03-13-2025 04:36 AM
Hello Community,
We have upgraded from Win 10 to Win 11 and are currently using EAP PEAP as the 802.1x authentication method. I was told this would no longer work with Win 11 and we would need to implement EAP TLS. I understand EAP TLS is not available for the version of XIQ SE we have - 23.4.12.3.
However, I believe later version of XIQ SE support EAP TLS. If this is not the case please let me know. Could anyone let me know which minimum version of XIQ SE supports EAP TLS for XIQ SE and will I need a root certificate to be installed on XIQ SE and the NAC devices?
Is there a guide or similar I could use to Implement EAP TLS?
Currently, we use the built in 802.1x authentication via a LDAP server. This I believe supports MsCHAP, PEAP and EAP-MsCHAPV2 only.
Many Thanks,
Solved! Go to Solution.
03-13-2025 05:28 AM - edited 03-13-2025 05:30 AM
Hi Asifi,
Any version of XIQ-SE supports EAP-TLS.
If you want EAP-PEAP to be still supported in Windows 11 clients, you will probably need to disable Credential Guard feature.
These links might be useful:
https://extreme-networks.my.site.com/ExtrArticleDetail?an=000100238&q=windows%2011%20802%201x
However, using EAP-TLS is a way better than EAP-PEAP in terms of security.
REGARDS, Robert
04-16-2025 07:48 AM
@Zdeněk_Pala - Thanks for the steps, much appreciated. For step 1, the CA trusted certificate goes in the section as in the screenshot below. This is what I have when I click on each Control Engine and go to Certificates > Manage >AAA Trusted Certificate Authorities. Also as I have 2 Control Engines, is the CA installed on each Engine?
Thanks,
04-16-2025 08:23 AM
Hi.
The Trusted Root CA should be inserted once (per AAA config), but the screen can be reached from multiple places.
add your CA certificate to that screen and you will see...
The AAA config is applied to all relevant Access Control Engines
Hope it helps.
04-17-2025 03:12 AM
@Zdeněk_Pala Thank you - finally, what format of the Root Certificate to use?
I have the below.
Many Thanks,
04-17-2025 03:26 AM
I was always using .CER. I would use the second one from your list.
Sincerely yours
04-17-2025 03:52 AM