Hi,
I'm trying to test such 802.1x wired environment:
windows xp sp3 as supplicant
windows NPS as radius server
2960 as authenticator
latest anyconnect (3.1.01065) + nam and standalone profile editor
I have a question:
Could someone explain me the difference between protected identity pattern and unprotected identity pattern (set in nam profile editor)? As I understand documentation PEAP-MSCHAPv2 is a tunneled method and it uses unprotected identity pattern to protect user's identity during phase 0. But if I use any fake identity here (anonymous, anonymous@[domain], etc) access is rejected (Access-Reject in switch debugs). I have to use exacly the same pattern in
unprotected identity pattern as in protected identity pattern ([username] or [username]@[domain]) to gain access, regardless of authenticaton mode (same in machine only, user only authentication)
I would be grateful for any clues
Best regards
Lukasz