<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 802.1x certificate based authentication on Cisco 3850. in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/802-1x-certificate-based-authentication-on-cisco-3850/m-p/3393085#M548563</link>
    <description>&lt;P&gt;ACS 5.5 has reached its last date of support, per&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/products/collateral/security/secure-access-control-system/eos-eol-notice-c51-733079.html" target="_blank"&gt;End-of-Sale and End-of-Life Announcement for the Cisco Secure Access Control System 5.5&lt;/A&gt;. ACS 5.8 has reached End of Sale and is only a couple of months away until the end of software maintenance. Thus, please plan on migrating to ISE by reviewing the info&amp;nbsp;@&amp;nbsp;&lt;A href="http://cs.co/acstoise" target="_blank"&gt;http://cs.co/acstoise&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In order for an endpoint to perform certificate-based 802.1X, the endpoint needs an identity/personal certificate suitable for EAP-TLS client authentication and the 802.1X supplicant on the endpoint OS configured to do so.&amp;nbsp;&lt;A href="https://communities.cisco.com/docs/DOC-64012#jive_content_id_Certificates__Private_Key_Infrastructure_PKI" target="_blank"&gt;Certificates / Private Key Infrastructure (PKI)&lt;/A&gt;&amp;nbsp;has several materials for reference.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 03 Jun 2018 03:19:23 GMT</pubDate>
    <dc:creator>hslai</dc:creator>
    <dc:date>2018-06-03T03:19:23Z</dc:date>
    <item>
      <title>802.1x certificate based authentication on Cisco 3850.</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-certificate-based-authentication-on-cisco-3850/m-p/3393007#M548561</link>
      <description>&lt;P&gt;&lt;FONT face="comic sans ms,sans-serif" size="3"&gt;Folks,&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="comic sans ms,sans-serif" size="3"&gt;We are looking at some help on certificate based authentication on our Cisco 3850 for LAN based authentication. The authentication feature is planned to be rolled out only on ports which are in the user VLAN and for other ports we would use MAC based authentication. We are going to authenticate against ACS 5.5.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="comic sans ms,sans-serif" size="3"&gt;Any suggestions on proceeding with this. I had received some solutions initially but all we see on the ACS is some MAC address trying to authenticate. The does not succeed.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="comic sans ms,sans-serif" size="3"&gt;Please provide me with some suggestions on getting this going.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="comic sans ms,sans-serif" size="3"&gt;Regards,&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="comic sans ms,sans-serif" size="3"&gt;N!!&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 18:57:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-certificate-based-authentication-on-cisco-3850/m-p/3393007#M548561</guid>
      <dc:creator>network_geek1979</dc:creator>
      <dc:date>2020-02-21T18:57:19Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x certificate based authentication on Cisco 3850.</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-certificate-based-authentication-on-cisco-3850/m-p/3393085#M548563</link>
      <description>&lt;P&gt;ACS 5.5 has reached its last date of support, per&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/products/collateral/security/secure-access-control-system/eos-eol-notice-c51-733079.html" target="_blank"&gt;End-of-Sale and End-of-Life Announcement for the Cisco Secure Access Control System 5.5&lt;/A&gt;. ACS 5.8 has reached End of Sale and is only a couple of months away until the end of software maintenance. Thus, please plan on migrating to ISE by reviewing the info&amp;nbsp;@&amp;nbsp;&lt;A href="http://cs.co/acstoise" target="_blank"&gt;http://cs.co/acstoise&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In order for an endpoint to perform certificate-based 802.1X, the endpoint needs an identity/personal certificate suitable for EAP-TLS client authentication and the 802.1X supplicant on the endpoint OS configured to do so.&amp;nbsp;&lt;A href="https://communities.cisco.com/docs/DOC-64012#jive_content_id_Certificates__Private_Key_Infrastructure_PKI" target="_blank"&gt;Certificates / Private Key Infrastructure (PKI)&lt;/A&gt;&amp;nbsp;has several materials for reference.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 03 Jun 2018 03:19:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-certificate-based-authentication-on-cisco-3850/m-p/3393085#M548563</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-06-03T03:19:23Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x certificate based authentication on Cisco 3850.</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-certificate-based-authentication-on-cisco-3850/m-p/3393146#M548565</link>
      <description>&lt;P&gt;&lt;FONT face="comic sans ms,sans-serif"&gt;Yes, we are aware on the EoL for the Cisco ACS. However, the replacement plans are futuristic. As an immediate need I actually need to get in some security on my existing infrastructure so looking at help in that.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="comic sans ms,sans-serif"&gt;Could someone please provide some guidelines on 802.1x security with use of certificates on Cisco 3850 switches with the ACS please?&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 03 Jun 2018 07:43:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-certificate-based-authentication-on-cisco-3850/m-p/3393146#M548565</guid>
      <dc:creator>network_geek1979</dc:creator>
      <dc:date>2018-06-03T07:43:02Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x certificate based authentication on Cisco 3850.</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-certificate-based-authentication-on-cisco-3850/m-p/3393213#M548567</link>
      <description>&lt;P&gt;The configuration on the client side is the same for ISE and ACS. For ACS configuration, please check out the following:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://supportforums.cisco.com/t5/aaa-identity-and-nac/802-1x-eap-tls-for-wired-users-with-acs-5-5/td-p/2544095" target="_blank"&gt;Solved: 802.1x EAP-TLS for wired users with ACS... - Cisco Support Community&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Lab Minutes has several videos on ACS —&amp;gt; &lt;A href="http://www.labminutes.com/video/sec/ACS" target="_blank"&gt;Video: Security - ACS | Lab Minutes&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 03 Jun 2018 14:02:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-certificate-based-authentication-on-cisco-3850/m-p/3393213#M548567</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-06-03T14:02:50Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x certificate based authentication on Cisco 3850.</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-certificate-based-authentication-on-cisco-3850/m-p/3835673#M548569</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;May i knw whether "aaa authorization network" cmd will affect anything currently in the switch like telnet, ssh,etc? Do i really need these 2 cmd below for 802.1x authentication with radius server? or "aaa authentication 802.1x..." is sufficient?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;awitch(Config)# &lt;STRONG&gt;aaa authorization network default group radius&lt;/STRONG&gt;&lt;BR /&gt;Switch(Config)# &lt;STRONG&gt;aaa accounting dot1x default start-stop group radius&lt;/STRONG&gt;&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Apr 2019 06:32:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-certificate-based-authentication-on-cisco-3850/m-p/3835673#M548569</guid>
      <dc:creator>getaway51</dc:creator>
      <dc:date>2019-04-10T06:32:49Z</dc:date>
    </item>
  </channel>
</rss>

