07-02-2025 05:58 AM
I plan to disable support for TLS 1.0 under the security settings. I am using ISE 3.3 and was wondering if there is anyway to see or detect if anything is connecting to ISE is still using TLS 1.0. Weather it be pxGrid or Context visibility I'll need to verify this to satisfy CC standards. Also, if I do disable it will this cause a reboot?
Thanks in advance.
07-02-2025 08:44 AM
- @pmcternan FYI : https://testtls.com/
https://www.cdn77.com/tls-test
Changing TLS parameters (if it can be done) will not cause a reboot ,
M.
07-02-2025 08:48 AM
07-02-2025 02:15 PM - edited 07-02-2025 02:18 PM
Well done for wanting to disable TLS 1.0 (as well as TLS 1.1 I assume).
When I have done this in the past, I found that there were still clients that negotiated this old protocol and I wasn't aware of it - then had to re-enable TLS 1.0/1.1
Changing this setting will restart application services on ALL nodes at the same time - yes ... ALL ISE nodes at the same time.
In my case, the clients that were preventing me to turn off TLS 1.0 were:
How to detect what systems are reliant on using TLS when speaking to ISE? If you're talking about 802.1X clients, then you need to enable SYSLOG forwarding for successful RADIUS authentications to a SYSLOG server and check the events - they contain attributes similar to "days remaining=xxx" (I don't recall the exact string) and also TLS version and cipher details. It's very handy.
But you must configure your ISE Authorization Profiles to re-auth WIRED endpoints periodically (e.g. reauth every 65535 seconds) to get these SYSLOG events. If you don't reauth 802.1X wired clients then you might have missed the auth that could have potentially happened a long time ago when the devices was first connected to a switch.
Web-based clients should not be using TLS 1.0 (e.g. web browsers from guests) - that must be some ancient equipment I would not want on my network. The focus should be on 802.1X clients, and also DNAC (if you're using it)
07-03-2025 05:01 AM
Arne,
We do use DNAC and This is exactly the type of information I was hoping for when I posted this. Thanks a ton.
08-01-2025 10:37 PM
Hi @pmcternan
please take a look at: ISE - What we need to know about TLS.
About:
" ... if there is anyway to see or detect if anything is connecting to ISE is still using TLS 1.0 ... ", search the above link for Identify the TLS version.
" ... do disable it will this cause a reboot ? ... ", search the above link for Particularities > Version and Particularities > Ciphers List.
Hope this helps !!!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide