Configuring EAP-TLS for Cisco ACS and ISE

Cisco Secure Access Control Server (ACS) provides authentication, accounting, and authorization services to network devices. It includes routers, switches, firewall, and network access servers.

To configure EAP-TLS for Cisco ACS, perform the following:
  1. Install a new ACS certificate.
  2. Add a Certificate Authority to the list of trusted Certificate Authorities.
  3. Edit the certificate trust list.
  4. Specify Global Authentication settings.
  5. Add a user for EAP-TLS authentication.
  6. Set up AP on the ACS.
  7. Restart ACS.

Cisco Identity Service Engine (ISE) allows user controlled access to the tools required while providing security through policy management and enforcement. This is critical in complex environments with access to data traffic from multiple locations and device types.

To configure Cisco ISE and to perform similar tasks listed for ACS, refer to Cisco Identity Services Engine Administrator Guide and Cisco Identity Services Engine User Guide.