<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PEAP/EAP-TLS replication in node group in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/peap-eap-tls-replication-in-node-group/m-p/3454507#M527918</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;DIV&gt;&lt;P&gt;Feature is based on master key that is common to all so that connection to different PSN will allow resumption based on initial negotiation for same master key.&lt;/P&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 07 Aug 2017 16:44:33 GMT</pubDate>
    <dc:creator>Craig Hyps</dc:creator>
    <dc:date>2017-08-07T16:44:33Z</dc:date>
    <item>
      <title>PEAP/EAP-TLS replication in node group</title>
      <link>https://community.cisco.com/t5/network-access-control/peap-eap-tls-replication-in-node-group/m-p/3454506#M527917</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Hi there,&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;My customer has a concern around millisecond network/IP outages for the traders. &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Question:&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;1. How is the PEAP/EAP-TLS session resumption replicated between PSNs in a node group? &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;My customer recognises that in a normal office environment, the PEAP/EAP-TLS exchange and failover process is "almost invisible" and not an issue however extra due diligence is required for trader workstations.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Thank you,&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Arron&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Aug 2017 16:24:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/peap-eap-tls-replication-in-node-group/m-p/3454506#M527917</guid>
      <dc:creator>kerai08</dc:creator>
      <dc:date>2017-08-07T16:24:20Z</dc:date>
    </item>
    <item>
      <title>Re: PEAP/EAP-TLS replication in node group</title>
      <link>https://community.cisco.com/t5/network-access-control/peap-eap-tls-replication-in-node-group/m-p/3454507#M527918</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;DIV&gt;&lt;P&gt;Feature is based on master key that is common to all so that connection to different PSN will allow resumption based on initial negotiation for same master key.&lt;/P&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Aug 2017 16:44:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/peap-eap-tls-replication-in-node-group/m-p/3454507#M527918</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2017-08-07T16:44:33Z</dc:date>
    </item>
    <item>
      <title>Re: PEAP/EAP-TLS replication in node group</title>
      <link>https://community.cisco.com/t5/network-access-control/peap-eap-tls-replication-in-node-group/m-p/3454508#M527919</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks, Craig!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Aug 2017 16:50:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/peap-eap-tls-replication-in-node-group/m-p/3454508#M527919</guid>
      <dc:creator>kerai08</dc:creator>
      <dc:date>2017-08-07T16:50:58Z</dc:date>
    </item>
    <item>
      <title>Re: PEAP/EAP-TLS replication in node group</title>
      <link>https://community.cisco.com/t5/network-access-control/peap-eap-tls-replication-in-node-group/m-p/3454509#M527920</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sure.&amp;nbsp; I should add that the implementation is based on RFC 5077 for session ticket extensions with EAP-TLS.&amp;nbsp; The feature is not limited to node group, but config is common across all PSNs as all will leverage the same master ticket.&amp;nbsp; A bit more info is provided in the Reference presentation for BRKSEC-3699 (CiscoLive.com&amp;nbsp; &amp;gt;&amp;gt; Session Catalog &amp;gt;&amp;gt; BRKSEC-3699 @ CLUS Vegas 2017).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, the implementation is specific to EAP-TLS.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Aug 2017 20:32:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/peap-eap-tls-replication-in-node-group/m-p/3454509#M527920</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2017-08-07T20:32:23Z</dc:date>
    </item>
  </channel>
</rss>

