cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
999
Views
0
Helpful
4
Replies

EAP Chaining with Machine TLS and User PEAP

zma
Level 1
Level 1

We are deploying an ISE based .1x. The design is to use eap-tls for machine and eap-peap for user. Apparently EAP-Chaining is recommended, but can anyone confirm if we can do chaining based on machine TLS and user PEAP. I have done some investigation and could not find any supporting document, but not any document saying not supporting either. Looking at Anyconnect profile editor, it does not look like this configuration is supported. Has anyone done this before?

 

Thanks a lot.

4 Replies 4

jan.nielsen
Level 7
Level 7

Yes, that is possible, i use it at a few different customers.

Thanks Jan. Do you have any info or link I can follow?

http://www.cisco.com/c/dam/en/us/solutions/collateral/enterprise/design-zone-security/howto_80_eapchaining_deployment.pdf

 

Just change the authentication policy to allow the methods you want to use under eap-fast (eap-chaining) and use the same ones in your nam client configuration settings.

 

 

Thanks again. I have had another look at profile editor, it is configurable.