07-09-2018 11:58 AM - edited 07-05-2021 08:49 AM
Hi, is it possible to deploy EAP-FAST without the anyconnect NAM module? I'm trying to use the option from the windows drop down list for the authentication methods but getting the attached error message and ISE complaining about not finding the authentication method.
Thanks
Solved! Go to Solution.
07-17-2018 10:55 AM
If you are not currently using NAM and using the Native supplicant for EAP-Fast you most likely have the EAP-Plugins that were provided to Microsoft years ago. You can still download them from a few different location, one of which is in the Surface bundle here.
https://www.microsoft.com/en-us/download/details.aspx?id=46703
That said, for multi-factor auth you will probably want the inner method of EAP-Fast to use GTC, and not MSCHAPv2. From the screenshot you provided the inner method sent to ISE was MSCHAPv2, and ISE tried to send this off to presumably your MFA server, and the server rejected it. I suspect the server is expecting GTC. I don't know your entire setup, but going off what you said this is my best guess.
Thanks,
Steve S.
07-09-2018 02:03 PM
Hi
From Cisco docs:
"
Error Message Automatic PAC provisioning is enabled for this profile. However, a
valid PAC that matches the server to which the client adapter is connecting could
not be found. Do you wish to obtain a new security credential (PAC)?
Recommended Action Click Yes to provision a new PAC for this server using your existing credentials or click No to cancel the operation. If you click No, the client adapter will fail the authentication."
-If I helped you somehow, please, rate it as useful.-i
07-09-2018 03:00 PM
Hi Flavio, thanks. Is the anyconnect client necessary to configure EAP-FAST?
07-09-2018 03:54 PM
Don't think so. However, looks like this EAP method is not used anymore. Are you using Windows XP? Windows 7 and 10 seems not support anymore.
Looks like EAP TLS or PEAP is currently available.
-If I helped you somehow, please, rate it as useful.-
07-09-2018 04:10 PM
07-17-2018 10:55 AM
If you are not currently using NAM and using the Native supplicant for EAP-Fast you most likely have the EAP-Plugins that were provided to Microsoft years ago. You can still download them from a few different location, one of which is in the Surface bundle here.
https://www.microsoft.com/en-us/download/details.aspx?id=46703
That said, for multi-factor auth you will probably want the inner method of EAP-Fast to use GTC, and not MSCHAPv2. From the screenshot you provided the inner method sent to ISE was MSCHAPv2, and ISE tried to send this off to presumably your MFA server, and the server rejected it. I suspect the server is expecting GTC. I don't know your entire setup, but going off what you said this is my best guess.
Thanks,
Steve S.
07-17-2018 11:35 AM
This windows native supplicant kept doing mschapv2 for the inner tunnel. I ended up using the anyconnect profile editor to create a profile for EAP-FAST with EAP-GTC and it worked.
One last question. Does EAP-FAST require a cert on ISE or this is just with PEAP?
Thanks
07-17-2018 11:55 AM
EAP-Fast does not require the use of client or server certificates when performing unauthenticated provisioning. The tunnel is established using anonymous DH (Diffie Hellman) exchange (less secure, not recommended). If you use authenticated provisioning the TLS tunnel is established using the ISE server certificate.
This doc explains a lot of this in detail.
PEAP always requires the server certificate.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide