Validation of the PAN VPN, SSID, and PEAP-TEAP Protocols

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Validation of the PAN VPN, SSID, and PEAP-TEAP Protocols

L3 Networker

Hi Team 

I got a question :

 


During a previous session with end user, it was determined that, following the migration from PEAP to TEAP on the metropolitan area’s wireless network, 802.1X authentications fail to complete correctly when traversing the site-to-site VPN between a branch and the corporate headquarters.
From a technical standpoint, the following was observed:
• The authentication process starts correctly, but the session is not completed and times out in Cisco ISE.
• The access points are able to send requests to the NAC; however, a complete response is not received.
• At the corporate headquarters (without going through the VPN), behavior is normal.
Based on the above, and considering that:
• TEAP introduces greater encapsulation and larger packet sizes compared to PEAP
• The IPsec VPN adds additional overhead
The primary hypothesis is a possible fragmentation or MTU issue in the VPN tunnel, which would be preventing the EAP exchange from completing correctly.

 

 

by any chance that you have a case similar to this one in order for me to solve the issue.

 

 

this is my action plan 

 

Agreed-Upon Testing Plan
To validate this hypothesis, it was agreed to conduct controlled tests during a low-impact window, including the following activities:
1. Validation of the actual MTU on the path
o Connectivity tests with the DF flag to identify the maximum size without fragmentation.
2. Controlled adjustment of the MTU in the VPN tunnel
o Reduce the MTU to a reference value (e.g., 1360) for testing.
3. Conduct authentication tests
o Verify whether the TEAP process completes successfully after the adjustment.
4. Monitor and capture traffic
o Review behavior at the firewall and NAC levels to confirm whether symptoms of fragmentation or truncated sessions disappear.

 

 

Any kind of help would be highly cherished

2 REPLIES 2

Cyber Elite

Hello,

While I have not had that same issue. Your path seems logical to ensure it either is or is not MTU. Depending on the packets, might have to go lower than what you have proposed.

Regards,

L3 Networker

I realized that there is an internal misconfiguration error the firewall is working as expected.

  • 74 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!