09-06-2022 08:46 AM
We have deployed a new site and are having issues with the EAP-TLS. We use the same profiles for each of our locations and there is no difference between this location and others. PEAP authentications are working without issue but EAP-TLS (profile that works at other locations) ISE shows the Supplicant abandoned the session and started a new one. I have a TAC case started but we have not made any progress. Wired EAP-TLS works as well. The setup and WLAN's are the same across all locations, I have a good capture and a bad capture and it appears the difference is the supplicant never provides the certificate for authentication.
Any suggestions would be appreciated.
See attached screenshots:
Thanks,
Joe
Solved! Go to Solution.
10-11-2022 06:23 AM
We were able to resolved this issue by enabling tunnel path-mtu-discovery on the GRE tunnel and "enabling" ip unreachables.
Thanks,
Joe
09-06-2022 03:35 PM
Few questions:
09-06-2022 05:28 PM
09-06-2022 05:36 PM
09-07-2022 07:48 AM
WLAN Autoconfig is set to Automatic and is in a Running state.
09-06-2022 05:16 PM
Your print shot points to supplicant issue, client cert is sent once the server cert is validated, in failed case it’s not being sent, make sure the CA that signed server cert is in trusted certificate store of client, Try disabling server cert check in supplicant config, Try reprovisioning client with eap-tls again … to start with.
09-13-2022 01:30 PM
Any suggestions, TAC can't figure it out and we are still struggling.
Thanks,
Joe
09-13-2022 02:59 PM
EAP-TLS is a standard protocol, based on your printshot last I saw was client was not sending certificate, is it still stuck at the same stage or any additional progress is made, if you are stuck at the same stage and all configuration is correctly verified by TAC then upgrade adapter firmware, try anyconnect supplicant, try different wireless adapter...
09-13-2022 05:28 PM - edited 09-13-2022 05:46 PM
Client Cert. is not available in Host when connect to WLC/AP
09-14-2022 08:38 AM
We are still in the same state, same user can plug directly into the switch located at the site and they authenticate successfully. TAC has said it is a fragmentation issue. Would that fragmentation not occur on the LAN side as well?
Thanks,
Joe
09-14-2022 09:22 AM
Yes one reason is the fragment of Server Cert., and hence the client can not defragment the Cert.
can you check the MTU between AP and WLC?
09-14-2022 09:18 AM
Yep that's what I was about to suggest. CAPWAP encapsulation imposes additional limits on the packet size so my bet is also on fragmentation somewhere. There must be something different in your transport between the AP and WLC at this site (what is between them?). Have you configured the recommended TCP MSS adjust value of 1250? For that matter what model of WLC are you using and what version of software?
09-19-2022 07:00 AM
Update:
We have sent a 3802 to the location and EAP-TLS is working as expected. I have sent this information to Cisco but not sure if anyone else has noticed anything similiar.
Thanks,
Joe
09-19-2022 08:44 AM
> We have sent a 3802 to the location and EAP-TLS is working as expected
Implying that where it's not working is on a different model of AP? So which model does not work? And you're sure the config of both APs is identical? What version of software are you using?
09-19-2022 09:05 AM
The original AP's are 9120's. We are using Tags for the AP's via a Regex Filter, so if the AP name starts with "Alpha" it inherits the same policy. WLC is running 17.06.01. I might have spoke to soon as it appears that when the client needed to reauthenticate (1800 seconds) they are now unable to authenticate again. From ISE I see the authentication coming from the switch not the WLC, which is different than the previous passed authentications. I am not sure I have noticed this in the past.
Please see attached screenshot.
This shows the end user attempting to connect but the failed ones are coming from 10.64.0.2 (switch) and the interface that the AP is connected to gi1/0/14. The ones that show 10.31.6.131 work find and that is the address of the WLC.
Thanks,
Joe
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide