<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic EAP-FAST unprotected identity in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/eap-fast-unprotected-identity/m-p/3598152#M536584</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi community!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was wondering, I'm using eap-fast with the unprotected identity as anonymous but I see that there are many failed authentications with this user in every authentication&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="anonymous.jpg" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/103475_anonymous.jpg" style="height: 168px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Reading documentation it says that I need to append the domain in the nam config file, but I don't see the benefit for this. In this config file I'm not validating server identity.&lt;/P&gt;&lt;P&gt;The thing is that I believe it's failing because PAC expired, but then when user logs in to windows the auth succeeds. I do have some cases that this is not working and anonymous always fails.&lt;/P&gt;&lt;P&gt;Is this normla behaviour? Do I have to create an anonymous named account in AD? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 05 Jan 2017 15:50:59 GMT</pubDate>
    <dc:creator>ahurtadove</dc:creator>
    <dc:date>2017-01-05T15:50:59Z</dc:date>
    <item>
      <title>EAP-FAST unprotected identity</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-fast-unprotected-identity/m-p/3598152#M536584</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi community!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was wondering, I'm using eap-fast with the unprotected identity as anonymous but I see that there are many failed authentications with this user in every authentication&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="anonymous.jpg" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/103475_anonymous.jpg" style="height: 168px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Reading documentation it says that I need to append the domain in the nam config file, but I don't see the benefit for this. In this config file I'm not validating server identity.&lt;/P&gt;&lt;P&gt;The thing is that I believe it's failing because PAC expired, but then when user logs in to windows the auth succeeds. I do have some cases that this is not working and anonymous always fails.&lt;/P&gt;&lt;P&gt;Is this normla behaviour? Do I have to create an anonymous named account in AD? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jan 2017 15:50:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-fast-unprotected-identity/m-p/3598152#M536584</guid>
      <dc:creator>ahurtadove</dc:creator>
      <dc:date>2017-01-05T15:50:59Z</dc:date>
    </item>
    <item>
      <title>Re: EAP-FAST unprotected identity</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-fast-unprotected-identity/m-p/3598153#M536585</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Antonio,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;EAP-FAST uses anonymous as outer identity. AFAIK this can be configured via Anyconnect NAM profile editor.&lt;/P&gt;&lt;P&gt;In ISE authencation policy, you have conditions that includes NAS port: Ethernet and Service type: Framed attribute. Usually this is enough for dot1x. Please look at the NAM logs from Windows logging to see what NAM is sending as outer and inner identity.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Finally please check in your NAM profile if service identity is configured. TLS happens within EAP-FAST as you might know.&lt;/P&gt;&lt;P&gt;Also check if the right inner protocol is selected in ISE UI from policy--&amp;gt;policy elements --&amp;gt;results--&amp;gt;allowed protocols.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope it helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Krishnan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jan 2017 18:50:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-fast-unprotected-identity/m-p/3598153#M536585</guid>
      <dc:creator>kthiruve</dc:creator>
      <dc:date>2017-01-05T18:50:23Z</dc:date>
    </item>
    <item>
      <title>Re: EAP-FAST unprotected identity</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-fast-unprotected-identity/m-p/3598154#M536586</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you Krishnan but I believe I did not explain myself clearly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I do have configured an outer identity and I know where to configure it. The thing that I don't understand is that "anonymous" is always a failed authentication as I don't have this user configured in any external or internal identity source. Outer identity is sent in clear text and I don't want to replace anonymous with [username] because I believe it will expose password.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So I wanted to know if this (anonymous failed auth) was normal behaviour or not. Also because in many devices I cannot see a domain computer authentication when user logs off windows, I wanted to know if this in any way was related.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Jan 2017 12:58:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-fast-unprotected-identity/m-p/3598154#M536586</guid>
      <dc:creator>ahurtadove</dc:creator>
      <dc:date>2017-01-06T12:58:59Z</dc:date>
    </item>
    <item>
      <title>Re: EAP-FAST unprotected identity</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-fast-unprotected-identity/m-p/3598155#M536587</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes you are correct. You dont want to expose the credential. To circumvent, you can configure host/anomymous to be part of authentication policy condition using RADIUS IETF attributes that will take care of it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Krishnan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Jan 2017 17:41:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-fast-unprotected-identity/m-p/3598155#M536587</guid>
      <dc:creator>kthiruve</dc:creator>
      <dc:date>2017-01-06T17:41:18Z</dc:date>
    </item>
    <item>
      <title>Re: EAP-FAST unprotected identity</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-fast-unprotected-identity/m-p/3682332#M536588</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We also have this issue, ISE tried to authenticate the outer identity instead on the inside one.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have also something weird, when authentication failed once, somethine Anyconnect or Switch keep the result of this authentication in cache and when we clear the authentication on the switch dot1x authentication failed instantly (The switch doesn't send a Radius authentication request).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any idea about that ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Mon, 06 Aug 2018 16:40:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-fast-unprotected-identity/m-p/3682332#M536588</guid>
      <dc:creator>Elbrabra</dc:creator>
      <dc:date>2018-08-06T16:40:28Z</dc:date>
    </item>
  </channel>
</rss>

