01-05-2011 06:17 AM - edited 03-10-2019 05:41 PM
I'm using ACS 4.2 and I defined in global Authentication Setup the EAP to use EAP-MSCHAPv2 and EAP-TLS.
For some of my users I would like to put in place 802.1x on wired with EAP-TLS only. How to do to restrict EAP-TLS use only on a set of devices (Cisco LAn switches for example or for WLC Controller)?
Thanks in advance.
Solved! Go to Solution.
01-05-2011 06:22 AM
Hello,
You could use Network Access Profiles (NAPs) to filter the Radius access-request based on the AAA client and EAP protocol in use:
You cannot explicitly force AAA clients to use a specific EAP authentication method, but you could filter access-requests based on both the AAA client they come from and the EAP authentication method in use.
Hope this helps,
Fede
--
If this helps you and/or answers your question please mark the question as "answered" and/or rate it, so other users can easily find it.
01-05-2011 06:22 AM
Hello,
You could use Network Access Profiles (NAPs) to filter the Radius access-request based on the AAA client and EAP protocol in use:
You cannot explicitly force AAA clients to use a specific EAP authentication method, but you could filter access-requests based on both the AAA client they come from and the EAP authentication method in use.
Hope this helps,
Fede
--
If this helps you and/or answers your question please mark the question as "answered" and/or rate it, so other users can easily find it.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide