cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
757
Views
0
Helpful
0
Replies

ISE EAP-FAST with inner method EAP-TLS 5440 problem

Kfir Mesika
Community Member

Hello,

The topology is(All devices are CISCO):

ISE(ip=4.0.110.1)-->Router-->MPLS Cloud-->Router-->Access Switch(ip=4.102.8.1)-->User(AnyConnect NAM)

ISE is version 2.1 with patch2

User is windows 7 using anyconnect version 4.3 NAM.

I am using dot1x to authenticate the end user only (anyconnect NAM client), without machine authentication. 

The EAP protocol that I'm using is EAP-FAST with certificate inner method with EAP-TLS.

When the user is trying to authenticate, the authentication is failling - ISE shows the following reason:

5440 Endpoint abandoned EAP session and started new step latency

When I'm changing the inner method to EAP-MSCHAPv2 the authentication is successful.

Then I tried to to change the topoloty like the following:

ISE(ip=4.0.110.1)-->Router-->Router-->Access Switch(ip=4.102.8.1)-->User(AnyConnect NAM)

In this case the authentication is successful for both EAP-TLS and EAP-MSCHAPv2 for inner method.

With packet capture we can see fregmented udp packets only when the MPLS core is in the middle. The access switch is generating those fregmented packets.

I'm attaching the following files:

PCAP file - showing RADIUS packets for the failling authentication.

LOG file - showing Endpoint debug from ISE.

TXT file - showing the Operations->Radius Authentication, with the 5440 failed reason.

Please help me understand the problem. I can't find the solution.

Regards.

0 Replies 0