cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
713
Views
10
Helpful
1
Replies

Wireless Authentication - Cisco ISE using LDAP

atsetheodros
Level 4
Level 4

I am using 5520 WLC and AP 9120 with 8.1.102.0 code to authenticate clients via ISE 2.6 using Novel LDAP as identity source.

It appears that MSCHAPv1/v2, EAP-MSCHAPV2 and PEAP are not supported on LDAP.

 

Please advise the possible ways to do it. Its urgent and time sensitive project.

 

Thank you!

1 Reply 1

Arne Bier
VIP
VIP

The issue is with the passwords in LDAP - (the passwords should not be transmitted, but rather, a hash is transmitted).

LDAP repositories are suited to PAP/ASCII password exchanges. And neither of those are supported inner EAP methods

 

Is there any way you could get those LDAP identities into ISE itself? It might require some coding and regular sync, but if the username and password existed in ISE, then you can do EAP and MSCHAPv1/2 inner method.

The obvious solution would be to migrate the users to Active Directory ... instead of Novel

 

I believe there are people on the internet who have got this to work -but they had to create password hashes for all of the accounts and then store this hashed password as an additional attribute per user. Quite clever - it means that ISE would have to retrieve that attribute during authentication, and not the regular user password. I cannot verify this but it sounds very promising.

 

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card