09-20-2022 04:57 AM
Hi,
I'm having issues getting some IoT devices authenitcating with Cisco ISE. We are running ver 3.1.
The supplier says his devices support
In Cisco ISE > Settings > Security Settings
i have disabled TLS 1.0 and disabled SHA1 ciphers.
if i enable both of those settings the device is able to auth ok. Is there a list somewhere of which ciphers cisco ISE supports? Cant understand why enabling SHA1 allows the above to work.
Solved! Go to Solution.
09-20-2022 05:12 AM - edited 09-20-2022 05:16 AM
Look at release notes : - due to security reason those ciphers are disabled by default.
https://www.cisco.com/c/en/us/td/docs/security/ise/3-1/release_notes/b_ise_31_RN.html
supported matrix :
https://www.cisco.com/c/en/us/td/docs/security/ise/3-1/compatibility_doc/b_ise_sdt_31.html#id_89206
09-20-2022 05:12 AM - edited 09-20-2022 05:16 AM
Look at release notes : - due to security reason those ciphers are disabled by default.
https://www.cisco.com/c/en/us/td/docs/security/ise/3-1/release_notes/b_ise_31_RN.html
supported matrix :
https://www.cisco.com/c/en/us/td/docs/security/ise/3-1/compatibility_doc/b_ise_sdt_31.html#id_89206
09-20-2022 05:32 AM
thanks - TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256 is enabled by default.
In Cisco ISE Radius logs. is there a way to see what cipher was used? If the authentication fails, it says. but if it succeeds there's no mention of the cipher userd.
Failed Auth
Successful Auth
10-02-2022 10:27 AM
You may submit that as an enhancement request @ https://cs.co/ise-wish
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide