EAP Configuration
EAP is a flexible request-response protocol for arbitrary authentication information (RFC 2284). EAP is layered on top of another protocol such as UDP, 802.1x, or RADIUS and supports multiple authentication types:
• EAP-TLS (based on X.509 certificates)
• EAP-MD5: Plain Password Hash (CHAP over EAP)
New extended EAP methods have been added to EAP for NAC:
• EAP-TLV: Carry posture credentials, adding posture AVPs, posture notifications.
• Status Query: You can use this new EAP method for securely querying the status of a peer without a full credential validation.
• EAPoUDP: use of EAP over UDP for Layer 3 transport.
Note LEAP (EAP-Cisco Wireless) is not supported when working with Network Access Profiles.
|
EAP-FAST |
EAP-FAST is a new, publicly accessible IEEE 802.1X EAP type that Cisco developed to support customers that cannot enforce a strong password policy and want to deploy an 802.1X EAP type that does not require digital certificates. EAP-FAST supports a variety of user and password database types, password change and expiration; and is flexible, easy to deploy, and easy to manage. For more information about EAP-FAST and comparison with other EAP types, see: http://www.cisco.com/en/US/products/hw/wireless/ps430/products_qanda_item09186a00802030dc.shtml You can set the following inner methods for EAP- FAST; • EAP-TLS |
|
Posture Validation Settings |
|
|
Several organizations might be transitional to supply their hosts with CTA and some hosts might or might not have CTA installed. Cases might arise where you might want to enforce posture validation on machines with CTA; however, you do not want to fail authentication on those machines that are temporarily without CTA. When EAP-FAST is enabled with Required Posture Validation, you can select the Optional selection and supply a resulting SPT. You can use the SPT that is set here for setting Authorization settings. For a description of the tokens that are used in ACS, see Posture Tokens, page 14-3. |
|
|
X |
|
|
Note |
If posture-validation rules are not defined, the posture token returned is Unknown. |
|
Credential Validation Databases |
|
|
The Credential Validation Databases are databases that you use to validate users. The Available Databases are the configured External User Databases that are mapped to ACS user groups by the mapping rules defined in Databases Group Mapping. The ACS internal database appears, by default, as a selected database. |
|
|
X |
|
|
Note |
If you specify multiple databases for authentication, ACS will query each directory server in the order specified until it receives an authoritative response. You should put the most likely directory servers higher in the list to improve response times and user experience. |
|
Setting Authentication Policies |
|
|
To set authentication policies: |
|
|
Step 1 |
Choose Network Access Profiles. |
|
Step 2 |
Choose the relevant Authentication policy. The Authentication Settings Page appears. |
|
Step 3 |
Select Populate from Global to populate authentication settings from the ACS Global Authentication Settings. For more information, see Global Authentication Setup, page 10-19. |
|
If you are not using the Global Authentication Setup settings: |
|
|
Step 4 |
Configure the Authentication Protocols for the profile. |
|
Step 5 |
Select the EAP Configuration. See EAP Configuration, page 15-29. |
|
Step 6 |
Select the EAP-FAST Configuration. See EAP-FAST, page 15-30 |
|
Step 7 |
Select the Credential Validation Databases. See Credential Validation Databases, page 15-30. |
|
Step 8 |
Click Submit. |
|
The Network Access Profiles Page appears. |
|
|
Step 9 |
Click Apply and Restart for your changes to take effect. |
|
Configuring MAC Authentication Bypass |
|
|
To configure the MAC authentication bypass: |
|
|
Step 1 |
Choose Network Access Profiles. |
|
Step 2 |
Choose the relevant Authentication policy. |
|
Step 3 |
In the Authentication Settings Page, enable Allow MAC-Authentication-Bypass. |
|
Step 4 |
Click Submit. |
|
The Network Access Profiles Page appears. |
|
|
Step 5 |
Choose the relevant Authentication policy. |
|
Step 6 |
Select the MAC Authentication Bypass Configuration link. |
|
The MAC Authentication Mapping Page appears. |
|
|
Step 7 |
Click Add. |
|
Step 8 |
Enter the MAC Addresses for the access requests that you want to group. |
|
Step 9 |
Select a User Group from the drop-down list. |
|
Step 10 |
Continue Adding MAC addresses and mappings to the list. (optional) |
|
Step 11 |
Define the default mapping for MAC addresses that do not match by selecting a group from the |
|
drop-down list. |
|
|
Step 12 |
Click Submit. |
|
The Network Access Profiles Page appears. |
|
|
Step 13 |
Click Apply and Restart for your changes to take effect. |
|
% |
|
|
Note Each NAP can hold up to 10,000 MAC addresses in the MAB page. Each NAP can hold up to |
|
|
100 mappings (a map between list of one or more MAC addresses to a group), meaning you can |
|
|
have up to 100 lines of mappings from lists of MACs to user-groups. You can map up to 10,000 |
|
|
MAC Addresses to the same user-group in one NAP. |
|
Authentication Settings Page
The Authentication Settings page contains:
|
Field |
Description |
|
Populate from Global |
Use this option to populate the Authentication Settings with the ACS global Authentication settings. This method facilitates configuration of the authentication settings each time you set up a new profile. |
|
Authentication Protocols |
|
|
Allow PAP |
Select to enable PAP. PAP uses clear-text passwords (that is, unencrypted passwords) and is the least secure authentication protocol. |
|
Allow CHAP |
Select to enable CHAP. CHAP uses a challenge-response mechanism with password encryption. CHAP does not work with the Windows user database. |
|
Allow MS-CHAPv1 |
Select to enable MS-CHAPv1. |
|
Allow MS-CHAPv2 |
Select to enable MS-CHAPv2 |
|
Allow MAC-Authentication Bypass |
Enable to configure the authentication process for a profile that receives a MAC address request. |
|
MAC Authentication Bypass Configuration |
Opens the MAC Authentication Mapping Page, page 15-34 |
|
EAP Configuration |
Note: PEAP is a certificate-based authentication protocol. Authentication can occur only after you have completed the required steps on the ACS Certificate Setup page. Select he PEAP types. In most cases, all three boxes should be checked. When none is selected, PEAP will not be allowed for authentication. |
|
Allow EAP-GTC (Cisco PEAP) |
Select to enable EAP-GTC within PEAP authentication. Use for RSA Secure ID authentication. |
|
Allow EAP-MS-CHAPv2 (MS PEAP) |
Select to enable EAP-MS-CHAPv2 within PEAP authentication. Use for AD authentication. |
|
Allow Posture validation |
Select to enable the collection of posture data when using PEAP. This options uses EAP over UDP. Note This EAP configuration must be checked to use the Layer 3 NAC Profile Template. |
|
Allow EAP-FAST |
Select to enable EAP-FAST authentication, All other EAP-FAST-related options are irrelevant if unchecked. Some of the following settings must have corresponding settings on the PC based authentication agent (the EAP-FAST client). |
|
Allow anonymous in-band PAC provisioning |
If this check box is checked, ACS establishes a secure anonymous TLS handshake with the client to provision it with a so-called PAC by using phase zero of EAP-FAST, and using EAP-MS-CHAP as the inner method. |
|
Field |
Description |
|
Allow authenticated in-band PAC provisioning |
ACS uses secure sockets layer (SSL) server-side authentication to provision the client with a PAC during phase zero of EAP-FAST. This option is more secure than anonymous provisioning; but requires that a server certificate and a trusted root CA are installed on ACS. |
|
Accept client on authenticated provisioning |
This option is only available when the Allow authenticated in-band PAC provisioning option is selected. This option should be checked to slightly shorten the protocol. |
|
Require client certificate for provisioning |
Select this option if the clients are configured with public key infrastructure' (PKI) certificates, which will be used to provision PACs |
|
Allow Stateless session resume |
Should normally be checked. Uncheck if you do not want ACS to provision authorization PACs for EAP-FAST clients, and always perform phase 2 of EAP-FAST. |
|
Authorization PAC TTL minutes hours |
You can use this setting to determine the expiration time of the user authorization PAC. When ACS receives an expired authorization PAC, it performs phase 2 EAP-FAST authentication. Enter a time in minutes or hours. |
|
Allowed inner methods |
These options determine which inner EAP methods run inside the EAP-FAST tunnel. For anonymous in-band provisioning, EAP-GTC and EAP-MS-CHAPv2 must be enabled for backward compatibility. In most cases, all the inner methods should be checked. Note ACS always starts the authentication process by using the first enabled EAP method. For example, if you select EAP-GTC and EAP-MS-CHAPv2, then the first enabled EAP method is EAP-GTC. ACS always runs the first enabled EAP method. For example, if you select EAP-GTC and EAP-MS-CHAPv2, then the first enabled EAP method is EAP-GTC. |
|
EAP-GTC |
This option uses a two-factor authentication; for example, OTP. |
|
EAP-MS-CHAPv2 |
This option is used for AD authentication. |
|
EAP-TLS |
This option uses certificates for authentication. |
|
Field |
Description |
|
Posture Validation |
Determines the EAP-FAST posture-validation mode. Select one of the following posture-validation modes: • None—Authentication is performed; however, no posture-validation data is requested from the client and no SPT is returned. • Required—Authentication and posture validation are performed in the same authentication session. As a result, an SPT is returned. If this option is selected and posture credentials that are requested from the client are not received, authentication fails. If you are implementing NAC, this option should be enabled. • Optional—Client may not supply posture data. Sets a default SPT when a client cannot supply posture data to ACS. • Use Token—Select an SPT from the drop-down list to use as the default posture token. • Posture Only—Perform posture validation without running authentication inner methods within the authentication session. This option returns an SPT for posture validation. |
|
EAP-TLS |
Check this check box to enable EAP-TLS authentication. Note: EAP-TLS is a certificate-based authentication protocol. EAP-TLS authentication can occur only after you have completed the required steps on the ACS Certificate Setup page. |
|
Select to enable EAP-based Message Digest 5 hashed authentication. |
|
|
Credential Validation Databases |
Select the databases that you want to use to validate users. Select from the Available Databases list and use the arrows to move them into the Selected Databases list. |
MAC Authentication Mapping Page
The MAC Authentication Mapping page contains:
|
Field |
Description |
|
MAC Addresses |
Enter the MAC Addresses to map to a user group. These values should be comma-separated values. Two MAC address formats are accepted: 00-0D-60-FB-16-D3 or 000D.60FB.16D3. MAC prefixes that serve as ranges are acceptable. For example, 00-0D-60-FB-16 or 000D.60 would match any MAC address that begins with these bytes. MAC prefixes must contain an even number of hexadecimal digits. MAC address matching is case sensitive. |
|
User-Group |
Select the group from the ACS-defined groups to which to apply the MAC Authentication policy. |
|
Field |
Description |
|
If a MAC address is not defined or there is no matched mapping. |
If the MAC addresses entered in the provided fields do not match any of the MAC addresses entered, select a group to which to assign the MAC address. |
|
Add |
Adds a MAC Address mapping field. |
|
Delete |
Deletes a MAC Address mapping field. |
|
Submit |
Click to submit your changes to the ACS database. |
|
Cancel |
Returns you to the Network Access Profiles Page. |
Continue reading here: Configuring Fail Open
Was this article helpful?