cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1527
Views
0
Helpful
6
Replies

EAP-TLS machine authentication with ldaps

zacakg
Frequent Visitor
Frequent Visitor

Hello,

We want to use ldaps for communication with AD. Is it possible to use ldaps for machine authentication with EAP-TLS?

Regards,

6 Replies 6

balaji.bandi
Hall of Fame
Hall of Fame

i do not see any reason its not going to work.

https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/216190-configure-and-troubleshoot-ise-with-exte.html

BB

=====️ Preenayamo Vasudevam ️=====

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

zacakg
Frequent Visitor
Frequent Visitor

Hello,

The document indicates that machine authentication is not possible with ldap.

Note: LDAP Identity Source on ISE is used only for User authentication.

Regards,

 

i have re-read your OP 

 ldaps for communication with AD

can you explain this more to understand better. (as i was in impression you using ISE and Externals source as X)

or you looking to integrade directly with LDAPs?

 

BB

=====️ Preenayamo Vasudevam ️=====

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

zacakg
Frequent Visitor
Frequent Visitor

Hi Balaji,

We are trying to add an ldaps external identity source. And we want to authenticate devices with eap-tls(machine authentication). Is it possible to authenticate clients with eap-tls via ldaps server?

Regards,

Now we go more deep here, what WLC controller and what code running - then check the WLC admin guide is that supported ?

may help if you using WLC 9800 :

https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/216744-configuring-catalyst-9800-wlc-with-ldap.html

 

BB

=====️ Preenayamo Vasudevam ️=====

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

@zacakg if you are just performing EAP-TLS authentication, that is between the client and ISE.

Lookup to an external identity source is optional. You would need to configure a Certificate Authentication Profile (CAP) and select the Identity Store and choose an option for Match Client Certificate Against Certificate In Identity Store.   https://www.cisco.com/c/en/us/td/docs/security/ise/3-1/admin_guide/b_ise_admin_3_1/b_ISE_admin_31_asset_visibility.html?bookSearch=true#ID425

Reference the CAP in the AuthC rules.