Showing results for 
Search instead for 
Did you mean: 

Flexconnect - EAP-TLS authentication after WAN failure


Dear Ciscoers,


I am studying branch authentication capabilities and I have got the needing to authorize clients even if the WAN link is down.

My authentication server is located in Data-center so i'm interested by the new functionnality of local EAP-TLS authentication described by this link :


I've seen these tables but I didn't really understood what is possible and what is not.

So, could you confirm that this method is compatible with Flexconnect "connected" mode ? We really don't need any local server, Flexconnect AP take completely authentication in charge ? 


And, subsidiary question : Is this possible with Mobility Express AP ?


Thanks a lot for your help.

1 Accepted Solution

Accepted Solutions

Yes sorry, I should have worded answer 1 more clearly. That will work too :)
Please rate helpful / correct posts

View solution in original post

3 Replies 3

Ric Beeching
Rising star
Rising star
When FlexConnect is in connected mode (i.e. WLC CAPWAP Control tunnel is up) you have two options for EAP-TLS:
1) Local mode EAP-TLS (works either connected or standalone mode). This is where clients are authenticated locally on the Access Points via certificates. As long as certificates are setup in the way outlined in the guide, this will work.
2) Use central auth with a RADIUS server like Cisco ISE setup with EAP-TLS chain in similar fashion. With this option you lose auth with WAN down and auth must traverse the WAN to central so local is a less risky option, but could be a headache to setup (I haven't set this up so not sure).

Mobility Express doesn't seem to support local EAP-TLS so there's a limitation there. It can still support central auth to a RADIUS server over the WAN with local switching if that is an option.

Please rate helpful / correct posts

Thanks for your answer :)


3) The third option could be to activate both central auth and « AP local mode Authentication » ?

- When the WLC and the ISE are reachable, Flexconnect AP use the central authentication.

- When the tunnel is down, WLC and ISE are not reachable but Flexconnect AP could use local authentication like below.




Is this a scenario thinkable ?

Yes sorry, I should have worded answer 1 more clearly. That will work too :)
Please rate helpful / correct posts
Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Recognize Your Peers