300-715 · Question #318
An enterprise uses a separate PSN for each of its four remote sites. Recently, a user reported receiving an "EAP-TLS authentication failed" message when moving between remote sites. Which…
The correct answer is D. Renew the expired certificate on one of the PSN. An "EAP-TLS authentication failed" message for a user moving between sites, each with its own PSN, indicates a potential issue with a PSN's certificate. The most likely cause is an expired certificate on one of the PSN nodes.
Question
An enterprise uses a separate PSN for each of its four remote sites. Recently, a user reported receiving an "EAP-TLS authentication failed" message when moving between remote sites. Which configuration must be applied on Cisco ISE?
Options
- AUse a third-party certificate on the network device.
- BAdd the device to all PSN nodes in the deployment.
- CConfigure an authorization profile for the end users.
- DRenew the expired certificate on one of the PSN.
How the community answered
(36 responses)- A3% (1)
- B17% (6)
- C8% (3)
- D72% (26)
Why each option
An "EAP-TLS authentication failed" message for a user moving between sites, each with its own PSN, indicates a potential issue with a PSN's certificate. The most likely cause is an expired certificate on one of the PSN nodes.
While using third-party certificates is common, this choice doesn't address the specific symptom of "EAP-TLS authentication failed" likely due to an expired certificate on a PSN, not the type of certificate on the network device.
"Add the device to all PSN nodes" is not a standard configuration step; network devices are typically registered once as NADs in ISE. Endpoints do not need to be added to PSNs.
An authorization profile defines what access the user gets after successful authentication, not the cause of an EAP-TLS authentication failure itself.
EAP-TLS authentication relies heavily on valid server certificates presented by the PSN to the client. If a user moves to a site whose PSN has an expired EAP-TLS certificate, the client will fail to establish a secure TLS tunnel, resulting in an "EAP-TLS authentication failed" message. Renewing the expired certificate on the affected PSN ensures continuous trust and successful authentication across all sites.
Concept tested: Cisco ISE EAP-TLS Certificate Management
Source: https://www.cisco.com/c/en/us/td/docs/security/ise/3-0/admin_guide/b_ise_admin_3_0/b_ise_admin_3_0_chapter_01000.html#concept_56B75775317E4598A843E2C4D350B4CC
Topics
Community Discussion
No community discussion yet for this question.