<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: EAP‑TLS 802.1X Rollouts on Cisco ISE in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/eap-tls-802-1x-rollouts-on-cisco-ise/m-p/5322147#M597858</link>
    <description>&lt;P&gt;Wireless is the best place to start with 802.1X.&lt;/P&gt;</description>
    <pubDate>Tue, 19 Aug 2025 22:29:13 GMT</pubDate>
    <dc:creator>Arne Bier</dc:creator>
    <dc:date>2025-08-19T22:29:13Z</dc:date>
    <item>
      <title>EAP‑TLS 802.1X Rollouts on Cisco ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-tls-802-1x-rollouts-on-cisco-ise/m-p/5321540#M597818</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi Mates,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We’re planning to roll out &lt;STRONG&gt;EAP‑TLS&lt;/STRONG&gt; and I’d like to tap into your experience. What prior considerations, best practices, and potential issues or challenges — either before or after rollout — should we be aware of?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks in advance for sharing your insights.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Best regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Aug 2025 09:12:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-tls-802-1x-rollouts-on-cisco-ise/m-p/5321540#M597818</guid>
      <dc:creator>henokk60</dc:creator>
      <dc:date>2025-08-18T09:12:21Z</dc:date>
    </item>
    <item>
      <title>Re: EAP‑TLS 802.1X Rollouts on Cisco ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-tls-802-1x-rollouts-on-cisco-ise/m-p/5321554#M597819</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1753581"&gt;@henokk60&lt;/a&gt;&amp;nbsp;first of all, what authentication mode are you using? User or machine authentication or EAP Chaining (user and machine)?&lt;/P&gt;
&lt;P&gt;Are you in open, monitor or closed mode?&lt;/P&gt;
&lt;P&gt;You are going to have to pre-deloy the certificates via GPO, assuming you are in an AD environment?&lt;/P&gt;
&lt;P&gt;If using user authentication via EAP-TLS and the user has never logged into the computer before, the user will not have&amp;nbsp;the necessary certificate at the time of authentication, 802.1X authentication will fail, and network access will be denied until the certificate is properly enrolled and installed.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Aug 2025 10:09:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-tls-802-1x-rollouts-on-cisco-ise/m-p/5321554#M597819</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2025-08-18T10:09:06Z</dc:date>
    </item>
    <item>
      <title>Re: EAP‑TLS 802.1X Rollouts on Cisco ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-tls-802-1x-rollouts-on-cisco-ise/m-p/5321563#M597820</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;Currently we operate in&amp;nbsp;&lt;/P&gt;&lt;P&gt;Authentication is&amp;nbsp;&amp;nbsp;&lt;STRONG&gt;PEAP‑MSCHAPv2&lt;/STRONG&gt;&amp;nbsp;-&amp;nbsp;User Authentication only and&amp;nbsp;Closed Mode.&lt;/P&gt;&lt;P&gt;To minimize disruption, and to roll out in a planned way with minimal interruption, what do you suggest to us?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Aug 2025 11:10:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-tls-802-1x-rollouts-on-cisco-ise/m-p/5321563#M597820</guid>
      <dc:creator>henokk60</dc:creator>
      <dc:date>2025-08-18T11:10:35Z</dc:date>
    </item>
    <item>
      <title>Re: EAP‑TLS 802.1X Rollouts on Cisco ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-tls-802-1x-rollouts-on-cisco-ise/m-p/5321565#M597821</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1753581"&gt;@henokk60&lt;/a&gt;&amp;nbsp;deploy the user/machine certificates via GPO well in advance (a month or so) of changing to use EAP-TLS, this will allow all devices time to enroll for the certifcates and avoid any authentication issues when you migrate to EAP-TLS.&lt;/P&gt;
&lt;P&gt;I'd recommend using EAP Chaining using TEAP with EAP-TLS to combine the user and machine authentications.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Aug 2025 11:18:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-tls-802-1x-rollouts-on-cisco-ise/m-p/5321565#M597821</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2025-08-18T11:18:32Z</dc:date>
    </item>
    <item>
      <title>Re: EAP‑TLS 802.1X Rollouts on Cisco ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-tls-802-1x-rollouts-on-cisco-ise/m-p/5321775#M597835</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1753581"&gt;@henokk60&lt;/a&gt;&amp;nbsp;you didn't mention whether wireless or wired deployment - there is quite a difference in how those get rolled out and the complexity involved. As&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;suggested, the modern approach is EAP-TEAP and that only works in Windows environments. If you have a mixed environment with older Windows 10 (ha ha ... not for long ...) and other devices such as mobile devices, then your lowest common denominator is EAP-TLS - and it's not a wrong choice - EAP-TEAP for Windows is great because it solves the age old issue of EAP chaining in a standards way.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Of course you can have clients using EAP-TLS and EAP-TEAP on the same SSID or switch - RADIUS servers can handle many EAP methods - don't be tempted by EAP-PEAP (it's discouraged on Windows platforms and Microsoft is trying hard to prevent this from working - for good reasons). But PEAP will work on IOT device and such.&lt;/P&gt;
&lt;P&gt;If 802.1X is new to you then start with a wireless SSID because setting up this stuff on wireless is much easier than on wired.&lt;/P&gt;
&lt;P&gt;Once you are happy with the experience, start with a few switches in Monitor Mode (assuming you have Cisco switches) and observe the fun and games with MAB/802.1X interactions. Cisco has an excellent wired prescriptive guide that takes you on that journey.&lt;/P&gt;
&lt;P&gt;Then move to Low Impact Mode once you know what devices are connecting to your switches, and you have prepared your RADIUS platform (hopefully ISE) for this to be smooth.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Aug 2025 20:53:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-tls-802-1x-rollouts-on-cisco-ise/m-p/5321775#M597835</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2025-08-18T20:53:17Z</dc:date>
    </item>
    <item>
      <title>Re: EAP‑TLS 802.1X Rollouts on Cisco ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-tls-802-1x-rollouts-on-cisco-ise/m-p/5321791#M597837</link>
      <description>&lt;P&gt;The answers are going to differ based on if it's for wired or wireless.&lt;/P&gt;
&lt;P&gt;But in general, and to add to the great points offered by Rob and Arne, try to consider different failure scenarios and try to test them.&lt;/P&gt;
&lt;P&gt;And in general, try to avoid peap &amp;amp; mschapv2 if at all possible.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Aug 2025 22:24:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-tls-802-1x-rollouts-on-cisco-ise/m-p/5321791#M597837</guid>
      <dc:creator>Jonatan Jonasson</dc:creator>
      <dc:date>2025-08-18T22:24:31Z</dc:date>
    </item>
    <item>
      <title>Re: EAP‑TLS 802.1X Rollouts on Cisco ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-tls-802-1x-rollouts-on-cisco-ise/m-p/5321955#M597855</link>
      <description>&lt;P&gt;It is wireless deployment with cisco WLC&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Aug 2025 12:40:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-tls-802-1x-rollouts-on-cisco-ise/m-p/5321955#M597855</guid>
      <dc:creator>henokk60</dc:creator>
      <dc:date>2025-08-19T12:40:42Z</dc:date>
    </item>
    <item>
      <title>Re: EAP‑TLS 802.1X Rollouts on Cisco ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-tls-802-1x-rollouts-on-cisco-ise/m-p/5322147#M597858</link>
      <description>&lt;P&gt;Wireless is the best place to start with 802.1X.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Aug 2025 22:29:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-tls-802-1x-rollouts-on-cisco-ise/m-p/5322147#M597858</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2025-08-19T22:29:13Z</dc:date>
    </item>
  </channel>
</rss>

