<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE - EAP Chaining (TLS vs MSCHAP) in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-eap-chaining-tls-vs-mschap/m-p/3372212#M549175</link>
    <description>&lt;P&gt;That sounds reasonable to me.&amp;nbsp; Thanks so much for the input and advice!&lt;/P&gt;</description>
    <pubDate>Tue, 24 Apr 2018 20:05:39 GMT</pubDate>
    <dc:creator>mitchell helton</dc:creator>
    <dc:date>2018-04-24T20:05:39Z</dc:date>
    <item>
      <title>ISE - EAP Chaining (TLS vs MSCHAP)</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-eap-chaining-tls-vs-mschap/m-p/3371241#M549169</link>
      <description>&lt;P&gt;Good morning!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm having a tough time wrapping my brain around something, and hope you experts can help.&amp;nbsp; I also hope this isn't too vague of a question, and if it is, I can give specifics around why I'm asking.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If I'm deploying user certificates via AD/GPO, is there any value in using certificates (EAP-TLS) for user authentication?&amp;nbsp; If someone captures a username/password,&amp;nbsp;once they login as that user the certificate will be deployed to them any way.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Am I missing something?&amp;nbsp; I had originally wanted to do EAP chaining with TLS for user and machine and now I'm wondering if using TLS for machine and MSCHAPv2 for the user makes more sense.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So, I guess my question is, what value does TLS for user authentication have within chaining as opposed to MSCHAPv2?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;mitch&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 18:54:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-eap-chaining-tls-vs-mschap/m-p/3371241#M549169</guid>
      <dc:creator>mitchell helton</dc:creator>
      <dc:date>2020-02-21T18:54:14Z</dc:date>
    </item>
    <item>
      <title>Re: ISE - EAP Chaining (TLS vs MSCHAP)</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-eap-chaining-tls-vs-mschap/m-p/3371878#M549171</link>
      <description>Hi,&lt;BR /&gt;Using User Certificates for authentication in some environments can be a pain E.g. multiple users logging in and out of the same computer.&lt;BR /&gt;&lt;BR /&gt;I don't see any issue using EAP Chaining (EAP-TLS for Computers and PEAP/MSCHAPv2 for User authentication). As long as the ISE rule is configured specifically = if User and Computer passed authenticiation then permit. If computer authentication fails but user authentication passes, either deny or limit the access with a DACL/TrustSec SGT etc.&lt;BR /&gt;&lt;BR /&gt;HTH&lt;BR /&gt;</description>
      <pubDate>Tue, 24 Apr 2018 13:26:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-eap-chaining-tls-vs-mschap/m-p/3371878#M549171</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2018-04-24T13:26:37Z</dc:date>
    </item>
    <item>
      <title>Re: ISE - EAP Chaining (TLS vs MSCHAP)</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-eap-chaining-tls-vs-mschap/m-p/3372212#M549175</link>
      <description>&lt;P&gt;That sounds reasonable to me.&amp;nbsp; Thanks so much for the input and advice!&lt;/P&gt;</description>
      <pubDate>Tue, 24 Apr 2018 20:05:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-eap-chaining-tls-vs-mschap/m-p/3372212#M549175</guid>
      <dc:creator>mitchell helton</dc:creator>
      <dc:date>2018-04-24T20:05:39Z</dc:date>
    </item>
  </channel>
</rss>

