cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1772
Views
0
Helpful
2
Replies

ISE Voip phones: authentication failed against AD

the message is

2064 Authentication method is not supported by any applicable identity store(s): Authentication failed

the user is present on AD and testing user in ise is ok

the authentication rule to check in AD is created

policy servers are joined and in green status

if I create an internal user (just for testing) authentication is ok

my authentication sequence is:

mab

mab_ad

dot1x

dot1x_ad

those phones uses eap-md5

i guess there is something to check in AD, can someone help me to solve this?

1 Accepted Solution

Accepted Solutions

Eduardo Aliaga
Level 4
Level 4

I don't think Active directory supports EAP-Md5.

I will recommend to use EAP-TLS instead. Most Cisco IP phones have builtin MIC certificates which really helps to deploy EAP-TLS

View solution in original post

2 Replies 2

Eduardo Aliaga
Level 4
Level 4

I don't think Active directory supports EAP-Md5.

I will recommend to use EAP-TLS instead. Most Cisco IP phones have builtin MIC certificates which really helps to deploy EAP-TLS

yes that is true however it supports eap md5 against internal database strange thing...

it won't have been a bad thing if it had the ability to turn over the eap-md5 request in another format like ldap...

thank you!!