Important Notice: Our web hosting provider recently started charging us for additional visits, which was unexpected. In response, we're seeking donations. Depending on the situation, we may explore different monetization options for our Community and Expert Contributors. It's crucial to provide more returns for their expertise and offer more Expert Validated Answers or AI Validated Answers. Learn more about our hosting issue here.

The WiSM log shows many messages similar to “Unable to delete username anonymous for mobile xx:xx:xx:xx:xx:xx” while some wireless clients (especially those authenticated by Extensible Authentication Protocol-Flexible Authentication via Secure Tunneling [EAP-FAST]) fail in their authentication. Why?

0
Posted

The WiSM log shows many messages similar to “Unable to delete username anonymous for mobile xx:xx:xx:xx:xx:xx” while some wireless clients (especially those authenticated by Extensible Authentication Protocol-Flexible Authentication via Secure Tunneling [EAP-FAST]) fail in their authentication. Why?

0

A. Authentication methods like EAP-FAST undergo two phases of authentication. In phase 1, the client and authentication, authorization, and accounting (AAA) server use Protected Access Credential (PAC) to authenticate each other and establish a mutually authenticated tunnel. This PAC is provisioned and managed dynamically by EAP-FAST through the AAA server. In other words, the first phase of authentication uses generic anonymous external identity in order to establish the tunnel. In phase 2, client authentication is done in the established tunnel. The client sends the original username and password to authenticate and establish a client authorization policy. As this authentication method hides the original user name at the first phase of authentication, the controller does not have a way to add the correct username to the authenticated user list. So the controller uses the anonymous username. The reason you see this error message might be due to Cisco bug ID CSCse53024 ( registered cus

Related Questions

Experts123