Cisco Cisco Identity Services Engine Software トラブルシューティングガイド

ページ / 19
Contents
Introduction
Prerequisites
Requirements
Components Used
Theory
Phases
PAC
When PACs are generated
EAP-FAST Server Master Key ACS 4.x vs ACS 5x and ISE
Session Resume
Server State
Stateless (PAC based)
AnyConnect NAM implementation
PAC provisioning (phase 0)
Anonymous TLS tunnel
Authenticated TLS tunnel
EAP-Chaining
Where PAC files are stored
AnyConnect NAM 3.1 vs 4.0
Examples
Network Diagram
EAP-Fast without EAP chaining with user and machine PAC
EAP-Fast with EAP chaining with PAC Fast Reconnect
EAP-Fast with EAP chaining without PAC
EAP-Fast with EAP chaining authorization PAC expiration
EAP-Fast with EAP chaining tunnel PAC expired
EAP-Fast with EAP chaining and anonymous TLS tunnel PAC provisioning
EAP-Fast with EAP chaining user authentication only
EAP-Fast with EAP chaining and inconsistent anonymous TLS tunnel settings
Troubleshoot
ISE
AnyConnect NAM
References
Introduction
This article explains details regarding EAP-FAST implementations on Cisco AnyConnect Network Access Manager
(NAM) and Identity Services Engine (ISE). It further explains how specific features work together and provides typical use
cases and examples.
Prerequisites