cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2482
Views
45
Helpful
15
Replies

New Wireless location EAP-TLS wireless doesn't work but PEAP does.

joeharb
Level 5
Level 5

We have deployed a new site and are having issues with the EAP-TLS.  We use the same profiles for each of our locations and there is no difference between this location and others.  PEAP authentications are working without issue but EAP-TLS (profile that works at other locations) ISE shows the Supplicant abandoned the session and started a new one.  I have a TAC case started but we have not made any progress.  Wired EAP-TLS works as well.  The setup and WLAN's are the same across all locations, I have a good capture and a bad capture and it appears the difference is the supplicant never provides the certificate for authentication. 

Any suggestions would be appreciated. 

See attached screenshots:

Thanks,

Joe

15 Replies 15

joeharb
Level 5
Level 5

We were able to resolved this issue by enabling tunnel path-mtu-discovery on the GRE tunnel and "enabling" ip unreachables.

Thanks,

Joe

Review Cisco Networking for a $25 gift card