cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1956
Views
0
Helpful
2
Replies

ISE and EAP-TLS + EAP-MD5

Dear all,

 

I've issue with Cisco ISE 2.0.1.130.

All computers are joined to the Active Direcory domain (2008 2), and I make authentication for all devices (Cisco IP phones and Windows computers and for printers).

 

I’ve issue with Cisco ISE because I’ve 3 rules on my authentication policy :

  • Printers : MAB
  • IP Phones : EAP-MD5
  • Computers : EAP-TLS

 


My problem is that when I add rules EAP-MD5 + EAP-TLS it’s not working:

  • EAP-MD5 at the first and EAP-TLS at the second place

Result: my IP phones are working but my computers are not working because my computers try to authenticate with eap-md5 and not eap-tls

 

  • EAP-TLS at the first and EAP-MD5 at the second place

Result: my IP phones are not working but my computers are working because my IP Phones try to authenticate with eap-tls and not eap-md5.


My rules :

  • EAP-MD5-CiscoPhones => Wired_802.1X => Allowed protocol : EAP-MD5 => internal Users
  • EAP-TLS CiscoPhones => Wired_802.1X => Allowed protocol : EAP-TLS => Authentication with Certificate in AD

authentication_policy.jpg

authentication policy

And the result :

result.jpg

result

As you can see the computer is not authenticated and not used EAP-TLS.

Have you any idea to solved the issue ?

Thanks in advance for your help.

Best regard

1 Accepted Solution

Accepted Solutions

jan.nielsen
Level 7
Level 7

Your computers are ending up in the phone authentication rule, because you only use wired_dot1x as your condition for what will matche the rule. Instead you need to have one authentication rule, and then allow both EAP-MD5 and EAP-TLS in that rule, then use a identity source sequence, to select the identity stores you wan't to look in (internal user, ad, and so on). The Allowed protocols setting is not used to select the rule its the result of the conditions.

View solution in original post

2 Replies 2

jan.nielsen
Level 7
Level 7

Your computers are ending up in the phone authentication rule, because you only use wired_dot1x as your condition for what will matche the rule. Instead you need to have one authentication rule, and then allow both EAP-MD5 and EAP-TLS in that rule, then use a identity source sequence, to select the identity stores you wan't to look in (internal user, ad, and so on). The Allowed protocols setting is not used to select the rule its the result of the conditions.

Hello,

thanks i just add an radius attribute on my Authentication Compound Conditions .

Thnaks again.