<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: EAP-FAST Security level in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/eap-fast-security-level/m-p/2182878#M10627</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It is supported , there is a piece of software to download it from microsoft and it should work 7abibi.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 19 Mar 2013 09:01:24 GMT</pubDate>
    <dc:creator>maldehne</dc:creator>
    <dc:date>2013-03-19T09:01:24Z</dc:date>
    <item>
      <title>EAP-FAST Security level</title>
      <link>https://community.cisco.com/t5/wireless/eap-fast-security-level/m-p/2182869#M10618</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I use EAP-FAST in my network and I have some questions about it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) is there any vulnerability detected with EAP-FAST?&lt;/P&gt;&lt;P&gt;2) &lt;SPAN style="font-size: 10pt;"&gt;Can I restrict the establishment two or more simultaneous sessions using the same account and same PAC? how&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;3) &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;Can I use EAP-FAST with MAC address filtering through ACS&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;4) &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;What is the level of security provided by EAP-FAST? is there &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;technology &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;more security than EAP-FAST?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Thanks for your reply.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Thanks.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 04 Jul 2021 06:45:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/eap-fast-security-level/m-p/2182869#M10618</guid>
      <dc:creator>mostafa ouamou</dc:creator>
      <dc:date>2021-07-04T06:45:07Z</dc:date>
    </item>
    <item>
      <title>EAP-FAST Security level</title>
      <link>https://community.cisco.com/t5/wireless/eap-fast-security-level/m-p/2182870#M10619</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;1) Vulnerabilty if anonymous PAC provisioning is enabled machines connecting with valid user credentials will be automatically assigned a PAC and can gain access if you need to use automatic PAC provsioning to get a machine on to the network switch it on to get the machine on but switch it back off again when you are done.&lt;/P&gt;&lt;P&gt;2) i have never tried this so I can't help you on that question sorry.&lt;/P&gt;&lt;P&gt;3) If you are using ACS 5 then I am sure you could but mac filtering is not really all that secure anyway as macs can still be easily spoofed..&lt;/P&gt;&lt;P&gt;4) One of the most secure methods that you can use is EAP-TLS this is a two way certficate exchange where the ACS verfied the client certificate and the client verfies that the ACS is genuine by verifiying the server certifcate, You need a CA server in place to do this and you need to have the CA added as a trusted root on the ACS. If a client machine is lost or stolen you can revoke the certificate and stop someone from gaining access. A little less secure is EAP-PEAP the client can use their AD credentials to gain access the credentials are passed within a tunnel to protect them. The client can also bet set to validate the server certifcate in this method. To prevent users logging on with machines by using their AD credentials you can also set up a policy to check the machine exists in AD before authorising the user onto to the network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Good Post about setting this up here&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-wiki-small" href="https://community.cisco.com/docs/DOC-21825"&gt;https://supportforums.cisco.com/docs/DOC-21825&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want to be really granualar about securtiy you could start looking at ISE&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Martin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Mar 2013 23:44:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/eap-fast-security-level/m-p/2182870#M10619</guid>
      <dc:creator>Martin Hart</dc:creator>
      <dc:date>2013-03-18T23:44:00Z</dc:date>
    </item>
    <item>
      <title>EAP-FAST Security level</title>
      <link>https://community.cisco.com/t5/wireless/eap-fast-security-level/m-p/2182871#M10620</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mostafa:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- I am not really deep in what vulnerabilities availalbe. Just try to avoid anonymous provisioning like Martin mentioned. I've read somewhere before that EAP-FAST phase 0 (anonymous provisioning) is somehow vulnerable (or let us say phase 0 is easier to be compromised).&lt;/P&gt;&lt;P&gt;- From the radius server you can restrict the number of user sessoins. In ACS 5.x for example that is configured under:&amp;nbsp; &lt;/P&gt;&lt;P&gt; Access Policies -&amp;gt; Max User Session Policy.&lt;/P&gt;&lt;P&gt; You can configure the max session per user or per group.&lt;/P&gt;&lt;P&gt;- There was an early discussion here in cisco support forums if user and mac auth both can be used at the same time with ACS 5.x and we found it is possible but it needs some overhead in configuration. If you ask about EAP-FAST with only mac filtering (i.e. the mac address is considered the username that is going to be sent to the radius) then the mac address of the client must be added to the radius as both a username and a password.&lt;/P&gt;&lt;P&gt;- EAP-FAST provides good level of security. However, EAP-TLS provides more security but it is however requires more overhead for CA implementation and provisioning the certificates to every single client device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is a configuration doc: &lt;SPAN style="font-size: 10pt;"&gt;&lt;A class="jive-link-wiki-small" href="https://community.cisco.com/docs/DOC-15587"&gt;https://supportforums.cisco.com/docs/DOC-15587&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Don't forget that EAP-FAST needs usually third-party supplicants to work. e.x. Windows by default does not support EAP-FAST. You need a third party utility for EAP-FAST to work or the utility that comes with your wireless adapter (if available).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this is useful to you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Amjad&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: blue;"&gt;Rating useful replies is more useful than saying &lt;SPAN style="color: green;"&gt; "&lt;SPAN style="text-decoration: underline;"&gt;Thank you&lt;/SPAN&gt;"&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Mar 2013 05:51:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/eap-fast-security-level/m-p/2182871#M10620</guid>
      <dc:creator>Amjad Abdullah</dc:creator>
      <dc:date>2013-03-19T05:51:35Z</dc:date>
    </item>
    <item>
      <title>EAP-FAST Security level</title>
      <link>https://community.cisco.com/t5/wireless/eap-fast-security-level/m-p/2182872#M10621</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;1)&lt;/P&gt;&lt;P&gt;Everything should be fine with EAP-FAST but you should take into consideration some issues when your clients are being provisioned their PACs through inband PAC provisioning.&lt;/P&gt;&lt;P&gt;What will happen? see&lt;/P&gt;&lt;P&gt;The in-band provisioning mode&amp;nbsp; operates inside a TLS tunnel raised by Anonymous DH or Authenticated DH&amp;nbsp; or RSA algorithm for key agreement. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;A name="wp1049631"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt; To minimize the risk of exposing the user's credentials, a clear text&amp;nbsp; password should not be used outside of the protected tunnel. Therefore,&amp;nbsp; EAP-MSCHAPv2 or EAP-GTC are used to authenticate the user's credentials&amp;nbsp; within the protected tunnel. The information contained in the PAC is&amp;nbsp; also available for further authentication sessions after the inner EAP&amp;nbsp; method has completed. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Automatic In-Band PAC Provisioning, which is the&amp;nbsp; same as EAP-FAST phase zero, sends a new PAC to an end-user client over a&amp;nbsp; secured network connection. Automatic In-Band PAC Provisioning requires&amp;nbsp; no intervention of the network user or an ACS administrator, provided&amp;nbsp; that you configure ACS and the end-user client to support Automatic&amp;nbsp; In-Band PAC Provisioning. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; In general, phase zero of EAP-FAST does not authorize network access. In&amp;nbsp; this general case, after the client has successfully performed phase&amp;nbsp; zero PAC provisioning, the client must send a new EAP-FAST request in&amp;nbsp; order to begin a new round of phase one tunnel establishment, followed&amp;nbsp; by phase two authentication. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;A name="wp1049863"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt; However, if you choose the Accept Client on Authenticated Provisioning&amp;nbsp; option, ACS sends a RADIUS Access-Accept (that contains an EAP Success)&amp;nbsp; at the end of a successful phase zero PAC provisioning, and the client&amp;nbsp; is not forced to reauthenticate again. This option can be enabled only&amp;nbsp; when the Allow Authenticated In-Band PAC Provisioning option is also&amp;nbsp; enabled. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;A name="wp1013995"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt; Because transmission of PACs in phase zero is secured by MSCHAPv2&amp;nbsp; authentication, when MSCHAPv2 is vulnerable to dictionary attacks, we&amp;nbsp; recommend that you limit use of Automatic In-Band PAC Provisioning to&amp;nbsp; initial deployment of EAP-FAST. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After a large EAP-FAST deployment, PAC provisioning should be done manually to ensure the highest security for PACs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; EAP-FAST has been enhanced to support an authenticated tunnel (by using&amp;nbsp; the server certificate) inside which PAC provisioning occurs. The new&amp;nbsp; cipher suites that are enhancements to EAP-FAST, and specifically the&amp;nbsp; server certificate, are used. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;A name="wp1038672"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;2) Max user sessions&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3)Yes&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;4)PEAP ( EAP TLS )&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Side note:&lt;/P&gt;&lt;P&gt;EAP FAST is now supported on Micrsofot supplicants , so yeah it should work with third party supplicants&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;----------------------------------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;Please make sure to rate correct answers and rate the thread as answered&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Mar 2013 06:09:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/eap-fast-security-level/m-p/2182872#M10621</guid>
      <dc:creator>maldehne</dc:creator>
      <dc:date>2013-03-19T06:09:09Z</dc:date>
    </item>
    <item>
      <title>EAP-FAST Security level</title>
      <link>https://community.cisco.com/t5/wireless/eap-fast-security-level/m-p/2182873#M10622</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Amjad,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3) no I ask about &lt;SPAN style="font-size: 10pt;"&gt;user and mac auth with EAP-FAST,is it possible?if yes can you give me the configuration.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Regards.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Mar 2013 08:35:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/eap-fast-security-level/m-p/2182873#M10622</guid>
      <dc:creator>mostafa ouamou</dc:creator>
      <dc:date>2013-03-19T08:35:27Z</dc:date>
    </item>
    <item>
      <title>EAP-FAST Security level</title>
      <link>https://community.cisco.com/t5/wireless/eap-fast-security-level/m-p/2182874#M10623</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;this is sample config on ACS for leap with mac auth:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/partner/products/sw/secursw/ps2086/products_configuration_example09186a00805e7a13.shtml"&gt;http://www.cisco.com/en/US/partner/products/sw/secursw/ps2086/products_configuration_example09186a00805e7a13.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The following link how to configure mac authentication alone:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/partner/tech/tk722/tk809/technologies_configuration_example09186a008084f13b.shtml"&gt;http://www.cisco.com/en/US/partner/tech/tk722/tk809/technologies_configuration_example09186a008084f13b.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Athenciation types config in gerenal examples:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/partner/tech/tk722/tk809/technologies_configuration_example09186a00807f42e9.shtml"&gt;http://www.cisco.com/en/US/partner/tech/tk722/tk809/technologies_configuration_example09186a00807f42e9.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;EAP FAST config:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/partner/products/ps6366/products_configuration_example09186a00808e5d6b.shtml"&gt;http://www.cisco.com/en/US/partner/products/ps6366/products_configuration_example09186a00808e5d6b.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Based on the above you can easily do it all together.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--------------------------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;Please make sure to rate correct answers &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Mar 2013 08:50:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/eap-fast-security-level/m-p/2182874#M10623</guid>
      <dc:creator>maldehne</dc:creator>
      <dc:date>2013-03-19T08:50:26Z</dc:date>
    </item>
    <item>
      <title>Re: EAP-FAST Security level</title>
      <link>https://community.cisco.com/t5/wireless/eap-fast-security-level/m-p/2182875#M10624</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;well, you can check this discussion:&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://community.cisco.com/message/3886301#3886301" rel="nofollow"&gt;https://supportforums.cisco.com/message/3886301#3886301&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Maldehne pretended it will work the way he posted (he posted a screenshot about configuration).&lt;/P&gt;&lt;P&gt;Now, from my understanding to how ACS works and the radius attribute he used I would say it will work in OR scenario (user OR mac auth) but not both at the same time.&lt;/P&gt;&lt;P&gt;As maldehne is an expert TAC engineer I would suggest that you give his config a try if it works or not.&lt;/P&gt;&lt;P&gt;If it did not work I posted a suggeted config that will usually work at the same discussion but below maldehne post.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let us know which worked with you. &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Amjad&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: blue; font-size: 10pt;"&gt;Rating useful replies is more useful than saying &lt;/SPAN&gt;&lt;SPAN style="color: green;"&gt; "&lt;SPAN style="text-decoration: underline;"&gt;Thank you&lt;/SPAN&gt;"&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Mar 2013 08:50:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/eap-fast-security-level/m-p/2182875#M10624</guid>
      <dc:creator>Amjad Abdullah</dc:creator>
      <dc:date>2013-03-19T08:50:29Z</dc:date>
    </item>
    <item>
      <title>Re: EAP-FAST Security level</title>
      <link>https://community.cisco.com/t5/wireless/eap-fast-security-level/m-p/2182876#M10625</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;BLOCKQUOTE class="jive-quote"&gt;&lt;P&gt;Side note:&lt;/P&gt;&lt;P&gt;EAP FAST is now supported on Micrsofot supplicants , so yeah it should work with third party supplicants&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mohammad: what do you mean by EAP-FAST supported on microsoft supplicant?&lt;/P&gt;&lt;P&gt;It is not supported by default on windows xp or windows 7. not even newer windows 8 (see below screenshot).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you have a supported driver (intel PROset for example) your config will probably appear in the list of EAP methods in the supplicant. But that is an addition done by the driver, not by microsoft with its supplicant.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://adamsync.files.wordpress.com/2012/05/securityoptions.jpg?w=700" /&gt; &lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: blue;"&gt;Rating useful replies is more useful than saying &lt;SPAN style="color: green;"&gt; "&lt;SPAN style="text-decoration: underline;"&gt;Thank you&lt;/SPAN&gt;"&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Mar 2013 08:57:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/eap-fast-security-level/m-p/2182876#M10625</guid>
      <dc:creator>Amjad Abdullah</dc:creator>
      <dc:date>2013-03-19T08:57:49Z</dc:date>
    </item>
    <item>
      <title>Re: EAP-FAST Security level</title>
      <link>https://community.cisco.com/t5/wireless/eap-fast-security-level/m-p/2182877#M10626</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Nice words my friend. keep going.&lt;/P&gt;&lt;P&gt;Check my answer on the thread u have referred to since you have doubts about it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Mar 2013 09:00:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/eap-fast-security-level/m-p/2182877#M10626</guid>
      <dc:creator>maldehne</dc:creator>
      <dc:date>2013-03-19T09:00:06Z</dc:date>
    </item>
    <item>
      <title>Re: EAP-FAST Security level</title>
      <link>https://community.cisco.com/t5/wireless/eap-fast-security-level/m-p/2182878#M10627</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It is supported , there is a piece of software to download it from microsoft and it should work 7abibi.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Mar 2013 09:01:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/eap-fast-security-level/m-p/2182878#M10627</guid>
      <dc:creator>maldehne</dc:creator>
      <dc:date>2013-03-19T09:01:24Z</dc:date>
    </item>
    <item>
      <title>Re: EAP-FAST Security level</title>
      <link>https://community.cisco.com/t5/wireless/eap-fast-security-level/m-p/2182879#M10628</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;check this one, may be i am still pretending:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://blogs.msdn.com/b/eapteam/archive/2008/10/17/how-do-i-install-cisco-eap-fast-on-my-computer.aspx"&gt;http://blogs.msdn.com/b/eapteam/archive/2008/10/17/how-do-i-install-cisco-eap-fast-on-my-computer.aspx&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;rate me please on this if you liked it&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Mar 2013 09:03:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/eap-fast-security-level/m-p/2182879#M10628</guid>
      <dc:creator>maldehne</dc:creator>
      <dc:date>2013-03-19T09:03:18Z</dc:date>
    </item>
    <item>
      <title>Re: EAP-FAST Security level</title>
      <link>https://community.cisco.com/t5/wireless/eap-fast-security-level/m-p/2182880#M10629</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There is a piece of software but it is not from microsoft.&lt;/P&gt;&lt;P&gt;If you have intel driver you can add eap-fast to your windows supplicant like in this link:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.intel.com/support/wireless/wlan/sb/CS-032728.htm"&gt;http://www.intel.com/support/wireless/wlan/sb/CS-032728.htm&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but it works only with intel adapters.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: blue;"&gt;Rating useful replies is more useful than saying &lt;SPAN style="color: green;"&gt; "&lt;SPAN style="text-decoration: underline;"&gt;Thank you&lt;/SPAN&gt;"&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Mar 2013 09:05:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/eap-fast-security-level/m-p/2182880#M10629</guid>
      <dc:creator>Amjad Abdullah</dc:creator>
      <dc:date>2013-03-19T09:05:40Z</dc:date>
    </item>
    <item>
      <title>Re: EAP-FAST Security level</title>
      <link>https://community.cisco.com/t5/wireless/eap-fast-security-level/m-p/2182881#M10630</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Your link is workign amazingly wiht my Broadcom adapter!!&lt;/P&gt;&lt;P&gt;Now I can say Bye Bye to the anyconnect NAM. &lt;SPAN __jive_emoticon_name="laugh" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/tiny_mce3/plugins/jiveemoticons/images/spacer.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can only give 5 starts. But I strongly encourage others to give you 5s as well. &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks my teacher,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Amjad&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: blue;"&gt;Rating useful replies is more useful than saying &lt;SPAN style="color: green;"&gt; "&lt;SPAN style="text-decoration: underline;"&gt;Thank you&lt;/SPAN&gt;"&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Mar 2013 09:36:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/eap-fast-security-level/m-p/2182881#M10630</guid>
      <dc:creator>Amjad Abdullah</dc:creator>
      <dc:date>2013-03-19T09:36:58Z</dc:date>
    </item>
    <item>
      <title>EAP-FAST Security level</title>
      <link>https://community.cisco.com/t5/wireless/eap-fast-security-level/m-p/2182882#M10631</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi all&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Is there outils to check/simulate attack or intrusion with EAP-FAST?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;to ensure that all is ok.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Mar 2013 12:16:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/eap-fast-security-level/m-p/2182882#M10631</guid>
      <dc:creator>mostafa ouamou</dc:creator>
      <dc:date>2013-03-19T12:16:18Z</dc:date>
    </item>
    <item>
      <title>EAP-FAST Security level</title>
      <link>https://community.cisco.com/t5/wireless/eap-fast-security-level/m-p/2182883#M10632</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Mostafa:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we value you rate useful posts.&lt;/P&gt;&lt;P&gt;regarding your question, check this link:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.techrepublic.com/article/ultimate-wireless-security-guide-a-primer-on-cisco-eap-fast-authentication/6148557"&gt;http://www.techrepublic.com/article/ultimate-wireless-security-guide-a-primer-on-cisco-eap-fast-authentication/6148557&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Amjad&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: blue;"&gt;Rating useful replies is more useful than saying &lt;SPAN style="color: green;"&gt; "&lt;SPAN style="text-decoration: underline;"&gt;Thank you&lt;/SPAN&gt;"&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Mar 2013 12:46:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/eap-fast-security-level/m-p/2182883#M10632</guid>
      <dc:creator>Amjad Abdullah</dc:creator>
      <dc:date>2013-03-19T12:46:56Z</dc:date>
    </item>
    <item>
      <title>Re: EAP-FAST Security level</title>
      <link>https://community.cisco.com/t5/wireless/eap-fast-security-level/m-p/2182884#M10633</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Amjad,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) &lt;SPAN style="font-size: 10pt;"&gt;with EAP-FAST we provide user + PAC to authenticate there isn't any other way to add ours mac address or it add automatically&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;2) &lt;SPAN style="font-size: 10pt;"&gt;Can I configure ACS to check first username then check mac address. but if one of two failed "the authentication fail".&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;3) Can I do a local MAC filtring in the WLC if authentication user+mac is not possible.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Thanks with rate&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Mar 2013 15:30:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/eap-fast-security-level/m-p/2182884#M10633</guid>
      <dc:creator>mostafa ouamou</dc:creator>
      <dc:date>2013-03-19T15:30:46Z</dc:date>
    </item>
  </channel>
</rss>

