12-27-2023 12:44 AM
Some my clients started to get error when they try to connect wifi with 802.1x. On the Ise I can see log with error (on the phone I set CA Certificate as don't validate)
Event 5400 Authentication failed
Failure Reason 12321 PEAP failed SSL/TLS handshake because the client rejected the ISE local-certificate
we don't use any certificates for our wifi environment.
Solved! Go to Solution.
01-02-2024 02:23 PM
@dijix1990 You should look at the other alternatives provided. Or you may get a well-known CA to sign the EAP server certificate for ISE.
12-27-2023 08:03 AM
M.
12-27-2023 04:46 PM - edited 12-27-2023 04:47 PM
I saw it. It's the note for domain devices. My devices (thousand different phones) aren't part of domain, and if I set on my wlc radius nps instead of ise it start to work
12-27-2023 10:14 PM
ISE Cert. is signed by public CA or you use PAN as CA ?
MHM
12-28-2023 10:41 AM
@dijix1990 Adding to what the others said... Since it works OK with NPS, you could try exporting the server certificate and the private key from NPS and importing the key-pair into ISE as the EAP server certificate. Or use the same CA as that for NPS to issue the EAP server certificate for ISE. If you are not sure what it is, take packet captures to check.
12-28-2023 06:38 PM
ISE has this certificates (for EAP)
but I can't upload root certificate to devices which is not in domain
12-28-2023 06:42 PM
if the issue to is same as issue by then ISE is CA, and you need to add ISE CA cert to each client
MHM
12-28-2023 06:51 PM
This is not possible, it guests network. Without ISE everything works perfect
12-28-2023 06:59 PM
so the issue to is same as issue by ?
MHM
12-28-2023 07:02 PM
I found that the problem only for samsung A51
01-01-2024 07:55 PM
@dijix1990 Recent Android releases usually need the certificate chain already trusted by the client OS before to allow EAP authentications. You may either use ISE dual-SSID BYOD to install the certificate chain or manually import it onto the client devices.
Note that on ISE, we may use a different certificate for EAP and leave what you have for the other usages. This EAP server certificate does not have to match the DNS domain of the ISE node. Alternatively, you may remove one of your ISE PSNs, reassign its DNS domain, import the certificate pair, and then retest. If that tested fine, then you may re-register it back to your ISE deployment.
01-02-2024 01:18 AM
We configured radius nps directly on the wlc, without ise and it works better. It guests phones I can't install cert chain
01-02-2024 02:23 PM
@dijix1990 You should look at the other alternatives provided. Or you may get a well-known CA to sign the EAP server certificate for ISE.
01-02-2024 06:29 PM
Yes, I know it, but we decided use ise only for domain devices
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide