<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How does ACS select EAP type to send to client? in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/how-does-acs-select-eap-type-to-send-to-client/m-p/2489792#M90821</link>
    <description>&lt;P&gt;From what I understand when using PEAP and EAP-TLS, it's the radius server that first determines which one to use.&lt;/P&gt;&lt;P&gt;From &lt;A href="http://tools.ietf.org/id/draft-kamath-pppext-peapv0-00.txt" target="_blank"&gt;draft-kamath-pppext-peapv0-00.txt&lt;/A&gt; :&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/peapv0-draft.png" class="migrated-markup-image" /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So my question is how does ACS select which one to use.&amp;nbsp; I'm assuming its the "Access Services" "Allowed Protocols" tab.&amp;nbsp; But what if you have multiple ones selected?&amp;nbsp; Does it first try the "Preferred EAP protocol" field?&amp;nbsp; Does it cycle through all checked options?&amp;nbsp; The way that "allowed protocols" tab is labeled seems to imply that ACS will know from the incoming request if the client wants to use PEAP or EAP-TLS which doesn't make sense.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/acs-allowed-protocols.png" class="migrated-markup-image" /&gt;&lt;/P&gt;&lt;P&gt;I read the &lt;A href="http://www.cisco.com/c/en/us/td/docs/net_mgmt/cisco_secure_access_control_system/5-5/user/guide/acsuserguide/access_policies.html#pgfId-1052497" target="_blank"&gt;Managing Access Policies user guide for ACS 5.5&lt;/A&gt; and it's still not clear to me.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any input is appreciated.&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 04:40:55 GMT</pubDate>
    <dc:creator>ds6123</dc:creator>
    <dc:date>2019-03-11T04:40:55Z</dc:date>
    <item>
      <title>How does ACS select EAP type to send to client?</title>
      <link>https://community.cisco.com/t5/network-access-control/how-does-acs-select-eap-type-to-send-to-client/m-p/2489792#M90821</link>
      <description>&lt;P&gt;From what I understand when using PEAP and EAP-TLS, it's the radius server that first determines which one to use.&lt;/P&gt;&lt;P&gt;From &lt;A href="http://tools.ietf.org/id/draft-kamath-pppext-peapv0-00.txt" target="_blank"&gt;draft-kamath-pppext-peapv0-00.txt&lt;/A&gt; :&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/peapv0-draft.png" class="migrated-markup-image" /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So my question is how does ACS select which one to use.&amp;nbsp; I'm assuming its the "Access Services" "Allowed Protocols" tab.&amp;nbsp; But what if you have multiple ones selected?&amp;nbsp; Does it first try the "Preferred EAP protocol" field?&amp;nbsp; Does it cycle through all checked options?&amp;nbsp; The way that "allowed protocols" tab is labeled seems to imply that ACS will know from the incoming request if the client wants to use PEAP or EAP-TLS which doesn't make sense.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/acs-allowed-protocols.png" class="migrated-markup-image" /&gt;&lt;/P&gt;&lt;P&gt;I read the &lt;A href="http://www.cisco.com/c/en/us/td/docs/net_mgmt/cisco_secure_access_control_system/5-5/user/guide/acsuserguide/access_policies.html#pgfId-1052497" target="_blank"&gt;Managing Access Policies user guide for ACS 5.5&lt;/A&gt; and it's still not clear to me.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any input is appreciated.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 04:40:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-does-acs-select-eap-type-to-send-to-client/m-p/2489792#M90821</guid>
      <dc:creator>ds6123</dc:creator>
      <dc:date>2019-03-11T04:40:55Z</dc:date>
    </item>
    <item>
      <title>Allowed Protocols is what ACS</title>
      <link>https://community.cisco.com/t5/network-access-control/how-does-acs-select-eap-type-to-send-to-client/m-p/2489793#M90824</link>
      <description>&lt;P&gt;Allowed Protocols is what ACS accept for authentication.. If for example &lt;STRONG&gt;Process Host Lookup&lt;/STRONG&gt; is not marked, no client can authenitcate with it´s MAC-Address.&amp;nbsp;&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 01 May 2014 08:30:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-does-acs-select-eap-type-to-send-to-client/m-p/2489793#M90824</guid>
      <dc:creator>hdussa</dc:creator>
      <dc:date>2014-05-01T08:30:37Z</dc:date>
    </item>
    <item>
      <title>Thanks for responding hdussa.</title>
      <link>https://community.cisco.com/t5/network-access-control/how-does-acs-select-eap-type-to-send-to-client/m-p/2489794#M90826</link>
      <description>&lt;P&gt;Thanks for responding hdussa.&amp;nbsp; I understand that.&amp;nbsp; Its what that policy will accept from the client.&amp;nbsp; Or is it.&lt;/P&gt;&lt;P&gt;But I'm wondering how the ACS server knows what EAP method the client wants to do?&amp;nbsp; According to that draft I linked to above, it's the server that suggests the EAP type to the client.&amp;nbsp; So do they somehow negotiate?&lt;/P&gt;&lt;P&gt;&lt;A href="https://supportforums.cisco.com/blog/154046"&gt;Here's a nice article&lt;/A&gt; but it kinda glosses over how the AS (Authenticating Server) knows what EAP method to select (see Packet 3 of the "phase 1").&amp;nbsp; And the packet capture clearly shows the ACS server saying that its using PEAP.&lt;/P&gt;</description>
      <pubDate>Fri, 02 May 2014 21:50:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-does-acs-select-eap-type-to-send-to-client/m-p/2489794#M90826</guid>
      <dc:creator>ds6123</dc:creator>
      <dc:date>2014-05-02T21:50:45Z</dc:date>
    </item>
    <item>
      <title>An EAP infrastructure</title>
      <link>https://community.cisco.com/t5/network-access-control/how-does-acs-select-eap-type-to-send-to-client/m-p/2489795#M90827</link>
      <description>&lt;P&gt;An EAP infrastructure consists of the following:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;EAP peer&lt;/STRONG&gt; Computer that is attempting to access a network, also known as an access client.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;EAP authenticator&lt;/STRONG&gt; An access point or network access server (NAS) that is requiring EAP authentication prior to granting access to a network.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;Authentication server&lt;/STRONG&gt; A server computer that negotiates the use of a specific EAP method with an EAP peer, validates the EAP peer's credentials, and authorizes access to the network. Typically, the authentication server is a Remote Authentication Dial-In User Service (RADIUS) server.&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;The EAP peer and the EAP authenticator send EAP messages using a supplicant-a software component that uses EAP to authenticate network access-and a data link layer transport protocol such as PPP or IEEE 802.1X. The EAP authenticator and the authentication server send EAP messages using RADIUS. The end result is that EAP messages are exchanged between the EAP components on the EAP peer and the authentication server. The following figure shows EAP infrastructure and information flow.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Because the logical communication of EAP messages is between the EAP components on the EAP peer and the authentication server, the EAP authenticator does not need to support any specific EAP methods.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;So it's all depend on the Endpoint (EAP Peer) which method it 's going to use not on Authentication server (Radius Server)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 04 May 2014 01:26:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-does-acs-select-eap-type-to-send-to-client/m-p/2489795#M90827</guid>
      <dc:creator>Ravi Singh</dc:creator>
      <dc:date>2014-05-04T01:26:52Z</dc:date>
    </item>
    <item>
      <title>Thanks for the response</title>
      <link>https://community.cisco.com/t5/network-access-control/how-does-acs-select-eap-type-to-send-to-client/m-p/2489796#M90828</link>
      <description>&lt;P&gt;Thanks for the response ravsingh!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV style="background:#eee;border:1px solid #ccc;padding:5px 10px;"&gt;&lt;U&gt;&lt;EM&gt;&lt;STRONG&gt;Because the logical communication of EAP messages is between the EAP components on the EAP peer and the authentication server, the EAP authenticator does not need to support any specific EAP methods.&lt;/STRONG&gt;&lt;/EM&gt;&lt;/U&gt;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sure, I totally agree.&amp;nbsp; So the wireless lan controller or switch is only the middle man and doesn't care about the EAP method.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV style="background:#eee;border:1px solid #ccc;padding:5px 10px;"&gt;&lt;U&gt;&lt;EM&gt;&lt;STRONG&gt;So it's all depend on the Endpoint (EAP Peer) which method it 's going to use not on Authentication server (Radius Server)&lt;/STRONG&gt;&lt;/EM&gt;&lt;/U&gt;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is what I'm still unclear on.&amp;nbsp; The packet captures I've seen shows the AS (Authentication Server - ie the radius server) suggest the EAP type.&amp;nbsp; I guess that's what the preferred EAP method is on ACS.&amp;nbsp; Then there must be some type of EAP negotiation that occurs.&amp;nbsp; I'm trying to find the appropriate RFC but there appears to be about 40 of them and 35 of them are obsolete.&lt;/P&gt;</description>
      <pubDate>Mon, 05 May 2014 14:48:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-does-acs-select-eap-type-to-send-to-client/m-p/2489796#M90828</guid>
      <dc:creator>ds6123</dc:creator>
      <dc:date>2014-05-05T14:48:15Z</dc:date>
    </item>
  </channel>
</rss>

