<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic EAP-FAST With MFA in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/eap-fast-with-mfa/m-p/3412860#M598</link>
    <description>&lt;P&gt;Hi, is it possible to deploy EAP-FAST without the anyconnect NAM module? I'm trying to use the option from the windows drop down list for the authentication methods but getting the attached error message and ISE complaining about not finding the authentication method.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Mon, 05 Jul 2021 15:49:41 GMT</pubDate>
    <dc:creator>NETAD</dc:creator>
    <dc:date>2021-07-05T15:49:41Z</dc:date>
    <item>
      <title>EAP-FAST With MFA</title>
      <link>https://community.cisco.com/t5/wireless/eap-fast-with-mfa/m-p/3412860#M598</link>
      <description>&lt;P&gt;Hi, is it possible to deploy EAP-FAST without the anyconnect NAM module? I'm trying to use the option from the windows drop down list for the authentication methods but getting the attached error message and ISE complaining about not finding the authentication method.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 15:49:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/eap-fast-with-mfa/m-p/3412860#M598</guid>
      <dc:creator>NETAD</dc:creator>
      <dc:date>2021-07-05T15:49:41Z</dc:date>
    </item>
    <item>
      <title>Re: EAP-FAST With MFA</title>
      <link>https://community.cisco.com/t5/wireless/eap-fast-with-mfa/m-p/3412921#M599</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;From Cisco docs:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;"&lt;/P&gt;
&lt;H2 class="p_H_Head1"&gt;EAP-FAST Error Messages and Prompts&lt;/H2&gt;
&lt;PRE&gt;&lt;SPAN class="pEM_ErrMsg"&gt;&lt;SPAN class="cBoldNormal"&gt;Error Message&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt; Automatic PAC provisioning is enabled for this profile. However, a 
valid PAC that matches the server to which the client adapter is connecting could 
not be found. Do you wish to obtain a new security credential (PAC)?
&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;P class="pEA_ErrAct"&gt;&lt;SPAN class="cBoldNormal"&gt;Recommended Action&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;Yes&amp;nbsp;&lt;/SPAN&gt;to provision a new PAC for this server using your existing credentials or click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;No&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;to cancel the operation. If you click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;No&lt;/SPAN&gt;, the client adapter will fail the authentication."&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/wireless/wlan_adapter/cb21ag/user/vista/1-0/configuration/guide/cb21ag10vistaconfigguide/messages_ap.html" target="_self"&gt;https://www.cisco.com/c/en/us/td/docs/wireless/wlan_adapter/cb21ag/user/vista/1-0/configuration/guide/cb21ag10vistaconfigguide/messages_ap.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-If I helped you somehow, please, rate it as useful.-i&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Jul 2018 21:03:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/eap-fast-with-mfa/m-p/3412921#M599</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2018-07-09T21:03:58Z</dc:date>
    </item>
    <item>
      <title>Re: EAP-FAST With MFA</title>
      <link>https://community.cisco.com/t5/wireless/eap-fast-with-mfa/m-p/3412934#M600</link>
      <description>&lt;P&gt;Hi Flavio, thanks. Is the anyconnect client necessary to configure EAP-FAST?&lt;/P&gt;</description>
      <pubDate>Mon, 09 Jul 2018 22:00:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/eap-fast-with-mfa/m-p/3412934#M600</guid>
      <dc:creator>NETAD</dc:creator>
      <dc:date>2018-07-09T22:00:54Z</dc:date>
    </item>
    <item>
      <title>Re: EAP-FAST With MFA</title>
      <link>https://community.cisco.com/t5/wireless/eap-fast-with-mfa/m-p/3412946#M601</link>
      <description>&lt;P&gt;Don't think so. However, looks like this EAP method is not used anymore. Are you using Windows XP? Windows 7 and 10 seems not support anymore.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;Looks like EAP TLS or PEAP is currently available.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-If I helped you somehow, please, rate it as useful.-&lt;/P&gt;</description>
      <pubDate>Mon, 09 Jul 2018 22:54:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/eap-fast-with-mfa/m-p/3412946#M601</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2018-07-09T22:54:29Z</dc:date>
    </item>
    <item>
      <title>Re: EAP-FAST With MFA</title>
      <link>https://community.cisco.com/t5/wireless/eap-fast-with-mfa/m-p/3412956#M602</link>
      <description>We're using Windows 7 and Windows 10. you mean EAP-Fast isn't supported on those anymore with or without the anyconnect client?</description>
      <pubDate>Mon, 09 Jul 2018 23:10:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/eap-fast-with-mfa/m-p/3412956#M602</guid>
      <dc:creator>NETAD</dc:creator>
      <dc:date>2018-07-09T23:10:58Z</dc:date>
    </item>
    <item>
      <title>Re: EAP-FAST With MFA</title>
      <link>https://community.cisco.com/t5/wireless/eap-fast-with-mfa/m-p/3417054#M603</link>
      <description>&lt;P&gt;If you are not currently using NAM and using the Native supplicant for EAP-Fast you most likely have the EAP-Plugins that were provided to Microsoft years ago.&amp;nbsp; You can still download them from a few different location, one of which is in the Surface bundle here.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.microsoft.com/en-us/download/details.aspx?id=46703" target="_blank"&gt;https://www.microsoft.com/en-us/download/details.aspx?id=46703&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That said, for multi-factor auth you will probably want the inner method of EAP-Fast to use GTC, and not&amp;nbsp;MSCHAPv2.&amp;nbsp; From the screenshot you provided the inner method sent to ISE was MSCHAPv2, and ISE tried to send this off to presumably your MFA server, and the server rejected it.&amp;nbsp; I suspect the server is expecting GTC.&amp;nbsp; I don't know your entire setup, but going off what you said this is my best guess.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Steve S.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Jul 2018 17:55:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/eap-fast-with-mfa/m-p/3417054#M603</guid>
      <dc:creator>stsargen</dc:creator>
      <dc:date>2018-07-17T17:55:37Z</dc:date>
    </item>
    <item>
      <title>Re: EAP-FAST With MFA</title>
      <link>https://community.cisco.com/t5/wireless/eap-fast-with-mfa/m-p/3417074#M605</link>
      <description>&lt;P&gt;This windows native supplicant kept doing mschapv2 for the inner tunnel. I ended up using the anyconnect profile editor to create a profile for EAP-FAST with EAP-GTC and it worked.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;One last question. Does EAP-FAST require a cert on ISE or this is just with PEAP?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 17 Jul 2018 18:35:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/eap-fast-with-mfa/m-p/3417074#M605</guid>
      <dc:creator>NETAD</dc:creator>
      <dc:date>2018-07-17T18:35:37Z</dc:date>
    </item>
    <item>
      <title>Re: EAP-FAST With MFA</title>
      <link>https://community.cisco.com/t5/wireless/eap-fast-with-mfa/m-p/3417090#M607</link>
      <description>&lt;P&gt;EAP-Fast does not require the use of client or server certificates when performing unauthenticated provisioning.&amp;nbsp; The tunnel is established using anonymous DH (Diffie Hellman) exchange (less secure, not recommended).&amp;nbsp; If you use authenticated provisioning the TLS tunnel is established using the ISE server certificate.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This doc explains a lot of this in detail.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless-mobility/eap-fast/200322-Understanding-EAP-FAST-and-Chaining-imp.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/wireless-mobility/eap-fast/200322-Understanding-EAP-FAST-and-Chaining-imp.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;PEAP always requires the server certificate.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Jul 2018 18:55:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/eap-fast-with-mfa/m-p/3417090#M607</guid>
      <dc:creator>stsargen</dc:creator>
      <dc:date>2018-07-17T18:55:16Z</dc:date>
    </item>
  </channel>
</rss>

