<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Flexconnect - EAP-TLS authentication after WAN failure in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/flexconnect-eap-tls-authentication-after-wan-failure/m-p/3831415#M592</link>
    <description>When FlexConnect is in connected mode (i.e. WLC CAPWAP Control tunnel is up) you have two options for EAP-TLS:&lt;BR /&gt;1) Local mode EAP-TLS (works either connected or standalone mode). This is where clients are authenticated locally on the Access Points via certificates. As long as certificates are setup in the way outlined in the guide, this will work.&lt;BR /&gt;2) Use central auth with a RADIUS server like Cisco ISE setup with EAP-TLS chain in similar fashion. With this option you lose auth with WAN down and auth must traverse the WAN to central so local is a less risky option, but could be a headache to setup (I haven't set this up so not sure).&lt;BR /&gt;&lt;BR /&gt;Mobility Express doesn't seem to support local EAP-TLS so there's a limitation there. It can still support central auth to a RADIUS server over the WAN with local switching if that is an option.&lt;BR /&gt;&lt;BR /&gt;Ric&lt;BR /&gt;</description>
    <pubDate>Wed, 03 Apr 2019 13:20:05 GMT</pubDate>
    <dc:creator>Ric Beeching</dc:creator>
    <dc:date>2019-04-03T13:20:05Z</dc:date>
    <item>
      <title>Flexconnect - EAP-TLS authentication after WAN failure</title>
      <link>https://community.cisco.com/t5/wireless/flexconnect-eap-tls-authentication-after-wan-failure/m-p/3831291#M591</link>
      <description>&lt;P&gt;Dear Ciscoers,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am studying branch authentication capabilities and I have got the needing to authorize clients even if the WAN link is down.&lt;/P&gt;&lt;P&gt;My authentication server is located in Data-center so i'm interested by the new functionnality of local EAP-TLS authentication described by this link :&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/td/docs/wireless/controller/8-1/configuration-guide/b_cg81/b_cg81_chapter_0101101.html#ID1324" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/td/docs/wireless/controller/8-1/configuration-guide/b_cg81/b_cg81_chapter_0101101.html#ID1324&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've seen these tables&amp;nbsp;but I didn't really understood what is possible and what is not.&lt;/P&gt;&lt;P&gt;So, could you confirm that this method is compatible with Flexconnect "connected" mode ? We really don't need any local server, Flexconnect AP take completely authentication in charge ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And, subsidiary question : Is this possible with Mobility Express AP ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks a lot for your help.&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 17:11:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/flexconnect-eap-tls-authentication-after-wan-failure/m-p/3831291#M591</guid>
      <dc:creator>julbvt</dc:creator>
      <dc:date>2021-07-05T17:11:33Z</dc:date>
    </item>
    <item>
      <title>Re: Flexconnect - EAP-TLS authentication after WAN failure</title>
      <link>https://community.cisco.com/t5/wireless/flexconnect-eap-tls-authentication-after-wan-failure/m-p/3831415#M592</link>
      <description>When FlexConnect is in connected mode (i.e. WLC CAPWAP Control tunnel is up) you have two options for EAP-TLS:&lt;BR /&gt;1) Local mode EAP-TLS (works either connected or standalone mode). This is where clients are authenticated locally on the Access Points via certificates. As long as certificates are setup in the way outlined in the guide, this will work.&lt;BR /&gt;2) Use central auth with a RADIUS server like Cisco ISE setup with EAP-TLS chain in similar fashion. With this option you lose auth with WAN down and auth must traverse the WAN to central so local is a less risky option, but could be a headache to setup (I haven't set this up so not sure).&lt;BR /&gt;&lt;BR /&gt;Mobility Express doesn't seem to support local EAP-TLS so there's a limitation there. It can still support central auth to a RADIUS server over the WAN with local switching if that is an option.&lt;BR /&gt;&lt;BR /&gt;Ric&lt;BR /&gt;</description>
      <pubDate>Wed, 03 Apr 2019 13:20:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/flexconnect-eap-tls-authentication-after-wan-failure/m-p/3831415#M592</guid>
      <dc:creator>Ric Beeching</dc:creator>
      <dc:date>2019-04-03T13:20:05Z</dc:date>
    </item>
    <item>
      <title>Re: Flexconnect - EAP-TLS authentication after WAN failure</title>
      <link>https://community.cisco.com/t5/wireless/flexconnect-eap-tls-authentication-after-wan-failure/m-p/3832022#M593</link>
      <description>&lt;P&gt;Thanks for your answer &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;3) The third option could be to activate both &lt;U&gt;central auth&lt;/U&gt; and «&amp;nbsp;&lt;EM&gt;AP local mode Authentication&lt;/EM&gt;&amp;nbsp;»&amp;nbsp;?&lt;/P&gt;&lt;P&gt;- When the WLC and the ISE are reachable, Flexconnect AP use the central authentication.&lt;/P&gt;&lt;P&gt;- When the tunnel is &lt;EM&gt;down&lt;/EM&gt;, WLC and ISE are not reachable but Flexconnect AP could use local authentication like below.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="351041" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/33535iBD10BB2721B37E5E/image-size/large?v=v2&amp;amp;px=999" role="button" title="351041" alt="351041" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is this a scenario thinkable&amp;nbsp;?&lt;/P&gt;</description>
      <pubDate>Thu, 04 Apr 2019 08:11:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/flexconnect-eap-tls-authentication-after-wan-failure/m-p/3832022#M593</guid>
      <dc:creator>julbvt</dc:creator>
      <dc:date>2019-04-04T08:11:45Z</dc:date>
    </item>
    <item>
      <title>Re: Flexconnect - EAP-TLS authentication after WAN failure</title>
      <link>https://community.cisco.com/t5/wireless/flexconnect-eap-tls-authentication-after-wan-failure/m-p/3832145#M594</link>
      <description>Yes sorry, I should have worded answer 1 more clearly. That will work too &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;</description>
      <pubDate>Thu, 04 Apr 2019 11:16:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/flexconnect-eap-tls-authentication-after-wan-failure/m-p/3832145#M594</guid>
      <dc:creator>Ric Beeching</dc:creator>
      <dc:date>2019-04-04T11:16:41Z</dc:date>
    </item>
  </channel>
</rss>

