<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Which EAP to use in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/which-eap-to-use/m-p/1557962#M10788</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can I jump on this discussion and change the requirments a little. A customer of mine has the same issue, he wants a security mechanism that allows the inclusion of mobile devices but wants to be able to control (read stop) the use of devices brought in from home. This is an NHS Trust that is willing to purchase ipads etc for certain staff but only those devices should be allowed to connect.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;He's suggested that EAP-TLS is the only way to do this but as I'm not an expert in this area can I ask for advice?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 19 Aug 2011 06:46:32 GMT</pubDate>
    <dc:creator>adbaker</dc:creator>
    <dc:date>2011-08-19T06:46:32Z</dc:date>
    <item>
      <title>Which EAP to use</title>
      <link>https://community.cisco.com/t5/wireless/which-eap-to-use/m-p/1557959#M10785</link>
      <description>&lt;P&gt;I am looking for the best EAP method to use for a diverse environment where end clients will be a mixture of Windows XP, Windows 7 and iPad devices.&amp;nbsp; I would like to use one SSID and security method for all devices.&amp;nbsp; Microsoft AD 2008R2 is the back end database I can authenticate to.&amp;nbsp; I only want company devices to be able to authenticate.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Which EAP flavor would help in all of these criteria?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have been looking at EAP-FAST, PEAP and EAP-TLS.&amp;nbsp; Any feedback would be most appreciated.&lt;/P&gt;</description>
      <pubDate>Sun, 04 Jul 2021 02:13:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/which-eap-to-use/m-p/1557959#M10785</guid>
      <dc:creator>jlhainy</dc:creator>
      <dc:date>2021-07-04T02:13:56Z</dc:date>
    </item>
    <item>
      <title>Re: Which EAP to use</title>
      <link>https://community.cisco.com/t5/wireless/which-eap-to-use/m-p/1557960#M10786</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need to look at what your clients support really.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would go for the one with least configuration needed from certificates perspectives and that would be eap-fast.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;eap-tls will make you install certs on clients and server along with CA&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;peap implementation is not very time consuming neither.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;Serge&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Oct 2010 22:37:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/which-eap-to-use/m-p/1557960#M10786</guid>
      <dc:creator>Serge Yasmine</dc:creator>
      <dc:date>2010-10-05T22:37:05Z</dc:date>
    </item>
    <item>
      <title>Re: Which EAP to use</title>
      <link>https://community.cisco.com/t5/wireless/which-eap-to-use/m-p/1557961#M10787</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you want a low management over head i would suggest EAP-PEAP v0. This is the most commonly used EAP today and it is Windows XP ZeroConfig friendly. Its not difficult to implement and its secure, but you want to validate certificates on the client.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;EAP-FAST is a Cisco flavor and you will likely run into devices that do not support it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;EAP-TLS is more secure because there is 2 way cert validation.&amp;nbsp; But it is a bear to manage ...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps... &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Oct 2010 05:33:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/which-eap-to-use/m-p/1557961#M10787</guid>
      <dc:creator>George Stefanick</dc:creator>
      <dc:date>2010-10-06T05:33:44Z</dc:date>
    </item>
    <item>
      <title>Which EAP to use</title>
      <link>https://community.cisco.com/t5/wireless/which-eap-to-use/m-p/1557962#M10788</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can I jump on this discussion and change the requirments a little. A customer of mine has the same issue, he wants a security mechanism that allows the inclusion of mobile devices but wants to be able to control (read stop) the use of devices brought in from home. This is an NHS Trust that is willing to purchase ipads etc for certain staff but only those devices should be allowed to connect.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;He's suggested that EAP-TLS is the only way to do this but as I'm not an expert in this area can I ask for advice?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Aug 2011 06:46:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/which-eap-to-use/m-p/1557962#M10788</guid>
      <dc:creator>adbaker</dc:creator>
      <dc:date>2011-08-19T06:46:32Z</dc:date>
    </item>
    <item>
      <title>Which EAP to use</title>
      <link>https://community.cisco.com/t5/wireless/which-eap-to-use/m-p/1557963#M10789</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have stayed away from EAP-TLS for now, simply because of the managment overhead.&amp;nbsp; I do agree it would be the most secure.&amp;nbsp; If you don't want personal mobile devices to connect, then you don't allow them to have a certificate.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My problem is that We do want to incorporate personal devices but don't want them to go on a Internal ssid and if we allow their user name to use that ssid, what is to stop them from attaching from the Internal SSID from their personal device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have 2 solutions to this.&amp;nbsp; One is to add mac authentication with PEAP and it works fine.&amp;nbsp; It is extra overhead, but still easier than EAP-TLS.&amp;nbsp; I know, I know, its not secure, but we are using it really as a way to profile corporate device vs personal devices.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The second solution is Cisco's new ISE that does device profiling and would give the same functionality without using mac authentication.&amp;nbsp; That is something I really want to look into, pending budget and maturity of the product.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Aug 2011 12:52:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/which-eap-to-use/m-p/1557963#M10789</guid>
      <dc:creator>jlhainy</dc:creator>
      <dc:date>2011-08-19T12:52:37Z</dc:date>
    </item>
    <item>
      <title>Which EAP to use</title>
      <link>https://community.cisco.com/t5/wireless/which-eap-to-use/m-p/1557964#M10790</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You could get fancy with certificates to segment the two groups. Althought after reading about ISE, it seems like its the way to go. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Aug 2011 13:01:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/which-eap-to-use/m-p/1557964#M10790</guid>
      <dc:creator>George Stefanick</dc:creator>
      <dc:date>2011-08-19T13:01:09Z</dc:date>
    </item>
    <item>
      <title>Which EAP to use</title>
      <link>https://community.cisco.com/t5/wireless/which-eap-to-use/m-p/1557965#M10791</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would have to agree George.&amp;nbsp; The ISE sounds way cool.&amp;nbsp; The problem is that I haven't even been on ACS 5.2 for a year yet.&amp;nbsp; I made the upgrade when we updated our domain controllers to 2008R2.&amp;nbsp; So as much as I want the ISE, I have some hesitations.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Aug 2011 15:31:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/which-eap-to-use/m-p/1557965#M10791</guid>
      <dc:creator>jlhainy</dc:creator>
      <dc:date>2011-08-19T15:31:25Z</dc:date>
    </item>
    <item>
      <title>Which EAP to use</title>
      <link>https://community.cisco.com/t5/wireless/which-eap-to-use/m-p/1557966#M10792</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Cisco is merging technologys WCS/Cisco Works to NCS and ACS/NAC to ISE. Its coming... They say by 2015 90% of WLAN will be using directed "managment" if you will. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the rating .. Yeah me! Blue Star! LOL&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Aug 2011 15:39:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/which-eap-to-use/m-p/1557966#M10792</guid>
      <dc:creator>George Stefanick</dc:creator>
      <dc:date>2011-08-19T15:39:04Z</dc:date>
    </item>
    <item>
      <title>Re: Which EAP to use</title>
      <link>https://community.cisco.com/t5/wireless/which-eap-to-use/m-p/1557967#M10793</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Not Sure if you got a chance to check the VoD by one of the wireless Developer Hemant on &lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;Cisco ISE and WLC (wireless lan controller).&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://community.cisco.com/videos/2497"&gt;https://supportforums.cisco.com/videos/2497&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://community.cisco.com/videos/2496"&gt;https://supportforums.cisco.com/videos/2496&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Vinay Sharma&lt;/P&gt;&lt;P&gt;Community Manager - Wireless&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 20 Aug 2011 04:16:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/which-eap-to-use/m-p/1557967#M10793</guid>
      <dc:creator>Vinay Sharma</dc:creator>
      <dc:date>2011-08-20T04:16:52Z</dc:date>
    </item>
    <item>
      <title>Re: Which EAP to use</title>
      <link>https://community.cisco.com/t5/wireless/which-eap-to-use/m-p/1557968#M10794</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Looks like the links have either been re-located or deleted.&amp;nbsp; Those are some videos I would like to see.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Aug 2011 12:58:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/which-eap-to-use/m-p/1557968#M10794</guid>
      <dc:creator>jlhainy</dc:creator>
      <dc:date>2011-08-22T12:58:18Z</dc:date>
    </item>
    <item>
      <title>Re: Which EAP to use</title>
      <link>https://community.cisco.com/t5/wireless/which-eap-to-use/m-p/1557969#M10795</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="https://community.cisco.com/videos/2478"&gt;https://supportforums.cisco.com/videos/2478&lt;/A&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This link is working for me ... try it ...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Aug 2011 17:04:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/which-eap-to-use/m-p/1557969#M10795</guid>
      <dc:creator>George Stefanick</dc:creator>
      <dc:date>2011-08-23T17:04:55Z</dc:date>
    </item>
    <item>
      <title>Re: Which EAP to use</title>
      <link>https://community.cisco.com/t5/wireless/which-eap-to-use/m-p/1557970#M10796</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jared,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You are right. pleas check these links:-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="https://community.cisco.com/videos/2478"&gt;https://supportforums.cisco.com/videos/2478&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="https://community.cisco.com/videos/2480"&gt;https://supportforums.cisco.com/videos/2480&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Vinay Sharma&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Aug 2011 06:12:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/which-eap-to-use/m-p/1557970#M10796</guid>
      <dc:creator>Vinay Sharma</dc:creator>
      <dc:date>2011-08-24T06:12:34Z</dc:date>
    </item>
  </channel>
</rss>

