08-08-2011 05:41 AM - edited 03-10-2019 06:17 PM
Hi
Im trying to setup 802.1x with ACS 5.2 but am struggling as its very differnet to ACS 4.2.
I have setup the ACS to be the domain and think i have setup up the External Idnetity Store, however when i try to authenticate a pc using authentication Medthod 'PEAP (EAP-MSCHAPv2), i get a failure reason '22056 Subject not found in the applicable identity store'
Marco
Solved! Go to Solution.
08-09-2011 10:35 AM
Hi Marco,
i guess you've missed a mapping configuration in the Access Policy Section.
Create a Access Service name it AS-802.1x select User Select Service Type and select Network Access. Select the Policy Structure Identity and Authorization. Select PEAP as allowed Protocol. Click Finish
You'll see the new service click Identity.
Select the identity source you've created then save.
Click on authorization
Select a default authorization rule permit access and save.
Create a Service Access Rule name it 802.1x
Select Protocol Radius as Condition and as Compound Condition select RADIUS-IETF:Service-Type match Framed then select the service you created before.
then you can try again.
regards
alex
08-09-2011 10:35 AM
Hi Marco,
i guess you've missed a mapping configuration in the Access Policy Section.
Create a Access Service name it AS-802.1x select User Select Service Type and select Network Access. Select the Policy Structure Identity and Authorization. Select PEAP as allowed Protocol. Click Finish
You'll see the new service click Identity.
Select the identity source you've created then save.
Click on authorization
Select a default authorization rule permit access and save.
Create a Service Access Rule name it 802.1x
Select Protocol Radius as Condition and as Compound Condition select RADIUS-IETF:Service-Type match Framed then select the service you created before.
then you can try again.
regards
alex
08-10-2011 01:10 AM
Alex
Thanks. That is what i was missing.
Found another link on there that was having the same problem.
Document is located here
https://supportforums.cisco.com/docs/DOC-13545. though not sure if can donwload it properly but if do a google search for the document name, you can then download from there
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide