cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1168
Views
5
Helpful
4
Replies

ISE 2.6 Cipher Suites

russell.sage
Level 3
Level 3

Hi

Does anyone know if ISE2.6 supports the cipher suites needed for WPA3.

4 Replies 4

balaji.bandi
Hall of Fame
Hall of Fame

ISE 2.6 : Supported Cipher Suites

 

https://www.cisco.com/c/en/us/td/docs/security/ise/2-7/compatibility_doc/b_ise_sdt_27.html#supportedciphersuites

 

WPA3 - is different way it was deployed : check some example :

 

https://mrncciew.com/2019/11/29/wpa3-sae-mode/

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Marvin Rhoads
Hall of Fame
Hall of Fame

WPA3 (Enterprise or Personal) is between the client and the AP - not with ISE.

In the case of WPA3 Enterprise the WLC talks to ISE via RADIUS and the client communicates over EAP-TLS. That is fully supported by ISE (2.6 or otherwise).

https://www.cisco.com/c/en/us/products/collateral/wireless/catalyst-9100ax-access-points/wpa3-dep-guide-og.html

 

That is interesting my enquiry was driven by a Cisco Meraki statement

"To use WPA3 enterprise, the RADIUS servers must use one of the permitted EAP ciphers:

* TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384
* TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
* TLS_DHE_RSA_WITH_AES_256_GCM_SHA384
"
Source https://documentation.meraki.com/MR/WiFi_Basics_and_Best_Practices/WPA3_Encryption_and_Configuration_Guide

Yes, those are ciphers used by EAP-TLS. The first two in the list you cited are supported by ISE as noted in the link that @balaji.bandi shared.