When we are following the abovedeployment "ISE 3.2 EAP-TLS with Microsoft Azure AD" only with user certificate, should we worry about below concerns about large EAP packet (Wireless) highlighted with "usually Client Certificate"?
Microsoft Windows sends EAP-TLS fragments (usually Client Certificate) that are 1,486 or 1,482 bytes long. For this value size, the Ethernet frame is 1,500 bytes.
If the ISE PSNs are deployed in Azure, then the out-of-sequence UDP issues caused by the certificate payload will be an issue. If the PSNs are deployed in any other location (on-prem, AWS, etc) it will not be an issue.
Learn, share, save
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.