09-02-2016 06:44 AM - edited 03-11-2019 12:03 AM
Dear all,
I've issue with Cisco ISE 2.0.1.130.
All computers are joined to the Active Direcory domain (2008 2), and I make authentication for all devices (Cisco IP phones and Windows computers and for printers).
I’ve issue with Cisco ISE because I’ve 3 rules on my authentication policy :
My problem is that when I add rules EAP-MD5 + EAP-TLS it’s not working:
Result: my IP phones are working but my computers are not working because my computers try to authenticate with eap-md5 and not eap-tls
Result: my IP phones are not working but my computers are working because my IP Phones try to authenticate with eap-tls and not eap-md5.
My rules :
And the result :
As you can see the computer is not authenticated and not used EAP-TLS.
Have you any idea to solved the issue ?
Thanks in advance for your help.
Best regard
Solved! Go to Solution.
09-03-2016 11:48 AM
Your computers are ending up in the phone authentication rule, because you only use wired_dot1x as your condition for what will matche the rule. Instead you need to have one authentication rule, and then allow both EAP-MD5 and EAP-TLS in that rule, then use a identity source sequence, to select the identity stores you wan't to look in (internal user, ad, and so on). The Allowed protocols setting is not used to select the rule its the result of the conditions.
09-03-2016 11:48 AM
Your computers are ending up in the phone authentication rule, because you only use wired_dot1x as your condition for what will matche the rule. Instead you need to have one authentication rule, and then allow both EAP-MD5 and EAP-TLS in that rule, then use a identity source sequence, to select the identity stores you wan't to look in (internal user, ad, and so on). The Allowed protocols setting is not used to select the rule its the result of the conditions.
09-05-2016 06:04 AM
Hello,
thanks i just add an radius attribute on my Authentication Compound Conditions .
Thnaks again.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide