<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Authenticate Redhat Linux ssh login using radius on Cisco ISE in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/authenticate-redhat-linux-ssh-login-using-radius-on-cisco-ise/m-p/4648408#M576073</link>
    <description>&lt;P&gt;So PEAP is a form on EAP.&amp;nbsp; EAP is not in play here since there isn't an endpoint or supplicant configuration.&amp;nbsp; It is just the text-based username/password entered into the SSH attempt on the Linux machine.&amp;nbsp; Is your Linux machine capable of encapsulating that plain text admin/password into a PEAP packet?&lt;/P&gt;</description>
    <pubDate>Mon, 11 Jul 2022 17:39:08 GMT</pubDate>
    <dc:creator>ahollifield</dc:creator>
    <dc:date>2022-07-11T17:39:08Z</dc:date>
    <item>
      <title>Authenticate Redhat Linux ssh login using radius on Cisco ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/authenticate-redhat-linux-ssh-login-using-radius-on-cisco-ise/m-p/4648396#M576067</link>
      <description>&lt;P&gt;I would like to using my Cisco ISE 3.1 patch 3 to authenticate linux ssh login via Cisco ISE with radius authentication.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have it working with my Redhat Linux and Cisco ISE 3.1 patch-3 using radius PAP authentication.&amp;nbsp; However, PAP is not a secure method and I would like to implement PEAP/msCHAPv2.&amp;nbsp; However, I have not been able to find any useful documentation on how to implement this.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Has anyone done this before?&amp;nbsp; If so, can you share your knowledge?&amp;nbsp; TIA.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jul 2022 17:15:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authenticate-redhat-linux-ssh-login-using-radius-on-cisco-ise/m-p/4648396#M576067</guid>
      <dc:creator>adamscottmaster2013</dc:creator>
      <dc:date>2022-07-11T17:15:26Z</dc:date>
    </item>
    <item>
      <title>Re: Authenticate Redhat Linux ssh login using radius on Cisco ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/authenticate-redhat-linux-ssh-login-using-radius-on-cisco-ise/m-p/4648408#M576073</link>
      <description>&lt;P&gt;So PEAP is a form on EAP.&amp;nbsp; EAP is not in play here since there isn't an endpoint or supplicant configuration.&amp;nbsp; It is just the text-based username/password entered into the SSH attempt on the Linux machine.&amp;nbsp; Is your Linux machine capable of encapsulating that plain text admin/password into a PEAP packet?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jul 2022 17:39:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authenticate-redhat-linux-ssh-login-using-radius-on-cisco-ise/m-p/4648408#M576073</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2022-07-11T17:39:08Z</dc:date>
    </item>
    <item>
      <title>Re: Authenticate Redhat Linux ssh login using radius on Cisco ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/authenticate-redhat-linux-ssh-login-using-radius-on-cisco-ise/m-p/4648409#M576074</link>
      <description>&lt;P&gt;I have successfully configured my redhat Linux to use radius authentication via Cisco ISE but only with PAP.&amp;nbsp; I would like to do it via msCHAPv2 or PEAP.&amp;nbsp; I've successfully configured my PaloAlto firewalls to authtenticate via ssh and https via PEAP/msCHAPv2.&amp;nbsp; I want to do the same thing on my redhat linux machine.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What make you think EAP is not in play here? yes, it is a text based but the authentication piece is much more complex than you think.&lt;/P&gt;&lt;P&gt;I know PEAP/msCHAPv2 is definitely doable, just just don't know how to go about configuring it.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jul 2022 17:46:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authenticate-redhat-linux-ssh-login-using-radius-on-cisco-ise/m-p/4648409#M576074</guid>
      <dc:creator>adamscottmaster2013</dc:creator>
      <dc:date>2022-07-11T17:46:19Z</dc:date>
    </item>
    <item>
      <title>Re: Authenticate Redhat Linux ssh login using radius on Cisco ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/authenticate-redhat-linux-ssh-login-using-radius-on-cisco-ise/m-p/4649530#M576129</link>
      <description>&lt;P&gt;Please provide some screenshots of the configurations you did on the redhat Linux and PaltoAlto firewalls for the SSH access so we may understand better.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jul 2022 13:39:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authenticate-redhat-linux-ssh-login-using-radius-on-cisco-ise/m-p/4649530#M576129</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2022-07-13T13:39:09Z</dc:date>
    </item>
    <item>
      <title>Re: Authenticate Redhat Linux ssh login using radius on Cisco ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/authenticate-redhat-linux-ssh-login-using-radius-on-cisco-ise/m-p/4650477#M576161</link>
      <description>&lt;P&gt;There is no screenshot on the linux.&amp;nbsp; It is all CLI based.&amp;nbsp; You can easily find it on the Internet for PAP.&amp;nbsp; For PaloAlto firewalls, it is very simple, I just changed it from PAP to "PEAP mschapv2" with "anonymous" on the outer shell.&amp;nbsp; There is nothing to it.&lt;/P&gt;&lt;P&gt;For linux:&amp;nbsp; &lt;A href="https://unix.stackexchange.com/questions/202233/simple-radius-authentication" target="_blank"&gt;https://unix.stackexchange.com/questions/202233/simple-radius-authentication&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i did that but there doesn't seem to be documentation to setup msCHAP-v2&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jul 2022 16:45:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authenticate-redhat-linux-ssh-login-using-radius-on-cisco-ise/m-p/4650477#M576161</guid>
      <dc:creator>adamscottmaster2013</dc:creator>
      <dc:date>2022-07-14T16:45:11Z</dc:date>
    </item>
    <item>
      <title>Re: Authenticate Redhat Linux ssh login using radius on Cisco ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/authenticate-redhat-linux-ssh-login-using-radius-on-cisco-ise/m-p/4651603#M576213</link>
      <description>&lt;P&gt;It's possible that Palo Alto firewall has a special client implementation for such communication option with a RADIUS AAA server.&lt;/P&gt;
&lt;P&gt;For Linux, you would need either find one with more protocol support or write one yourself.&lt;/P&gt;</description>
      <pubDate>Sat, 16 Jul 2022 23:40:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authenticate-redhat-linux-ssh-login-using-radius-on-cisco-ise/m-p/4651603#M576213</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2022-07-16T23:40:43Z</dc:date>
    </item>
    <item>
      <title>Re: Authenticate Redhat Linux ssh login using radius on Cisco ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/authenticate-redhat-linux-ssh-login-using-radius-on-cisco-ise/m-p/4769526#M579672</link>
      <description>&lt;P&gt;May please write how you configure ISE Radius for Linux?&lt;/P&gt;</description>
      <pubDate>Mon, 06 Feb 2023 11:35:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authenticate-redhat-linux-ssh-login-using-radius-on-cisco-ise/m-p/4769526#M579672</guid>
      <dc:creator>netbfc</dc:creator>
      <dc:date>2023-02-06T11:35:36Z</dc:date>
    </item>
    <item>
      <title>Re: Authenticate Redhat Linux ssh login using radius on Cisco ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/authenticate-redhat-linux-ssh-login-using-radius-on-cisco-ise/m-p/4885891#M582882</link>
      <description>&lt;P&gt;Hello, how did you do it? I am trying with Rocky 8.8 (which is more or less like RHEL 8), but ssh with ISE-radius is not working.&lt;BR /&gt;It's ok when I just do a radtest from Linux-server, but not with real ssh connection (wrong user name or password).&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;It seems that Linux needs to have the user (without password) also local to authenticate him against Radius?&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;Which is not very comfortable.&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jul 2023 09:48:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authenticate-redhat-linux-ssh-login-using-radius-on-cisco-ise/m-p/4885891#M582882</guid>
      <dc:creator>chris-doro</dc:creator>
      <dc:date>2023-07-17T09:48:22Z</dc:date>
    </item>
    <item>
      <title>Re: Authenticate Redhat Linux ssh login using radius on Cisco ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/authenticate-redhat-linux-ssh-login-using-radius-on-cisco-ise/m-p/4886021#M582889</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1472553"&gt;@chris-doro&lt;/a&gt;:&amp;nbsp; Please send me a private message and I will send you the instruction on how to do this.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jul 2023 13:08:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authenticate-redhat-linux-ssh-login-using-radius-on-cisco-ise/m-p/4886021#M582889</guid>
      <dc:creator>adamscottmaster2013</dc:creator>
      <dc:date>2023-07-17T13:08:34Z</dc:date>
    </item>
    <item>
      <title>Re: Authenticate Redhat Linux ssh login using radius on Cisco ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/authenticate-redhat-linux-ssh-login-using-radius-on-cisco-ise/m-p/4897824#M583239</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1191533"&gt;@adamscottmaster2013&lt;/a&gt;were you able to get the authentication working with msCHAP-v2?&lt;/P&gt;</description>
      <pubDate>Wed, 02 Aug 2023 19:17:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authenticate-redhat-linux-ssh-login-using-radius-on-cisco-ise/m-p/4897824#M583239</guid>
      <dc:creator>franksilva</dc:creator>
      <dc:date>2023-08-02T19:17:05Z</dc:date>
    </item>
  </channel>
</rss>

