07-23-2020 11:49 AM
Hello, ISE 2.6 patch 7 PEAP Outer/MSCHAPv2 Inner 3850 switch IOS 16.9.4 Windows 10. 802.1x is enabled via GPO ISE logs show successful PEAP negotiation but when ISE sends inner MSCHAPv2 challenge....ISE shows endpoint supplicant abandon and start new. What's interesting is we do not see any radius debug log on the NAD. the show authentications interface detail shows authc with 802.1x. Any ideas?
07-23-2020 03:05 PM
07-23-2020 03:39 PM
Hi,
Thanks for the quick response.
This is a green field. Just installed.
ISE log shows 2 workstations successfully hitting the correct authz policy. I.e. completing both PEAP and MSCHAPv2. Unfortunately all other pc is failing with the error posted. It's in monitor mode so no major outage.
07-23-2020 05:20 PM
Are there any differences between the working and non-working PCs in relation to support for UEFI/SecureBoot?
Be aware that, for Win10 PCs with UEFI//SecureBoot enabled, the default domain policy likely enables the Credential Guard feature which breaks MSCHAPv2.
You might want to check the supplicant settings for the non-working PCs to see if the following option is greyed out. If it is, CG is enabled and MSCHAPv2 will not work. You would need to disable CG in the domain policy or look at moving to EAP-TLS, using a different supplicant (like NAM), etc.
07-23-2020 08:40 PM
Yes Gregg! I do remember seeing that greyed out.
I will confirm tomorrow.
Thanks Gregg!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide