is using some random numbers for the EAP Identifier field:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN style="font-size: 8pt; font-family: 'courier new', courier;"&gt;030080: Feb&amp;nbsp; 6 00:59:52.105: RADIUS: Received from id 1645/209 10.10.203.253:1812,&lt;STRONG&gt; Access-Challenge,&lt;/STRONG&gt; len 122&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1" style="font-family: 'courier new', courier; font-size: 8pt;"&gt;030081: Feb&amp;nbsp; 6 00:59:52.105: RADIUS:&amp;nbsp; authenticator BC FD AE B6 4F 35 7D A5 - DA A7 85 E7 AA 7C 37 A8&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1" style="font-family: 'courier new', courier; font-size: 8pt;"&gt;030082: Feb&amp;nbsp; 6 00:59:52.105: RADIUS:&amp;nbsp; State&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [24]&amp;nbsp; 76&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1" style="font-family: 'courier new', courier; font-size: 8pt;"&gt;030083: Feb&amp;nbsp; 6 00:59:52.105: RADIUS:&amp;nbsp;&amp;nbsp; 33 37 43 50 4D 53 65 73 73 69 6F 6E 49 44 3D 30&amp;nbsp; [37CPMSessionID=0]&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1" style="font-family: 'courier new', courier; font-size: 8pt;"&gt;030084: Feb&amp;nbsp; 6 00:59:52.105: RADIUS:&amp;nbsp;&amp;nbsp; 41 36 34 30 43 34 31 30 30 30 30 30 30 36 38 31&amp;nbsp; [A640C41000000681]&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1" style="font-family: 'courier new', courier; font-size: 8pt;"&gt;030085: Feb&amp;nbsp; 6 00:59:52.105: RADIUS:&amp;nbsp;&amp;nbsp; 33 41 43 45 46 37 30 3B 33 31 53 65 73 73 69 6F&amp;nbsp; [3ACEF70;31Sessio]&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1" style="font-family: 'courier new', courier; font-size: 8pt;"&gt;030086: Feb&amp;nbsp; 6 00:59:52.105: RADIUS:&amp;nbsp;&amp;nbsp; 6E 49 44 3D 43 43 49 53 45 30 31 2F 33 30 36 38&amp;nbsp; [nID=CCISE01/3068]&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1" style="font-family: 'courier new', courier; font-size: 8pt;"&gt;030087: Feb&amp;nbsp; 6 00:59:52.105: RADIUS:&amp;nbsp;&amp;nbsp; 30 38 37 33 31 2F 32 34 35 3B&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [ 08731/245;]&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1" style="font-family: 'courier new', courier; font-size: 8pt;"&gt;030088: Feb&amp;nbsp; 6 00:59:52.105: RADIUS:&amp;nbsp; &lt;STRONG&gt;EAP-Message&lt;/STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [79]&amp;nbsp; 8&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1" style="font-family: 'courier new', courier; font-size: 8pt;"&gt;030089: Feb&amp;nbsp; 6 00:59:52.105: RADIUS:&amp;nbsp;&amp;nbsp; 01 &lt;STRONG&gt;FD&lt;/STRONG&gt; 00 06 0D 20&lt;STRONG&gt; &lt;/STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [&amp;nbsp; ]&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1" style="font-family: 'courier new', courier; font-size: 8pt;"&gt;030090: Feb&amp;nbsp; 6 00:59:52.105: RADIUS:&amp;nbsp; Message-Authenticato[80]&amp;nbsp; 18&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1" style="font-family: 'courier new', courier; font-size: 8pt;"&gt;030091: Feb&amp;nbsp; 6 00:59:52.105: RADIUS:&amp;nbsp;&amp;nbsp; 9A 4E BE D3 5E FE 37 DC 5A 6F 8B EC 51 5F 33 96&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [ N^7ZoQ_3]&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1" style="font-family: 'courier new', courier; font-size: 8pt;"&gt;030092: Feb&amp;nbsp; 6 00:59:52.105: RADIUS(00000278): Received from id 1645/209&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1" style="font-family: 'courier new', courier; font-size: 8pt;"&gt;030093: Feb&amp;nbsp; 6 00:59:52.107: RADIUS/DECODE: EAP-Message fragments, 6, total 6 bytes&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1" style="font-family: 'courier new', courier; font-size: 8pt;"&gt;…&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN style="font-family: 'courier new', courier; font-size: 8pt;"&gt;&lt;SPAN class="s1"&gt;030106: Feb&amp;nbsp; 6 00:59:52.109: &lt;STRONG&gt;EAP code: 0x1&amp;nbsp; &lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN class="s2"&gt;&lt;STRONG&gt;id: 0xFD &lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="s1" style="; font-size: 8pt; font-family: 'courier new', courier;"&gt;&lt;STRONG&gt;length: 0x0006 type: 0xD&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1" style="; font-size: 8pt; font-family: 'courier new', courier;"&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN style="font-size: 13.3333px; font-family: arial, helvetica, sans-serif;"&gt;Other Radius server like NPS, CPAR or FreeRadius will instead increment the value of the Identifier of the previous request. It means for the packet captured above, a value of 0x2.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN style="font-size: 13.3333px; font-family: arial, helvetica, sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;Why is ISE EAP implementation behaving differently from the other types of server ?&lt;/P&gt;&lt;P class="p1"&gt;&lt;/P&gt;&lt;P class="p1"&gt;The reason I'm asking is my supplicant is expected the Identifier from a EAP-Request to be an increment of the previous one which means its is currently dropping the requests received from ISE.&lt;/P&gt;&lt;P class="p1"&gt;&lt;/P&gt;&lt;P class="p1"&gt;Thanks for your support&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Feb 2018 12:48:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-eap-message-format/m-p/3443005#M517940</guid>
      <dc:creator>Laurent Aubert</dc:creator>
      <dc:date>2018-02-09T12:48:56Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.3 EAP message format</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-eap-message-format/m-p/3443006#M517941</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We will discuss this further offline.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Feb 2018 03:12:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-eap-message-format/m-p/3443006#M517941</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-02-12T03:12:42Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.3 EAP message format</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-eap-message-format/m-p/3760837#M517942</link>
      <description>&lt;P&gt;Hi hslai,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have also &lt;SPAN&gt;encountered&lt;/SPAN&gt; this ISE EAP id issue.&lt;/P&gt;
&lt;P&gt;Does the Cisco ISE EAP id implementation deviate from the RFC?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;JH&lt;/P&gt;</description>
      <pubDate>Mon, 10 Dec 2018 21:25:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-eap-message-format/m-p/3760837#M517942</guid>
      <dc:creator>jharaldsson</dc:creator>
      <dc:date>2018-12-10T21:25:55Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.3 EAP message format</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-eap-message-format/m-p/3764705#M517943</link>
      <description>&lt;P&gt;I am not seeing any issue. Increment it sequentially is a suggestion.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://tools.ietf.org/html/rfc3748#section-4.1" target="_blank"&gt;rfc3748 4.1 Request and Response&lt;/A&gt;&amp;nbsp;says,&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;...&lt;/P&gt;
&lt;PRE class="newpage"&gt;Identifier
      ...
      In order to avoid confusion between new Requests and
      retransmissions, the Identifier value chosen for each new Request
      need only be different from the previous Request, but need not be
      unique within the conversation.  One way to achieve this is to
      start the Identifier at an initial value and increment it for each
      new Request.  Initializing the first Identifier with a random
      number rather than starting from zero is recommended, since it
      makes sequence attacks somewhat more difficult.&lt;BR /&gt;...&lt;/PRE&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Dec 2018 02:05:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-eap-message-format/m-p/3764705#M517943</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-12-17T02:05:27Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.3 EAP message format</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-eap-message-format/m-p/4703080#M577754</link>
      <description>&lt;P&gt;I tried to send CCX wifi packets but Cisco not recognize that. i guess maybe wrong format . I need Packet structure format .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;Neil.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Oct 2022 04:46:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-eap-message-format/m-p/4703080#M577754</guid>
      <dc:creator>Titus O Neil</dc:creator>
      <dc:date>2022-10-14T04:46:33Z</dc:date>
    </item>
  </channel>
</rss>

