<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ISE 2.1 - TLS 1.2 in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-2-1-tls-1-2/m-p/4065437#M559584</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;FONT color="#008000"&gt;&amp;nbsp;Yes ,&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
    <pubDate>Tue, 14 Apr 2020 12:56:47 GMT</pubDate>
    <dc:creator>Mark Elsen</dc:creator>
    <dc:date>2020-04-14T12:56:47Z</dc:date>
    <item>
      <title>Cisco ISE 2.1 - TLS 1.2</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-2-1-tls-1-2/m-p/4065346#M559578</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have Cisco ISE 2.1 implemented and after I ran a vulnerability scan, I found that ISE is using TLS 1.0 and TLS 1.1. I pretend to disable both and enable TLS 1.2, but before I proceed, I have a few questions:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. Is TLS 1.2 supported on Cisco ISE 2.1?&lt;/P&gt;&lt;P&gt;2. If yes, can I only have TLS 1.2 running?&lt;/P&gt;&lt;P&gt;3. To enable TLS 1.2, I only need to uncheck 'Allow TLS 1.0' and 'Allow TLS 1.1' on &lt;STRONG&gt;Administration &amp;gt; System &amp;gt; Settings &amp;gt; Security Settings&lt;/STRONG&gt;?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your help &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Apr 2020 10:19:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-2-1-tls-1-2/m-p/4065346#M559578</guid>
      <dc:creator>PedroDias1994</dc:creator>
      <dc:date>2020-04-14T10:19:26Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 2.1 - TLS 1.2</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-2-1-tls-1-2/m-p/4065349#M559579</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- From the 2.1 Release Notes it seems that TLS 1.2 is supported :&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-1/release_notes/ise21_rn.html#pgfId-627732" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/2-1/release_notes/ise21_rn.html#pgfId-627732&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Apr 2020 10:23:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-2-1-tls-1-2/m-p/4065349#M559579</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2020-04-14T10:23:53Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 2.1 - TLS 1.2</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-2-1-tls-1-2/m-p/4065408#M559580</link>
      <description>Adding additional info:&lt;BR /&gt;Not sure what types of hosts you manage in your environment, but this may potentially help you if you face issues once making changes:&lt;BR /&gt;&lt;BR /&gt;Change tls version on windows host:&lt;BR /&gt;&lt;BR /&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\RasMan\PPP\EAP\13&lt;BR /&gt;&lt;BR /&gt;TLS version	DWORD value&lt;BR /&gt;TLS 1.0		0xC0&lt;BR /&gt;TLS 1.1		0x300&lt;BR /&gt;TLS 1.2 		0xC00&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://support.microsoft.com/en-us/help/3121002/windows-10-devices-can-t-connect-to-an-802-1x-environment" target="_blank"&gt;https://support.microsoft.com/en-us/help/3121002/windows-10-devices-can-t-connect-to-an-802-1x-environment&lt;/A&gt;. HTH!&lt;BR /&gt;</description>
      <pubDate>Tue, 14 Apr 2020 12:12:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-2-1-tls-1-2/m-p/4065408#M559580</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2020-04-14T12:12:25Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 2.1 - TLS 1.2</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-2-1-tls-1-2/m-p/4065436#M559583</link>
      <description>&lt;P&gt;And it is possible to run TLS 1.2 with TLS 1.0 and TLS 1.1 disabled?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can't find this information anywhere...&lt;/P&gt;</description>
      <pubDate>Tue, 14 Apr 2020 12:54:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-2-1-tls-1-2/m-p/4065436#M559583</guid>
      <dc:creator>PedroDias1994</dc:creator>
      <dc:date>2020-04-14T12:54:47Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 2.1 - TLS 1.2</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-2-1-tls-1-2/m-p/4065437#M559584</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;FONT color="#008000"&gt;&amp;nbsp;Yes ,&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Apr 2020 12:56:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-2-1-tls-1-2/m-p/4065437#M559584</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2020-04-14T12:56:47Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 2.1 - TLS 1.2</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-2-1-tls-1-2/m-p/4065438#M559585</link>
      <description>&lt;P&gt;Thank you for the information!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have Windows 10 devices in our tech park, so it is good to know &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Apr 2020 12:57:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-2-1-tls-1-2/m-p/4065438#M559585</guid>
      <dc:creator>PedroDias1994</dc:creator>
      <dc:date>2020-04-14T12:57:41Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 2.1 - TLS 1.2</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-2-1-tls-1-2/m-p/4065933#M559610</link>
      <description>&lt;P&gt;Another important thing to note before disabling TLS 1.0 and 1.1 support in ISE... as noted in the Security Settings section in ISE, disabling support for those legacy TLS ciphers affects the following functions:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Cisco ISE is configured as EAP server&lt;/LI&gt;
&lt;LI&gt;Cisco ISE downloads CRL from HTTPS or secure LDAP server&lt;/LI&gt;
&lt;LI&gt;Cisco ISE is configured as secure syslog client&lt;/LI&gt;
&lt;LI&gt;Cisco ISE is configured as secure LDAP client&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;If you use any of these functions and the associated systems use legacy TLS ciphers, disabling the legacy TLS cipher support in ISE will break them.&lt;/P&gt;
&lt;P&gt;I have seen this first-hand with a customer that decided to disable support for legacy ciphers (TLS 1.1, SHA-1, etc) before verifying that their external systems (like the CA that signed their client certificates) did not use them. Disabling the legacy ciphers in ISE resulted in mass outages due to their 802.1x client authentication failing.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Apr 2020 00:11:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-2-1-tls-1-2/m-p/4065933#M559610</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2020-04-15T00:11:08Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 2.1 - TLS 1.2</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-2-1-tls-1-2/m-p/4288900#M565385</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/388087"&gt;@Greg Gibbs&lt;/a&gt;&amp;nbsp;Is rolling back as simple as enabling the TLS 1.0 and 1.1 check boxes again?&amp;nbsp; I keep getting EAP(PEAP) issues on my Win10 machines since update 1909 where MS monkeyed with 802.1x again.&amp;nbsp; I'm using the reg key to force TLS 1.2 that Mike referenced to get some of them working but it's not consistent.&amp;nbsp; Would disabling TLS 1.0/1.1 force ISE to use 1.2 and in combination with that reg key solve my issue?&amp;nbsp; We use AD for LDAP and a publicly signed CA multi-use cert.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Feb 2021 18:31:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-2-1-tls-1-2/m-p/4288900#M565385</guid>
      <dc:creator>pnowikow</dc:creator>
      <dc:date>2021-02-09T18:31:36Z</dc:date>
    </item>
  </channel>
</rss>

