cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
532
Views
0
Helpful
2
Replies

ACS doesn't support EAP-MD5 with Windows AD Database

c.ong
Level 1
Level 1

Hi,

I would like to know the reason why ACS cannot support EAP-MD5 with Windows AD Database? I plan to implement 802.1x on Wired and choose EAP-MD5 as the EAP protocol.

I understand that IAS can be used to implement EAP-MD5 with Windows AD database provided the user account password stored as Reversable Encryption Password in the Domain Settings.

Why cant I do the same with ACS?

Thank you.

Delon

2 Replies 2

bwilmoth
Level 5
Level 5

EAP-MD5 is the lease secure protocol. Industry support for EAP-MD5 is almost very minimal. It is used in combination with other EAP techniques.

Premdeep Banga
Level 7
Level 7

This is the reason,

http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.1/user/Overvw.html#wp858207

ACS is not designed to work in that way. And yes, it is the least favored, or now-a-days I guess no one uses EAP-MD5. Go for PEAP.

Regards,

Prem

Review Cisco Networking products for a $25 gift card