<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: mschap v2 in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/mschap-v2/m-p/4651472#M576211</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/199513"&gt;@ahollifield&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sorry&amp;nbsp; I could not make clear my question , sorry for my english . ,&amp;nbsp; I don't have plus licenses but still users can connect to the wifi using dot1x peap mschapv2&amp;nbsp; . Since users can connect their personal devices using base license , why do we need plus license&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Sat, 16 Jul 2022 04:36:32 GMT</pubDate>
    <dc:creator>bluesea2010</dc:creator>
    <dc:date>2022-07-16T04:36:32Z</dc:date>
    <item>
      <title>mschap v2</title>
      <link>https://community.cisco.com/t5/network-access-control/mschap-v2/m-p/4651098#M576181</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have the following&amp;nbsp; coprporate clients , windows&amp;nbsp; and ios ,I want to avoid mschap v2 , what is the alternative&amp;nbsp;&lt;/P&gt;&lt;P&gt;and byod clients are windows ios and android&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jul 2022 10:24:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mschap-v2/m-p/4651098#M576181</guid>
      <dc:creator>bluesea2010</dc:creator>
      <dc:date>2022-07-15T10:24:36Z</dc:date>
    </item>
    <item>
      <title>Re: mschap v2</title>
      <link>https://community.cisco.com/t5/network-access-control/mschap-v2/m-p/4651105#M576182</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/306956"&gt;@bluesea2010&lt;/a&gt; for corporate devices use certificates (EAP-TLS) issued by an internal Cetificate Authority via Group Policies.&lt;/P&gt;
&lt;P&gt;For BYOD devices usually you'd use the ISE internal CA.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jul 2022 10:33:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mschap-v2/m-p/4651105#M576182</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2022-07-15T10:33:19Z</dc:date>
    </item>
    <item>
      <title>Re: mschap v2</title>
      <link>https://community.cisco.com/t5/network-access-control/mschap-v2/m-p/4651109#M576183</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;So the alternative of mschapv2 is only eap-tls&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I&amp;nbsp; use ise internal&amp;nbsp; ca for byod , how&amp;nbsp; I can i deploy these&amp;nbsp; certificate in BYOD devices&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jul 2022 10:47:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mschap-v2/m-p/4651109#M576183</guid>
      <dc:creator>bluesea2010</dc:creator>
      <dc:date>2022-07-15T10:47:59Z</dc:date>
    </item>
    <item>
      <title>Re: mschap v2</title>
      <link>https://community.cisco.com/t5/network-access-control/mschap-v2/m-p/4651126#M576184</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/306956"&gt;@bluesea2010&lt;/a&gt; you can use the BYOD portal to enroll for certificates on the BYOD devices. &lt;A href="https://community.cisco.com/t5/security-knowledge-base/cisco-ise-byod-prescriptive-deployment-guide/ta-p/3641867#toc-hId-694972267" target="_blank"&gt;https://community.cisco.com/t5/security-knowledge-base/cisco-ise-byod-prescriptive-deployment-guide/ta-p/3641867#toc-hId-694972267&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jul 2022 11:12:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mschap-v2/m-p/4651126#M576184</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2022-07-15T11:12:11Z</dc:date>
    </item>
    <item>
      <title>Re: mschap v2</title>
      <link>https://community.cisco.com/t5/network-access-control/mschap-v2/m-p/4651251#M576190</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have only base license ,&amp;nbsp; does it require&amp;nbsp; profiling&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jul 2022 15:19:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mschap-v2/m-p/4651251#M576190</guid>
      <dc:creator>bluesea2010</dc:creator>
      <dc:date>2022-07-15T15:19:23Z</dc:date>
    </item>
    <item>
      <title>Re: mschap v2</title>
      <link>https://community.cisco.com/t5/network-access-control/mschap-v2/m-p/4651281#M576191</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/306956"&gt;@bluesea2010&lt;/a&gt; you would need Plus licensing if you use BYOD. &lt;BR /&gt;Profiling is not a requirement for BYOD or using certificates for 802.1x authentication if that was your question.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-7/admin_guide/b_ise_27_admin_guide/m_ise_man_license.html" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/2-7/admin_guide/b_ise_27_admin_guide/m_ise_man_license.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jul 2022 16:00:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mschap-v2/m-p/4651281#M576191</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2022-07-15T16:00:20Z</dc:date>
    </item>
    <item>
      <title>Re: mschap v2</title>
      <link>https://community.cisco.com/t5/network-access-control/mschap-v2/m-p/4651297#M576194</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I could see that BYOD need plus licensing , but in my case I have&amp;nbsp; only base license .&amp;nbsp;&lt;/P&gt;&lt;P&gt;In that case what will I miss in terms of BYOD . (Currently&amp;nbsp; non corporate devices are connecting&amp;nbsp; to the corporate wifi , Can I call this as byod ? )&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jul 2022 16:30:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mschap-v2/m-p/4651297#M576194</guid>
      <dc:creator>bluesea2010</dc:creator>
      <dc:date>2022-07-15T16:30:21Z</dc:date>
    </item>
    <item>
      <title>Re: mschap v2</title>
      <link>https://community.cisco.com/t5/network-access-control/mschap-v2/m-p/4651303#M576195</link>
      <description>&lt;P&gt;Yes, this is precisely the use-case for BYOD.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jul 2022 16:48:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mschap-v2/m-p/4651303#M576195</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2022-07-15T16:48:48Z</dc:date>
    </item>
    <item>
      <title>Re: mschap v2</title>
      <link>https://community.cisco.com/t5/network-access-control/mschap-v2/m-p/4651314#M576199</link>
      <description>&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;My question why byod&amp;nbsp; need plus licensing , I&amp;nbsp; have only base license but still I am allowing&amp;nbsp; non corporate device. I mean still users can connect their personal devices&amp;nbsp; &amp;nbsp;using dot1x&amp;nbsp; (peap mschapv2)&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jul 2022 17:13:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mschap-v2/m-p/4651314#M576199</guid>
      <dc:creator>bluesea2010</dc:creator>
      <dc:date>2022-07-15T17:13:14Z</dc:date>
    </item>
    <item>
      <title>Re: mschap v2</title>
      <link>https://community.cisco.com/t5/network-access-control/mschap-v2/m-p/4651328#M576204</link>
      <description>&lt;P&gt;If you want to use BYOD, ISE requires Plus/Advantage licensing per endpoint.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jul 2022 17:47:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mschap-v2/m-p/4651328#M576204</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2022-07-15T17:47:45Z</dc:date>
    </item>
    <item>
      <title>Re: mschap v2</title>
      <link>https://community.cisco.com/t5/network-access-control/mschap-v2/m-p/4651472#M576211</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/199513"&gt;@ahollifield&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sorry&amp;nbsp; I could not make clear my question , sorry for my english . ,&amp;nbsp; I don't have plus licenses but still users can connect to the wifi using dot1x peap mschapv2&amp;nbsp; . Since users can connect their personal devices using base license , why do we need plus license&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Sat, 16 Jul 2022 04:36:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mschap-v2/m-p/4651472#M576211</guid>
      <dc:creator>bluesea2010</dc:creator>
      <dc:date>2022-07-16T04:36:32Z</dc:date>
    </item>
    <item>
      <title>Re: mschap v2</title>
      <link>https://community.cisco.com/t5/network-access-control/mschap-v2/m-p/4651549#M576212</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/306956"&gt;@bluesea2010&lt;/a&gt; yes the users could just enter their username/password (mschapv2) but that's considered insecure.&lt;/P&gt;
&lt;P&gt;For a BYOD environment you can onboard the end users personal endpoints via the ISE BYOD portal and provision a CA signed endpoint certificate as well as configure the network interface and OS native supplicant to utilise this certificate for network access. This functionality requires an ISE Plus license.&lt;/P&gt;</description>
      <pubDate>Sat, 16 Jul 2022 15:59:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/mschap-v2/m-p/4651549#M576212</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2022-07-16T15:59:08Z</dc:date>
    </item>
  </channel>
</rss>

