cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
927
Views
10
Helpful
6
Replies

Cisco ISE protocols for ldap and Windows wireless client

Mathieu Sturm
Level 1
Level 1

Only the protocols below are supported by ise in combination with ldap identity sources.

EAP-GTC, PAP, EAP-TLS, PEAP-TLS.

Mac OS devices seem to be able to use these but Windows users seem to be having problems. How should windows users connect with ise that only uses ldap?


1 Accepted Solution

Accepted Solutions

Tarik Admani
VIP Alumni
VIP Alumni

You can use the anyconnect network access manager. Just out of curiosity why ldap over joining ise to AD?


Sent from Cisco Technical Support Android App

View solution in original post

6 Replies 6

Nicholas Poole
Level 1
Level 1

The Windows supplicant supports EAP-TLS when you select certificates as the auth method.  (you of course needs client side certs issued to windows user to use EAP-TLS though)

That doesn't seem to be very user friendly

Tarik Admani
VIP Alumni
VIP Alumni

You can use the anyconnect network access manager. Just out of curiosity why ldap over joining ise to AD?


Sent from Cisco Technical Support Android App

Do you still need the certificates then  with the network access manager? We need to strip of everything after the @ sign. I know you can connect with an AD through LDAP external identity source but because of our complicated AD structure this isn't possible.

Mathieu,

Take a look at the user guide for NAM -

http://www.cisco.com/en/US/docs/security/vpn_client/anyconnect/anyconnect30/administration/guide/ac04namconfig.html

You will see the protocols support like GTC that should allow you not to have to deploy certs.

Thanks.

Tarik Admani
*Please rate helpful posts*

I can't ask the users to install something. The reason I use LDAP is because I need to strip of some data in the username starting from the @ sign. Unfortunately LDAP is the only way to go to do this isn't it?