Thursday, October 3, 2019

Cisco ISE Wireless 802.1x Compute Auth

I’m setting up Cisco ISE with a Cisco WLC to allow only Domain Joined Computers on the the Network (That single SSID). It’s a Windows 7 native supplicant which I configured for WPA2 enterprise AES and used the Computer Authentication Only (in the new wireless network setup).

The client is unable to connect. ISE is showing the following error: “client didn't provide suitable ciphers that are allowed on ise”

I have my policy admission criteria configured to Radius called station ends with [ssid name]. Inside of the policy AuthC is set to check AD and AuthZ is configured to PEAP and Member of domain Computer.

This is on ISE 2.6 patch 2.

Any idea why I get the error in ise live logs “client didn't provide suitable ciphers that are allowed on ise” and the client is unable to authenticate.

Also if I remove ISE and just use PSK on the WLC client is able to successfully connect.



No comments:

Post a Comment