cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
655
Views
2
Helpful
3
Replies

PEAP/EAP-TLS replication in node group

kerai08
Cisco Employee
Cisco Employee

Hi there,


My customer has a concern around millisecond network/IP outages for the traders.


Question:


1. How is the PEAP/EAP-TLS session resumption replicated between PSNs in a node group?

My customer recognises that in a normal office environment, the PEAP/EAP-TLS exchange and failover process is "almost invisible" and not an issue however extra due diligence is required for trader workstations.


Thank you,

Arron

1 Accepted Solution

Accepted Solutions

Sure.  I should add that the implementation is based on RFC 5077 for session ticket extensions with EAP-TLS.  The feature is not limited to node group, but config is common across all PSNs as all will leverage the same master ticket.  A bit more info is provided in the Reference presentation for BRKSEC-3699 (CiscoLive.com  >> Session Catalog >> BRKSEC-3699 @ CLUS Vegas 2017).

Also, the implementation is specific to EAP-TLS.

View solution in original post

3 Replies 3

Craig Hyps
Level 10
Level 10

Feature is based on master key that is common to all so that connection to different PSN will allow resumption based on initial negotiation for same master key.

Thanks, Craig!

Sure.  I should add that the implementation is based on RFC 5077 for session ticket extensions with EAP-TLS.  The feature is not limited to node group, but config is common across all PSNs as all will leverage the same master ticket.  A bit more info is provided in the Reference presentation for BRKSEC-3699 (CiscoLive.com  >> Session Catalog >> BRKSEC-3699 @ CLUS Vegas 2017).

Also, the implementation is specific to EAP-TLS.