<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 9120 EWC EAP-TLS support in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/9120-ewc-eap-tls-support/m-p/5289344#M283175</link>
    <description>&lt;P&gt;You don't say what actual version of software you are using?&amp;nbsp; 17.6 could mean anything from 17.6.1 to 17.6.8!&lt;BR /&gt;Either way, 17.6 is almost end of life - it has already passed the&amp;nbsp;&lt;STRONG&gt;End of SW Maintenance &lt;/STRONG&gt;and&amp;nbsp;&lt;STRONG&gt;End of Vulnerability/Security Support&amp;nbsp;&lt;/STRONG&gt;dates!&amp;nbsp; So you really should be looking at updating.&amp;nbsp; Refer to the TAC recommended code link below.&lt;/P&gt;
&lt;P&gt;Check your config using the Config Analyzer (link below) using the output from "&lt;STRONG&gt;&lt;FONT face="courier new,courier"&gt;show tech wireless&lt;/FONT&gt;&lt;/STRONG&gt;".&amp;nbsp; This will highlight many common mistakes and best practices.&amp;nbsp; Also refer to the Best Practices link below.&lt;/P&gt;
&lt;P&gt;The radioactive trace will show what response you get back from the radius server (if any).&amp;nbsp; If you're getting back a reject then that confirms it's the server rejecting the client and you need to check the server and client logs for the reason.&amp;nbsp; If you're not getting a reply then it's your connection to the radius that's the problem - either network connectivity (routing, firewalls, ACLs) or incorrect radius secret.&amp;nbsp; Be careful about using special characters in the key - try to stick to standard ASCII characters to be safe - or if the key is very long then try shortening it.&lt;/P&gt;</description>
    <pubDate>Fri, 09 May 2025 07:32:46 GMT</pubDate>
    <dc:creator>Rich R</dc:creator>
    <dc:date>2025-05-09T07:32:46Z</dc:date>
    <item>
      <title>9120 EWC EAP-TLS support</title>
      <link>https://community.cisco.com/t5/wireless/9120-ewc-eap-tls-support/m-p/5289136#M283155</link>
      <description>&lt;P&gt;Hi all,&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have 9120 running EWC 17.6 firmware version. We are trying to implement EAP-TLS on client laptops. Below is the customer setup&lt;/P&gt;&lt;P&gt;1) Windows server running AD and CS services&lt;/P&gt;&lt;P&gt;2) Windows 11 laptops / Windows 10 laptops&lt;/P&gt;&lt;P&gt;3) Aruba ClearPass&lt;/P&gt;&lt;P&gt;4) Cisco 9120 APs running EWC (no physical controller)&lt;/P&gt;&lt;P&gt;Now we have already testing clearpass with cisco C1000 switch and its working perfectly ok with EAP-TLS. But for some reason, the AP doesnt support EAP-TLS. When we try to attempt the EAP-PEAP from the laptop, we are able to connect successfully, but when we set the authentication mode to EAP-TLS (smart card option) in laptop, the hit that we get on the clearpass doesnt even show EAP type. Without changing any setup, when we deploy Aruba AP (505) and broadcast the same SSID, the client is able to connect on first attempt using EAP-TLS. But for some reason its not able to connect via cisco 9120 EWC.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I just want to confirm that is there any limitation that its not supporting, anything special we need to do to enable EAP-TLS? if there any guide available that shows EAP-TLS with any NAC (ISE, FortiNAC etc), we can use that to see if we have configured EWC correctly. For reference purpose i have followed below video and like i said i am able to connect via EAP-PEAP but not EAP-TLS.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.youtube.com/watch?v=-RQANru0l_k" target="_blank"&gt;https://www.youtube.com/watch?v=-RQANru0l_k&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 08 May 2025 16:46:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/9120-ewc-eap-tls-support/m-p/5289136#M283155</guid>
      <dc:creator>Engineer101</dc:creator>
      <dc:date>2025-05-08T16:46:59Z</dc:date>
    </item>
    <item>
      <title>Re: 9120 EWC EAP-TLS support</title>
      <link>https://community.cisco.com/t5/wireless/9120-ewc-eap-tls-support/m-p/5289142#M283156</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;-&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1236639"&gt;@Engineer101&lt;/a&gt;&amp;nbsp; &amp;nbsp; &lt;EM&gt;&amp;nbsp;&amp;gt;....But for some reason &lt;FONT color="#FF6600"&gt;its not able to connect via cisco 9120 EWC.&amp;nbsp;&lt;/FONT&gt;&lt;/EM&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Track the client when it tries to connect using :&amp;nbsp;&lt;A href="https://logadvisor.cisco.com/logadvisor/wireless/9800/9800ClientConnectivity" target="_blank"&gt;https://logadvisor.cisco.com/logadvisor/wireless/9800/9800ClientConnectivity&lt;/A&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;These so called &lt;EM&gt;&lt;STRONG&gt;RadioActive Traces&lt;/STRONG&gt; &lt;/EM&gt;can be analyzed with :&amp;nbsp;&lt;A href="https://cway.cisco.com/wireless-debug-analyzer/" target="_blank"&gt;Wireless Debug Analyzer&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Thu, 08 May 2025 16:57:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/9120-ewc-eap-tls-support/m-p/5289142#M283156</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2025-05-08T16:57:18Z</dc:date>
    </item>
    <item>
      <title>Re: 9120 EWC EAP-TLS support</title>
      <link>https://community.cisco.com/t5/wireless/9120-ewc-eap-tls-support/m-p/5289232#M283157</link>
      <description>&lt;P&gt;What you need to know is that on a Cisco wireless, EWC or Controller, you just configure 802.1x, that is it.&amp;nbsp; It's defined on the radius to allow EAP-TLS and or PEAP.&amp;nbsp; As far as Windows is concerned, if configured for EAP-TLS and that fails, then users get prompt to enter credentials.&amp;nbsp; I would look at the ClearPass radius logs and see if its hitting the right policy and why its failing when using EAP-TLS.&amp;nbsp; There might be additional configuration on the ClearPass side to authenticate the Cisco Wireless.&amp;nbsp; You would need to hit up the Aruba forum for help on that.&lt;/P&gt;
&lt;P&gt;This is similar to the video you were using:&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/217935-configure-9800-wlc-integration-with-arub.pdf" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/217935-configure-9800-wlc-integration-with-arub.pdf&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 08 May 2025 19:22:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/9120-ewc-eap-tls-support/m-p/5289232#M283157</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2025-05-08T19:22:17Z</dc:date>
    </item>
    <item>
      <title>Re: 9120 EWC EAP-TLS support</title>
      <link>https://community.cisco.com/t5/wireless/9120-ewc-eap-tls-support/m-p/5289344#M283175</link>
      <description>&lt;P&gt;You don't say what actual version of software you are using?&amp;nbsp; 17.6 could mean anything from 17.6.1 to 17.6.8!&lt;BR /&gt;Either way, 17.6 is almost end of life - it has already passed the&amp;nbsp;&lt;STRONG&gt;End of SW Maintenance &lt;/STRONG&gt;and&amp;nbsp;&lt;STRONG&gt;End of Vulnerability/Security Support&amp;nbsp;&lt;/STRONG&gt;dates!&amp;nbsp; So you really should be looking at updating.&amp;nbsp; Refer to the TAC recommended code link below.&lt;/P&gt;
&lt;P&gt;Check your config using the Config Analyzer (link below) using the output from "&lt;STRONG&gt;&lt;FONT face="courier new,courier"&gt;show tech wireless&lt;/FONT&gt;&lt;/STRONG&gt;".&amp;nbsp; This will highlight many common mistakes and best practices.&amp;nbsp; Also refer to the Best Practices link below.&lt;/P&gt;
&lt;P&gt;The radioactive trace will show what response you get back from the radius server (if any).&amp;nbsp; If you're getting back a reject then that confirms it's the server rejecting the client and you need to check the server and client logs for the reason.&amp;nbsp; If you're not getting a reply then it's your connection to the radius that's the problem - either network connectivity (routing, firewalls, ACLs) or incorrect radius secret.&amp;nbsp; Be careful about using special characters in the key - try to stick to standard ASCII characters to be safe - or if the key is very long then try shortening it.&lt;/P&gt;</description>
      <pubDate>Fri, 09 May 2025 07:32:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/9120-ewc-eap-tls-support/m-p/5289344#M283175</guid>
      <dc:creator>Rich R</dc:creator>
      <dc:date>2025-05-09T07:32:46Z</dc:date>
    </item>
  </channel>
</rss>

