<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ISE - EAP-TLS and EAP-TEAP simultaneously run in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-eap-tls-and-eap-teap-simultaneously-run/m-p/5374744#M599977</link>
    <description>&lt;P&gt;Why bother having these be separate policy sets at all?&lt;/P&gt;</description>
    <pubDate>Thu, 05 Mar 2026 13:21:29 GMT</pubDate>
    <dc:creator>ahollifield</dc:creator>
    <dc:date>2026-03-05T13:21:29Z</dc:date>
    <item>
      <title>Cisco ISE - EAP-TLS and EAP-TEAP simultaneously run</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-eap-tls-and-eap-teap-simultaneously-run/m-p/5369284#M599780</link>
      <description>&lt;P&gt;Dear Team,&lt;/P&gt;
&lt;P&gt;I have below Policy Set:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mikiNet_0-1770801197224.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/259466iE291BEC6D0E8CECF/image-size/medium?v=v2&amp;amp;px=400" role="button" title="mikiNet_0-1770801197224.png" alt="mikiNet_0-1770801197224.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;All RADIUS request is hiting the first policy even if I set supplicant to use TEAP. I know that problem is with&amp;nbsp;hierarchy of this two policy. When I move second policy to the top, then TEAP working but TLS not.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Profile for "Allowed Protocols" is set as we see: I have two profile EAP-TLS which only allow TLS and second profile which allow only TEAP.&lt;/P&gt;
&lt;P&gt;So for example If&amp;nbsp;hierarchy is as on the screenshot and if supplicant is set to use TEAP, the request from NAD is hitting first rule because Condition is matching, but in Allowed Protocol profile TEAP is not allowed.&lt;/P&gt;
&lt;P&gt;Is there any chance to&amp;nbsp;distinguish this two Policy on the Condition to have working properly this policy?&lt;/P&gt;
&lt;P&gt;I know that when I go inside policy, In authentication Tab I can use "Network Access-EapAuthentication" set to e.x. EAP-TLS but this not resolve my issue.&lt;/P&gt;
&lt;P&gt;I want it to work on the main page. Any idea ?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Feb 2026 09:23:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-eap-tls-and-eap-teap-simultaneously-run/m-p/5369284#M599780</guid>
      <dc:creator>mikiNet</dc:creator>
      <dc:date>2026-02-11T09:23:01Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE - EAP-TLS and EAP-TEAP simultaneously run</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-eap-tls-and-eap-teap-simultaneously-run/m-p/5374543#M599970</link>
      <description>&lt;P&gt;ISE Policy Set conditions work top-down and the first match wins.&lt;/P&gt;
&lt;P&gt;Both sets of conditions are working because your supplicant is probably configured to do &lt;EM&gt;both&lt;/EM&gt; EAP-TLS or TEAP.&lt;/P&gt;
&lt;P&gt;Typically we don't have separate Policy Sets for different EAP protocols - if the endpoint can do 802.1X with EAP, then you handle the EAP-based authentication in the Authentication Policy and the Authorization Policy will likely be the same regardless of the protocol:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/260630i7ACB70F7599CE855/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;If you want to separate at the EAP Authentication or EAP Tunnel Type, you must do this &lt;EM&gt;within&lt;/EM&gt; a Policy Set - you will not have this option at the Policy Set level because the &lt;STRONG&gt;Allowed Protocols&lt;/STRONG&gt;&amp;nbsp;selection determines which protocols will be attempted by ISE for authentication.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 361px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/260631i4E4BF2944B9382EF/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&amp;nbsp;&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 358px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/260632i688ADB017CC85C4C/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Hopefully that helps answer your question to get you what you need.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Mar 2026 22:09:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-eap-tls-and-eap-teap-simultaneously-run/m-p/5374543#M599970</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2026-03-04T22:09:36Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE - EAP-TLS and EAP-TEAP simultaneously run</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-eap-tls-and-eap-teap-simultaneously-run/m-p/5374744#M599977</link>
      <description>&lt;P&gt;Why bother having these be separate policy sets at all?&lt;/P&gt;</description>
      <pubDate>Thu, 05 Mar 2026 13:21:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-eap-tls-and-eap-teap-simultaneously-run/m-p/5374744#M599977</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2026-03-05T13:21:29Z</dc:date>
    </item>
  </channel>
</rss>

