<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: EAP-TLS vs PEAP-EAP-TLS performance question in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/eap-tls-vs-peap-eap-tls-performance-question/m-p/5322795#M597905</link>
    <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="images (4).png" style="width: 513px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/250673i2F42FA1DDA536016/image-size/medium?v=v2&amp;amp;px=400" role="button" title="images (4).png" alt="images (4).png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Inner method allow eap-tls&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So ISE support PEAP eap-tls&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
    <pubDate>Thu, 21 Aug 2025 09:38:59 GMT</pubDate>
    <dc:creator>MHM Cisco World</dc:creator>
    <dc:date>2025-08-21T09:38:59Z</dc:date>
    <item>
      <title>EAP-TLS vs PEAP-EAP-TLS performance question</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-tls-vs-peap-eap-tls-performance-question/m-p/5322633#M597893</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have a question about performance when using EAP-TLS and PEAP-MSCHAPv2 versus PEAP-EAP-TLS. Referring to the Cisco link: &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/performance_and_scalability/b_ise_perf_and_scale.html#reference_dfk_mjh_m5b" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/performance_and_scalability/b_ise_perf_and_scale.html#reference_dfk_mjh_m5b&lt;/A&gt;, specifically table 5, which shows RADIUS transactions per second (TPS) for a dedicated PSN node, I notice that the appliances we have (3655) support the following:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;PEAP (MSCHAPv2) with Active Directory - 200&lt;/LI&gt;&lt;LI&gt;EAP-TLS with Active Directory - 200&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;These are the maximum TPS supported by these appliances. However, what happens if I use PEAP-EAP-TLS? Will those numbers decrease, and if so, by how much?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Aug 2025 18:25:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-tls-vs-peap-eap-tls-performance-question/m-p/5322633#M597893</guid>
      <dc:creator>pabloayalas</dc:creator>
      <dc:date>2025-08-20T18:25:59Z</dc:date>
    </item>
    <item>
      <title>Re: EAP-TLS vs PEAP-EAP-TLS performance question</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-tls-vs-peap-eap-tls-performance-question/m-p/5322636#M597894</link>
      <description>&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/net_mgmt/prime/access_registrar/9-3/reference/guide/reference/TPS.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/net_mgmt/prime/access_registrar/9-3/reference/guide/reference/TPS.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;I think it also depends on license&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Wed, 20 Aug 2025 18:32:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-tls-vs-peap-eap-tls-performance-question/m-p/5322636#M597894</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-08-20T18:32:12Z</dc:date>
    </item>
    <item>
      <title>Re: EAP-TLS vs PEAP-EAP-TLS performance question</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-tls-vs-peap-eap-tls-performance-question/m-p/5322637#M597895</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/767942"&gt;@pabloayalas&lt;/a&gt;&amp;nbsp;I've never come across any customer using PEAP-EAP-TLS, typically EAP-TLS is used and this may be why the cisco document does not have this information. I would imagine the performance would be worse using PEAP-EAP-TLS as there is more overhead (packets exchanged) as part of the process.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Aug 2025 18:33:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-tls-vs-peap-eap-tls-performance-question/m-p/5322637#M597895</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2025-08-20T18:33:11Z</dc:date>
    </item>
    <item>
      <title>Re: EAP-TLS vs PEAP-EAP-TLS performance question</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-tls-vs-peap-eap-tls-performance-question/m-p/5322642#M597896</link>
      <description>&lt;P&gt;by the way it TEAP EAP TLS not PEAP&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Wed, 20 Aug 2025 18:50:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-tls-vs-peap-eap-tls-performance-question/m-p/5322642#M597896</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-08-20T18:50:22Z</dc:date>
    </item>
    <item>
      <title>Re: EAP-TLS vs PEAP-EAP-TLS performance question</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-tls-vs-peap-eap-tls-performance-question/m-p/5322646#M597897</link>
      <description>&lt;P&gt;Actually there is also PEAP-EAP-TLS as well as EAP-TLS. Using PEAP-EAP-TLS, first establishes an encrypted PEAP tunnel and then EAP-TLS is used for client/server authentication. EAP-TLS just skips the first step (the PEAP tunnel establishment) and securely authenticates the client/server certificates.&lt;/P&gt;
&lt;P&gt;TEAP combines user and machine authentication, which uses EAP-TLS or PEAP/MSCHAPv2 authentication methods.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Aug 2025 19:04:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-tls-vs-peap-eap-tls-performance-question/m-p/5322646#M597897</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2025-08-20T19:04:23Z</dc:date>
    </item>
    <item>
      <title>Re: EAP-TLS vs PEAP-EAP-TLS performance question</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-tls-vs-peap-eap-tls-performance-question/m-p/5322648#M597898</link>
      <description>&lt;P&gt;I try to find PEAP as outer and inner EAP-TLS but I could not find any doc about it&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Wed, 20 Aug 2025 19:09:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-tls-vs-peap-eap-tls-performance-question/m-p/5322648#M597898</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-08-20T19:09:52Z</dc:date>
    </item>
    <item>
      <title>Re: EAP-TLS vs PEAP-EAP-TLS performance question</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-tls-vs-peap-eap-tls-performance-question/m-p/5322653#M597899</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Protected EAP (PEAP)&lt;/STRONG&gt;: &lt;A href="https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-peap" data-linktype="absolute-path" target="_blank"&gt;Microsoft-defined&lt;/A&gt; EAP method that encapsulates EAP within a TLS tunnel. The TLS tunnel secures the inner EAP method, which could be unprotected otherwise. Windows supports EAP-TLS and EAP-MSCHAP v2 as inner methods.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;EAP-Transport Layer Security (EAP-TLS)&lt;/STRONG&gt;: &lt;A href="https://datatracker.ietf.org/doc/html/rfc5216" data-linktype="external" target="_blank"&gt;Standards-based&lt;/A&gt; EAP method that uses TLS with certificates for mutual authentication. Appears as &lt;STRONG&gt;Smart Card or other Certificate (EAP-TLS)&lt;/STRONG&gt; in Windows. EAP-TLS can be deployed as an &lt;STRONG&gt;inner method&lt;/STRONG&gt; for another EAP method or as a standalone EAP method.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/en-us/windows-server/networking/technologies/extensible-authentication-protocol/network-access?tabs=eap-tls%2Cserveruserprompt-eap-tls%2Ceap-sim" target="_blank"&gt;https://learn.microsoft.com/en-us/windows-server/networking/technologies/extensible-authentication-protocol/network-access?tabs=eap-tls%2Cserveruserprompt-eap-tls%2Ceap-sim&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;PEAP is the outer method, then the inner method could be either EAP-TLS or MSCHAPv2&lt;/P&gt;</description>
      <pubDate>Wed, 20 Aug 2025 19:19:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-tls-vs-peap-eap-tls-performance-question/m-p/5322653#M597899</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2025-08-20T19:19:20Z</dc:date>
    </item>
    <item>
      <title>Re: EAP-TLS vs PEAP-EAP-TLS performance question</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-tls-vs-peap-eap-tls-performance-question/m-p/5322657#M597900</link>
      <description>&lt;P&gt;But that for Microsoft not ISE.&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Wed, 20 Aug 2025 19:24:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-tls-vs-peap-eap-tls-performance-question/m-p/5322657#M597900</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-08-20T19:24:05Z</dc:date>
    </item>
    <item>
      <title>Re: EAP-TLS vs PEAP-EAP-TLS performance question</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-tls-vs-peap-eap-tls-performance-question/m-p/5322740#M597901</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;you are correct. These are the steps from one of my computers:&lt;BR /&gt;Steps&lt;BR /&gt;Step ID Description Latency (ms)&lt;BR /&gt;11001 Received RADIUS Access-Request - company_AD&lt;BR /&gt;11017 RADIUS created a new session - host/computer 0&lt;BR /&gt;15049 Evaluating Policy Group - company.com 0&lt;BR /&gt;15008 Evaluating Service Selection Policy - from: host/computer to: host/computer.company.com 0&lt;BR /&gt;15048 Queried PIP - company.com 1&lt;BR /&gt;15048 Queried PIP - Radius.Called-Station-ID 0&lt;BR /&gt;11507 Extracted EAP-Response/Identity - company.com 0&lt;BR /&gt;12500 Prepared EAP-Request proposing EAP-TLS with challenge - company_AD 0&lt;BR /&gt;12625 Valid EAP-Key-Name attribute received - company.com 1&lt;BR /&gt;11006 Returned RADIUS Access-Challenge - company_AD 0&lt;BR /&gt;11001 Received RADIUS Access-Request - company_AD 3&lt;BR /&gt;11018 RADIUS is re-using an existing session 0&lt;BR /&gt;12301 Extracted EAP-Response/NAK requesting to use PEAP instead 0&lt;BR /&gt;12300 Prepared EAP-Request proposing PEAP with challenge 0&lt;BR /&gt;12625 Valid EAP-Key-Name attribute received 0&lt;BR /&gt;11006 Returned RADIUS Access-Challenge 0&lt;BR /&gt;11001 Received RADIUS Access-Request 9&lt;BR /&gt;11018 RADIUS is re-using an existing session 0&lt;BR /&gt;12302 Extracted EAP-Response containing PEAP challenge-response and accepting PEAP as negotiated 1&lt;BR /&gt;61025 Open secure connection with TLS peer 0&lt;BR /&gt;12318 Successfully negotiated PEAP version 0 0&lt;BR /&gt;12800 Extracted first TLS record; TLS handshake started 0&lt;BR /&gt;12805 Extracted TLS ClientHello message 1&lt;BR /&gt;12806 Prepared TLS ServerHello message 0&lt;BR /&gt;12807 Prepared TLS Certificate message 0&lt;BR /&gt;12808 Prepared TLS ServerKeyExchange message 9&lt;BR /&gt;12810 Prepared TLS ServerDone message 0&lt;BR /&gt;12305 Prepared EAP-Request with another PEAP challenge 0&lt;BR /&gt;11006 Returned RADIUS Access-Challenge 0&lt;BR /&gt;11001 Received RADIUS Access-Request 4&lt;BR /&gt;11018 RADIUS is re-using an existing session 0&lt;BR /&gt;12304 Extracted EAP-Response containing PEAP challenge-response 0&lt;BR /&gt;12305 Prepared EAP-Request with another PEAP challenge 0&lt;BR /&gt;11006 Returned RADIUS Access-Challenge 0&lt;BR /&gt;11001 Received RADIUS Access-Request 4&lt;BR /&gt;11018 RADIUS is re-using an existing session 0&lt;BR /&gt;12304 Extracted EAP-Response containing PEAP challenge-response 1&lt;BR /&gt;12305 Prepared EAP-Request with another PEAP challenge 0&lt;BR /&gt;11006 Returned RADIUS Access-Challenge 0&lt;BR /&gt;11001 Received RADIUS Access-Request 4&lt;BR /&gt;11018 RADIUS is re-using an existing session 0&lt;BR /&gt;12304 Extracted EAP-Response containing PEAP challenge-response 0&lt;BR /&gt;12305 Prepared EAP-Request with another PEAP challenge 0&lt;BR /&gt;11006 Returned RADIUS Access-Challenge 0&lt;BR /&gt;11001 Received RADIUS Access-Request 5&lt;BR /&gt;11018 RADIUS is re-using an existing session 0&lt;BR /&gt;12304 Extracted EAP-Response containing PEAP challenge-response 0&lt;BR /&gt;12305 Prepared EAP-Request with another PEAP challenge 0&lt;BR /&gt;11006 Returned RADIUS Access-Challenge 0&lt;BR /&gt;11001 Received RADIUS Access-Request 4&lt;BR /&gt;11018 RADIUS is re-using an existing session 0&lt;BR /&gt;12304 Extracted EAP-Response containing PEAP challenge-response 0&lt;BR /&gt;12305 Prepared EAP-Request with another PEAP challenge 0&lt;BR /&gt;11006 Returned RADIUS Access-Challenge 0&lt;BR /&gt;11001 Received RADIUS Access-Request 20&lt;BR /&gt;11018 RADIUS is re-using an existing session 0&lt;BR /&gt;12304 Extracted EAP-Response containing PEAP challenge-response 0&lt;BR /&gt;12318 Successfully negotiated PEAP version 0 0&lt;BR /&gt;12810 Prepared TLS ServerDone message 0&lt;BR /&gt;12812 Extracted TLS ClientKeyExchange message 3&lt;BR /&gt;12803 Extracted TLS ChangeCipherSpec message 0&lt;BR /&gt;12804 Extracted TLS Finished message 0&lt;BR /&gt;12801 Prepared TLS ChangeCipherSpec message 1&lt;BR /&gt;12802 Prepared TLS Finished message 0&lt;BR /&gt;12816 TLS handshake succeeded 0&lt;BR /&gt;12310 PEAP full handshake finished successfully 0&lt;BR /&gt;12305 Prepared EAP-Request with another PEAP challenge 0&lt;BR /&gt;11006 Returned RADIUS Access-Challenge 0&lt;BR /&gt;11001 Received RADIUS Access-Request 23&lt;BR /&gt;11018 RADIUS is re-using an existing session 0&lt;BR /&gt;12304 Extracted EAP-Response containing PEAP challenge-response 0&lt;BR /&gt;12313 PEAP inner method started 0&lt;BR /&gt;11521 Prepared EAP-Request/Identity for inner EAP method 0&lt;BR /&gt;12305 Prepared EAP-Request with another PEAP challenge 1&lt;BR /&gt;11006 Returned RADIUS Access-Challenge 0&lt;BR /&gt;11001 Received RADIUS Access-Request 3&lt;BR /&gt;11018 RADIUS is re-using an existing session 0&lt;BR /&gt;12304 Extracted EAP-Response containing PEAP challenge-response 0&lt;BR /&gt;11522 Extracted EAP-Response/Identity for inner EAP method 0&lt;BR /&gt;12522 Prepared EAP-Request for inner method proposing EAP-TLS with challenge 0&lt;BR /&gt;12625 Valid EAP-Key-Name attribute received 1&lt;BR /&gt;12305 Prepared EAP-Request with another PEAP challenge 0&lt;BR /&gt;11006 Returned RADIUS Access-Challenge 0&lt;BR /&gt;11001 Received RADIUS Access-Request 14&lt;BR /&gt;11018 RADIUS is re-using an existing session 0&lt;BR /&gt;12304 Extracted EAP-Response containing PEAP challenge-response 0&lt;BR /&gt;12524 Extracted EAP-Response containing EAP-TLS challenge-response for inner method and accepting EAP-TLS as negotiated 0&lt;BR /&gt;61025 Open secure connection with TLS peer 0&lt;BR /&gt;12800 Extracted first TLS record; TLS handshake started 1&lt;BR /&gt;12545 Client requested EAP-TLS session ticket 0&lt;BR /&gt;12546 The EAP-TLS session ticket received from supplicant. Inner EAP-TLS does not support stateless session resume. Performing full authentication 0&lt;BR /&gt;12805 Extracted TLS ClientHello message 0&lt;BR /&gt;12806 Prepared TLS ServerHello message 0&lt;BR /&gt;12807 Prepared TLS Certificate message 0&lt;BR /&gt;12808 Prepared TLS ServerKeyExchange message 7&lt;BR /&gt;12809 Prepared TLS CertificateRequest message 0&lt;BR /&gt;12810 Prepared TLS ServerDone message 0&lt;BR /&gt;12527 Prepared EAP-Request for inner method with another EAP-TLS challenge 1&lt;BR /&gt;12305 Prepared EAP-Request with another PEAP challenge 0&lt;BR /&gt;11006 Returned RADIUS Access-Challenge 0&lt;BR /&gt;11001 Received RADIUS Access-Request 4&lt;BR /&gt;11018 RADIUS is re-using an existing session 0&lt;BR /&gt;12304 Extracted EAP-Response containing PEAP challenge-response 0&lt;BR /&gt;12526 Extracted EAP-Response for inner method containing TLS challenge-response 0&lt;BR /&gt;12527 Prepared EAP-Request for inner method with another EAP-TLS challenge 0&lt;BR /&gt;12305 Prepared EAP-Request with another PEAP challenge 0&lt;BR /&gt;11006 Returned RADIUS Access-Challenge 1&lt;BR /&gt;11001 Received RADIUS Access-Request 3&lt;BR /&gt;11018 RADIUS is re-using an existing session 0&lt;BR /&gt;12304 Extracted EAP-Response containing PEAP challenge-response 0&lt;BR /&gt;12526 Extracted EAP-Response for inner method containing TLS challenge-response 0&lt;BR /&gt;12527 Prepared EAP-Request for inner method with another EAP-TLS challenge 1&lt;BR /&gt;12305 Prepared EAP-Request with another PEAP challenge 0&lt;BR /&gt;11006 Returned RADIUS Access-Challenge 0&lt;BR /&gt;11001 Received RADIUS Access-Request 16&lt;BR /&gt;11018 RADIUS is re-using an existing session 0&lt;BR /&gt;12304 Extracted EAP-Response containing PEAP challenge-response 0&lt;BR /&gt;12526 Extracted EAP-Response for inner method containing TLS challenge-response 0&lt;BR /&gt;12527 Prepared EAP-Request for inner method with another EAP-TLS challenge 0&lt;BR /&gt;12305 Prepared EAP-Request with another PEAP challenge 0&lt;BR /&gt;11006 Returned RADIUS Access-Challenge 1&lt;BR /&gt;11001 Received RADIUS Access-Request 3&lt;BR /&gt;11018 RADIUS is re-using an existing session 0&lt;BR /&gt;12304 Extracted EAP-Response containing PEAP challenge-response 0&lt;BR /&gt;12526 Extracted EAP-Response for inner method containing TLS challenge-response 1&lt;BR /&gt;12527 Prepared EAP-Request for inner method with another EAP-TLS challenge 0&lt;BR /&gt;12305 Prepared EAP-Request with another PEAP challenge 0&lt;BR /&gt;11006 Returned RADIUS Access-Challenge 0&lt;BR /&gt;11001 Received RADIUS Access-Request 4&lt;BR /&gt;11018 RADIUS is re-using an existing session 0&lt;BR /&gt;12304 Extracted EAP-Response containing PEAP challenge-response 0&lt;BR /&gt;12526 Extracted EAP-Response for inner method containing TLS challenge-response 0&lt;BR /&gt;12527 Prepared EAP-Request for inner method with another EAP-TLS challenge 0&lt;BR /&gt;12305 Prepared EAP-Request with another PEAP challenge 1&lt;BR /&gt;11006 Returned RADIUS Access-Challenge 0&lt;BR /&gt;11001 Received RADIUS Access-Request 9&lt;BR /&gt;11018 RADIUS is re-using an existing session 0&lt;BR /&gt;12304 Extracted EAP-Response containing PEAP challenge-response 0&lt;BR /&gt;12526 Extracted EAP-Response for inner method containing TLS challenge-response 0&lt;BR /&gt;12527 Prepared EAP-Request for inner method with another EAP-TLS challenge 0&lt;BR /&gt;12305 Prepared EAP-Request with another PEAP challenge 1&lt;BR /&gt;11006 Returned RADIUS Access-Challenge 0&lt;BR /&gt;11001 Received RADIUS Access-Request 5&lt;BR /&gt;11018 RADIUS is re-using an existing session 0&lt;BR /&gt;12304 Extracted EAP-Response containing PEAP challenge-response 0&lt;BR /&gt;12526 Extracted EAP-Response for inner method containing TLS challenge-response 0&lt;BR /&gt;12527 Prepared EAP-Request for inner method with another EAP-TLS challenge 0&lt;BR /&gt;12305 Prepared EAP-Request with another PEAP challenge 1&lt;BR /&gt;11006 Returned RADIUS Access-Challenge 0&lt;BR /&gt;11001 Received RADIUS Access-Request 3&lt;BR /&gt;11018 RADIUS is re-using an existing session 0&lt;BR /&gt;12304 Extracted EAP-Response containing PEAP challenge-response 0&lt;BR /&gt;12526 Extracted EAP-Response for inner method containing TLS challenge-response 1&lt;BR /&gt;12810 Prepared TLS ServerDone message 0&lt;BR /&gt;12571 ISE will continue to CRL verification if it is configured for specific CA - certificate for computer 0&lt;BR /&gt;12571 ISE will continue to CRL verification if it is configured for specific CA - certificate for company CRL 8&lt;BR /&gt;12811 Extracted TLS Certificate message containing client certificate 1&lt;BR /&gt;12812 Extracted TLS ClientKeyExchange message 3&lt;BR /&gt;12813 Extracted TLS CertificateVerify message 0&lt;BR /&gt;12803 Extracted TLS ChangeCipherSpec message 0&lt;BR /&gt;12804 Extracted TLS Finished message 0&lt;BR /&gt;12801 Prepared TLS ChangeCipherSpec message 0&lt;BR /&gt;12802 Prepared TLS Finished message 0&lt;BR /&gt;12816 TLS handshake succeeded 0&lt;BR /&gt;12509 EAP-TLS full handshake finished successfully 1&lt;BR /&gt;12527 Prepared EAP-Request for inner method with another EAP-TLS challenge 0&lt;BR /&gt;12305 Prepared EAP-Request with another PEAP challenge 0&lt;BR /&gt;11006 Returned RADIUS Access-Challenge 0&lt;BR /&gt;11001 Received RADIUS Access-Request 8&lt;BR /&gt;11018 RADIUS is re-using an existing session 0&lt;BR /&gt;12304 Extracted EAP-Response containing PEAP challenge-response 0&lt;BR /&gt;12526 Extracted EAP-Response for inner method containing TLS challenge-response 0&lt;BR /&gt;15041 Evaluating Identity Policy 1&lt;BR /&gt;15048 Queried PIP - Network Access.EapAuthentication 0&lt;BR /&gt;15048 Queried PIP - CERTIFICATE.Issuer 0&lt;BR /&gt;15048 Queried PIP - CERTIFICATE.Issuer - Common Name 0&lt;BR /&gt;15048 Queried PIP - CERTIFICATE.Issuer - Organization 0&lt;BR /&gt;22070 Identity name is taken from certificate attribute 1&lt;BR /&gt;22037 Authentication Passed 0&lt;BR /&gt;12528 Inner EAP-TLS authentication succeeded 0&lt;BR /&gt;61026 Shutdown secure connection with TLS peer 0&lt;BR /&gt;11519 Prepared EAP-Success for inner EAP method 1&lt;BR /&gt;12314 PEAP inner method finished successfully 0&lt;BR /&gt;12305 Prepared EAP-Request with another PEAP challenge 0&lt;BR /&gt;11006 Returned RADIUS Access-Challenge 0&lt;BR /&gt;11001 Received RADIUS Access-Request 23&lt;BR /&gt;11018 RADIUS is re-using an existing session 0&lt;BR /&gt;12304 Extracted EAP-Response containing PEAP challenge-response 0&lt;BR /&gt;24715 ISE has not confirmed locally previous successful machine authentication for user in Active Directory 1&lt;BR /&gt;15036 Evaluating Authorization Policy 0&lt;BR /&gt;24209 Looking up Endpoint in Internal Endpoints IDStore - computer 0&lt;BR /&gt;24211 Found Endpoint in Internal Endpoints IDStore 2&lt;BR /&gt;15048 Queried PIP - Session.ANCPolicy 2&lt;BR /&gt;15048 Queried PIP - Session.ANCPolicy 1&lt;BR /&gt;15048 Queried PIP - Session.ANCPolicy 2&lt;BR /&gt;15048 Queried PIP - Radius.Called-Station-ID 0&lt;BR /&gt;24433 Looking up machine in Active Directory - computer&lt;BR /&gt;24325 Resolving identity&lt;BR /&gt;24313 Search for matching accounts at join point&lt;BR /&gt;24357 Incoming identity was rewritten&lt;BR /&gt;24319 Single matching account found in forest&lt;BR /&gt;24323 Identity resolution detected single matching account&lt;BR /&gt;24355 LDAP fetch succeeded&lt;BR /&gt;24435 Machine Groups retrieval from Active Directory succeeded&lt;BR /&gt;24355 LDAP fetch succeeded&lt;BR /&gt;24458 Not all Active Directory attributes are retrieved successfully&lt;BR /&gt;24100 Some of the expected attributes are not found on the subject record. The default values, if configured, will be used for these attributes&lt;BR /&gt;15048 Queried PIP - company_AD.extensionAttribute1 6&lt;BR /&gt;15048 Queried PIP - DEVICE.Location 0&lt;BR /&gt;15016 Selected Authorization Profile - company_computer 0&lt;BR /&gt;22081 Max sessions policy passed 1&lt;BR /&gt;22080 New accounting session created in Session cache 0&lt;BR /&gt;12306 PEAP authentication succeeded 0&lt;BR /&gt;61026 Shutdown secure connection with TLS peer 1&lt;BR /&gt;11503 Prepared EAP-Success 0&lt;BR /&gt;11002 Returned RADIUS Access-Accept 1&lt;/P&gt;&lt;H3&gt;&lt;STRONG&gt;Protocol Used&lt;/STRONG&gt;&lt;/H3&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;The authentication used &lt;STRONG&gt;PEAP (Protected Extensible Authentication Protocol) with an inner EAP-TLS method&lt;/STRONG&gt;.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;The logs show:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;Initial EAP-TLS proposal (12500 Prepared EAP-Request proposing EAP-TLS), but the client &lt;STRONG&gt;NAK'd&lt;/STRONG&gt; and requested PEAP instead (12301 Extracted EAP-Response/NAK requesting to use PEAP instead).&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;The outer tunnel is negotiated with &lt;STRONG&gt;PEAP&lt;/STRONG&gt; (12318 Successfully negotiated PEAP version 0).&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Within PEAP, an &lt;STRONG&gt;inner EAP-TLS handshake&lt;/STRONG&gt; occurs to authenticate the user/computer.&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;H3&gt;&lt;STRONG&gt;Step-by-Step Authentication Flow&lt;/STRONG&gt;&lt;/H3&gt;&lt;OL&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;Session Initiation&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;ISE receives an initial &lt;STRONG&gt;RADIUS Access-Request&lt;/STRONG&gt; (11001) from the network device carrying the EAP identity.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;A new session is created (11017).&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;Initial Protocol Negotiation&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;ISE first proposes &lt;STRONG&gt;EAP-TLS&lt;/STRONG&gt; (12500).&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;The client rejects this and requests &lt;STRONG&gt;PEAP&lt;/STRONG&gt; (12301).&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;ISE responds by preparing a PEAP challenge (12300).&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;PEAP Tunnel Establishment (Outer TLS Tunnel)&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;TLS handshake begins with &lt;STRONG&gt;ClientHello&lt;/STRONG&gt; and &lt;STRONG&gt;ServerHello&lt;/STRONG&gt; messages (12805, 12806).&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Server sends its certificate (12807), key exchange (12808), and finishes (12810).&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Handshake is completed (12816 TLS handshake succeeded).&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;Outer tunnel established&lt;/STRONG&gt; – traffic between client and ISE is now encrypted.&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;Inner EAP Method Negotiation&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;Inside PEAP, ISE starts an &lt;STRONG&gt;inner EAP-TLS&lt;/STRONG&gt; session (12522).&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;TLS handshake for inner EAP-TLS begins (similar sequence as outer handshake).&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Client certificate is received (12811), verified via CRL if configured (12571).&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Inner TLS handshake succeeds (12509 EAP-TLS full handshake finished successfully).&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;Certificate-Based Authentication&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;ISE extracts identity information from client certificate (22070 Identity name is taken from certificate attribute).&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Authentication passes (22037 Authentication Passed).&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;Authorization &amp;amp; Policy Evaluation&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;ISE checks Active Directory for endpoint and machine group membership (24433, 24435).&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Authorization Profile is applied (15016 Selected Authorization Profile - company_computer).&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;Final Success&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;PEAP inner method finishes successfully (12314).&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;ISE sends &lt;STRONG&gt;EAP-Success&lt;/STRONG&gt; (11503) and then a &lt;STRONG&gt;RADIUS Access-Accept&lt;/STRONG&gt; (11002).&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;When I did this deployment, I was mainly thinking about security. Although PEAP and EAP-TLS have very high security, I wanted to hide the certificate exchange inside the PEAP tunnel. Everything has been working fine; however, I am somewhat concerned when we have many employees, as it could cause high CPU or memory usage on the PSN nodes.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Aug 2025 01:49:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-tls-vs-peap-eap-tls-performance-question/m-p/5322740#M597901</guid>
      <dc:creator>pabloayalas</dc:creator>
      <dc:date>2025-08-21T01:49:56Z</dc:date>
    </item>
    <item>
      <title>Re: EAP-TLS vs PEAP-EAP-TLS performance question</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-tls-vs-peap-eap-tls-performance-question/m-p/5322758#M597902</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/767942"&gt;@pabloayalas&lt;/a&gt;&amp;nbsp;how many concurrent/total number of authenticated users? what is the size of the deployment (small, medium or large), how many PSNs do you have? do you have load balancers in front of the PSNs? are you using RADIUS over DTLS? If this is a production environment, are you actually experiencing any problems?&lt;/P&gt;</description>
      <pubDate>Thu, 21 Aug 2025 06:58:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-tls-vs-peap-eap-tls-performance-question/m-p/5322758#M597902</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2025-08-21T06:58:01Z</dc:date>
    </item>
    <item>
      <title>Re: EAP-TLS vs PEAP-EAP-TLS performance question</title>
      <link>https://community.cisco.com/t5/network-access-control/eap-tls-vs-peap-eap-tls-performance-question/m-p/5322795#M597905</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="images (4).png" style="width: 513px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/250673i2F42FA1DDA536016/image-size/medium?v=v2&amp;amp;px=400" role="button" title="images (4).png" alt="images (4).png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Inner method allow eap-tls&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So ISE support PEAP eap-tls&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Thu, 21 Aug 2025 09:38:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/eap-tls-vs-peap-eap-tls-performance-question/m-p/5322795#M597905</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-08-21T09:38:59Z</dc:date>
    </item>
  </channel>
</rss>

