cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
631
Views
0
Helpful
3
Replies

EAP-TLS machine auth - no AD

bthomson
Level 1
Level 1

Hi, I have a test environment with Light weight Access Points, 4404 WLC, ACS v4.0, a stand-alone CA and XP wireless clients. Can I get EAP-TLS with machine authentication(certificate based) without requiring an external AD database?

I am getting authentication traffic between the wireless client and the ACS but currently getting an authentication failure code on ACS log saying "external DB not available"

3 Replies 3

Scott Fella
Hall of Fame
Hall of Fame

Did you load the certificate on the machines first? If you are using username and password, then you can set that up in ACS. Do you have ACS setup for external DB and not local DB?

-Scott
*** Please rate helpful posts ***

fieus
Level 1
Level 1

I'm trying to do the same thing without success.

WLC 4404, ACS v3.3, enterprise CA and XP SP2 wireless clients.

I configured the System Conf -> Global Auth Setup for EAP-TLS with SAN/CN/Binary comparison, but then the ACS log complains about "external DB not available"

http://www.cisco.com.ru/univercd/cc/td/doc/product/access/acs_soft/csacs4nt/acs32/user/o.htm talks about "EAP Authentication Protocol and User Database Compatibility" in table 1.3. From my point of view EAP-TLS should be configurable using the internal ACS db.

Thanks for your support!

Mark

taelon_x7
Level 1
Level 1

Sounds like you have ACS configured to check an external database if the user authentication fails.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card