cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2265
Views
0
Helpful
6
Replies

Zebra Printers EAP-TLS

Ben Meagher
Level 1
Level 1

Having some issues implementing TLS on some zebra printers. Does anyone have any pointers?

User Template

Verified cert on a laptop

OpenSSL to convert to PEM

Renamed as NRD

     CACertsv.nrd

     certcln.nrd

     Privkey.nrd

ACS 5.3 on the backend

Local cert for ACS with trusted intermediaries and of course root

Im getting an EAP timeout, capture shows..

EAPOL start

Controller Identity

Client Identity

Radius Access Request

Radius Access Challenge

Controller request EAP TLS

Client     crickets.....

6 Replies 6

Amjad Abdullah
VIP Alumni
VIP Alumni

What do the logs on the ACS say? EAP timeout? this is usually issue with the client.

Tried to contact Zebra support? They may provide useful info.

Rating useful replies is more useful than saying "Thank you"

Rating useful replies is more useful than saying "Thank you"

Chris Illsley
Level 3
Level 3

Hi,

Did you have any luck with this?  We're having issues connecting Zebra Label Printers with EAP-TLS as well.

Thanks
Chris

This topic is 10 years old and references ACS (all versions of ACS are now EOL).  I would suggest making a new topic on this.

https://community.cisco.com/t5/security-knowledge-base/how-to-ask-the-community-for-help/ta-p/3704356

Andrew Woolman
Level 1
Level 1

100% this is a certificate issue on the printer - except no one knows what the answer is. It seems I found the other 2 people in the world who are trying to do this. My bet is that it's an issue with the certificate chain.
I have a support call with Zebra and will post the answer if I find it.
This is not an ACS (or now ISE) issue

I had this classic issue in my previous job. our issue was resloved later by changing the RSSI value of the zebra printer. these printer are really hard guys some time give you a hard time.

our issue was they working fine and all of sudden lost the connection to wireless. even most of the time these printer were sitting next around to the AP not far at all.

please do not forget to rate.

Jagermeister
Level 1
Level 1

I have tried to do this with wired zebra printers, using eap-tls to authenticate them against ISE. I had a range of different models of Zebra printers and my observation was that that some models (mainly the newer ones) worked but that the older ones were behaving like you are saying right now.  Sometimes I had a newer model that also didn't work with the exact same config as the working ones, upgrading the firmware helped in that case.

In the end I never managed to get the older ones working and also decided to move away from eap-tls with these printers since it was such a pain to manage these settings. Not sure if you're using some MDM for them but I had to send commands to them using the Zebra tool.