cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1566
Views
0
Helpful
2
Replies

ACS 5.1 EAP-TLS

willgraham
Level 1
Level 1

EAP-TLS is failing.

See log below.

2 Replies 2

willgraham
Level 1
Level 1
Below are the steps and attached is the doc containing all of the info. STUCK!


Steps

11001  Received RADIUS Access-Request
11017  RADIUS created a new session
Evaluating Service Selection Policy
15004  Matched rule
15012  Selected Access Service - WLC
11507  Extracted EAP-Response/Identity
12500  Prepared EAP-Request proposing EAP-TLS with challenge
11006  Returned RADIUS Access-Challenge
11001  Received RADIUS Access-Request
11018  RADIUS is re-using an existing session
12502  Extracted EAP-Response containing EAP-TLS challenge-response and accepting EAP-TLS as negotiated
12800  Extracted first TLS record; TLS handshake started.
12805  Extracted TLS ClientHello message.
12806  Prepared TLS ServerHello message.
12807  Prepared TLS Certificate message.
12809  Prepared TLS CertificateRequest message.
12505  Prepared EAP-Request with another EAP-TLS challenge
11006  Returned RADIUS Access-Challenge
11001  Received RADIUS Access-Request
11018  RADIUS is re-using an existing session
12504  Extracted EAP-Response containing EAP-TLS challenge-response
11514  Unexpectedly received empty TLS message; treating as a rejection by the client
12512  Treat the unexpected TLS acknowledge message as a rejection from the client
11504  Prepared EAP-Failure
11003  Returned RADIUS Access-Reject

I also have this issue. I have done Debugs on Wireless Controllers for dot1x and not seeing anything except a deny after three attempts.

Is the Local ACS Certificate supposed to be the Certificate created by the CA or is it dynamically generated?

Thanks