<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PEAP outer identity in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/peap-outer-identity/m-p/3298614#M550917</link>
    <description>You are right. ISE will need make sure that username attribute is present&lt;BR /&gt;and at this early stage ISE won't be considering the actual username. I&lt;BR /&gt;think Marvin Provided better explanation than myself. For mobile devices&lt;BR /&gt;you can tune this using MDM and push common profile to allow phones. For&lt;BR /&gt;windows OS, you can configure the supplicant parameters using group policy&lt;BR /&gt;(including name anonymous) and push it to users.&lt;BR /&gt;</description>
    <pubDate>Tue, 19 Dec 2017 13:10:08 GMT</pubDate>
    <dc:creator>Mohammed al Baqari</dc:creator>
    <dc:date>2017-12-19T13:10:08Z</dc:date>
    <item>
      <title>PEAP outer identity</title>
      <link>https://community.cisco.com/t5/network-access-control/peap-outer-identity/m-p/3298305#M550897</link>
      <description>&lt;P&gt;I am new to security and testing few stuff with authentication.&lt;/P&gt;
&lt;P&gt;I was doing some captures and noticed that although I am using PEAP but the outer identity still show my actual username. In my understand this should have been "anonymous", am I missing something here ??&lt;/P&gt;
&lt;P&gt;I also know that this is a configurable parameter, I am using iPhone 7 iOS11.2.1, anyone know how can I configure outer identity manually for PEAP ??&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;see enclosed capture.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 18:41:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/peap-outer-identity/m-p/3298305#M550897</guid>
      <dc:creator>Ambuj M</dc:creator>
      <dc:date>2020-02-21T18:41:52Z</dc:date>
    </item>
    <item>
      <title>Re: PEAP outer identity</title>
      <link>https://community.cisco.com/t5/network-access-control/peap-outer-identity/m-p/3298374#M550901</link>
      <description>It won't be anonymous. NAD will request for identity to encapsulate in&lt;BR /&gt;username Radius attribute and send it to ISE. Based on this ISE will&lt;BR /&gt;perform authentication lookup and in your case should match a rule which&lt;BR /&gt;allows PEAP authentication.&lt;BR /&gt;&lt;BR /&gt;&amp;gt;From their PEAP outter authentication starts. Before this, ISE needs to&lt;BR /&gt;verify what authentication methods are allowed based on initial attributes&lt;BR /&gt;received from client and username is one of the mandatory attributes.&lt;BR /&gt;&lt;BR /&gt;If you debug radius authentication on the switch, you will see that&lt;BR /&gt;username received from EAP is sent as radius attribute to ISE&lt;BR /&gt;</description>
      <pubDate>Tue, 19 Dec 2017 03:48:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/peap-outer-identity/m-p/3298374#M550901</guid>
      <dc:creator>Mohammed al Baqari</dc:creator>
      <dc:date>2017-12-19T03:48:48Z</dc:date>
    </item>
    <item>
      <title>Re: PEAP outer identity</title>
      <link>https://community.cisco.com/t5/network-access-control/peap-outer-identity/m-p/3298429#M550905</link>
      <description>&lt;P&gt;Hi Ambuj,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I believe you are seeing a default behavior on iOS. I agree it is a bit counter-intuitive since the name of the protocol stands for &lt;STRONG&gt;Protected&lt;/STRONG&gt; Extensible Authentication Protocol. You are giving up some protection by putting the inner method identity in clear text in the outer method wrapper.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When we setup Anyconnect NAM with PEAP, we have the option in the Anyconnect NAM profile editor of choosing the unprotected (outer) and protected (inner) identity pattern. In that case, the defaults are anonymous and [username] as shown here:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PEAP outer identity in NAM Profile editor.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/4924iB58F98633159937E/image-size/large?v=v2&amp;amp;px=999" role="button" title="PEAP outer identity in NAM Profile editor.PNG" alt="PEAP outer identity in NAM Profile editor.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When doing the equivalent setup in iOS there is no option to do that directly. I believe if you use the Apple Configurator 2 program that you can change this setting. I don't have a Mac to try it on but here is the documentation reference:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://help.apple.com/configurator/mac/2.6/#/apdF985515F-9344-46EE-BAC5-D60ABBF1C1D1" target="_blank"&gt;https://help.apple.com/configurator/mac/2.6/#/apdF985515F-9344-46EE-BAC5-D60ABBF1C1D1&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/326176"&gt;@George Stefanick&lt;/a&gt;&amp;nbsp;also has a blog posting with some screen shots here:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="http://community.arubanetworks.com/t5/Technology-Blog/Apple-TV-EAP-PEAP-Configuration-Clock-Fix/ba-p/143391" target="_blank"&gt;http://community.arubanetworks.com/t5/Technology-Blog/Apple-TV-EAP-PEAP-Configuration-Clock-Fix/ba-p/143391&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As you can see in his Section 6, we can set the outer identity to any arbitrary value using that tool.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Dec 2017 06:11:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/peap-outer-identity/m-p/3298429#M550905</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-12-19T06:11:50Z</dc:date>
    </item>
    <item>
      <title>Re: PEAP outer identity</title>
      <link>https://community.cisco.com/t5/network-access-control/peap-outer-identity/m-p/3298551#M550909</link>
      <description>Thanks Marvin, this helps.</description>
      <pubDate>Tue, 19 Dec 2017 11:11:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/peap-outer-identity/m-p/3298551#M550909</guid>
      <dc:creator>Ambuj M</dc:creator>
      <dc:date>2017-12-19T11:11:56Z</dc:date>
    </item>
    <item>
      <title>Re: PEAP outer identity</title>
      <link>https://community.cisco.com/t5/network-access-control/peap-outer-identity/m-p/3298555#M550911</link>
      <description>&lt;P&gt;Thanks for the reply Mohammed, but I am using wireless, don’t you think if that’s the way it works then it’s a vulnerability, anyone can capture this conversation over air and know the actual username. Moreover even if ISE needs to determine allowed protocol, it should still be able to do it with an anonymous username. The only attribute it will be looking for is a username present I believe.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Dec 2017 11:20:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/peap-outer-identity/m-p/3298555#M550911</guid>
      <dc:creator>Ambuj M</dc:creator>
      <dc:date>2017-12-19T11:20:12Z</dc:date>
    </item>
    <item>
      <title>Re: PEAP outer identity</title>
      <link>https://community.cisco.com/t5/network-access-control/peap-outer-identity/m-p/3298614#M550917</link>
      <description>You are right. ISE will need make sure that username attribute is present&lt;BR /&gt;and at this early stage ISE won't be considering the actual username. I&lt;BR /&gt;think Marvin Provided better explanation than myself. For mobile devices&lt;BR /&gt;you can tune this using MDM and push common profile to allow phones. For&lt;BR /&gt;windows OS, you can configure the supplicant parameters using group policy&lt;BR /&gt;(including name anonymous) and push it to users.&lt;BR /&gt;</description>
      <pubDate>Tue, 19 Dec 2017 13:10:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/peap-outer-identity/m-p/3298614#M550917</guid>
      <dc:creator>Mohammed al Baqari</dc:creator>
      <dc:date>2017-12-19T13:10:08Z</dc:date>
    </item>
    <item>
      <title>Re: PEAP outer identity</title>
      <link>https://community.cisco.com/t5/network-access-control/peap-outer-identity/m-p/3298721#M550919</link>
      <description>Thanks for clarification</description>
      <pubDate>Tue, 19 Dec 2017 15:59:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/peap-outer-identity/m-p/3298721#M550919</guid>
      <dc:creator>Ambuj M</dc:creator>
      <dc:date>2017-12-19T15:59:29Z</dc:date>
    </item>
  </channel>
</rss>

