Skip to main content

Allowed Protocols

Location in GUI: Work Centers » Network Access » Policy Elements » Results » Allowed Protocols

Diagram

Classes

policy_elements (ise.network_access)

NameTypeConstraintMandatoryDefault Value
allowed_protocolsList[allowed_protocols]No

allowed_protocols (ise.network_access.policy_elements)

NameTypeConstraintMandatoryDefault Value
nameStringRegex: ^[\w\d_ ]+$Yes
descriptionStringNo
process_host_lookupBooleantrue, falseNotrue
allow_pap_asciiBooleantrue, falseNotrue
allow_chapBooleantrue, falseNofalse
allow_ms_chap_v1Booleantrue, falseNofalse
allow_ms_chap_v2Booleantrue, falseNofalse
allow_eap_md5Booleantrue, falseNotrue
allow_leapBooleantrue, falseNofalse
allow_eap_tlsBooleantrue, falseNotrue
allow_eap_ttlsBooleantrue, falseNotrue
allow_eap_fastBooleantrue, falseNotrue
allow_peapBooleantrue, falseNotrue
allow_teapBooleantrue, falseNotrue
allow_preferred_eap_protocolBooleantrue, falseNofalse
preferred_eap_protocolChoiceEAP_FAST, PEAP, LEAP, EAP_MD5, EAP_TLS, EAP_TTLS, TEAPNo
eap_tls_l_bitBooleantrue, falseNofalse
allow_weak_ciphers_for_eapBooleantrue, falseNofalse
require_message_authBooleantrue, falseNofalse
five_gBooleantrue, falseNofalse
teapClass[teap]No
eap_ttlsClass[eap_ttls]No
eap_tlsClass[eap_tls]No
eap_fastClass[eap_fast]No
peapClass[peap]No

teap (ise.network_access.policy_elements.allowed_protocols)

NameTypeConstraintMandatoryDefault Value
eap_ms_chap_v2Booleantrue, falseNotrue
eap_ms_chap_v2_pwd_changeBooleantrue, falseNotrue
eap_ms_chap_v2_pwd_change_retriesIntegermin: 0, max: 3No3
eap_tlsBooleantrue, falseNotrue
eap_tls_auth_of_expired_certsBooleantrue, falseNofalse
accept_client_cert_during_tunnel_estBooleantrue, falseNotrue
enable_eap_chainingBooleantrue, falseNofalse
allow_downgrade_mskBooleantrue, falseNotrue
request_basic_pwd_authBooleantrue, falseNofalse

eap_ttls (ise.network_access.policy_elements.allowed_protocols)

NameTypeConstraintMandatoryDefault Value
pap_asciiBooleantrue, falseNotrue
chapBooleantrue, falseNotrue
ms_chap_v1Booleantrue, falseNotrue
ms_chap_v2Booleantrue, falseNotrue
eap_md5Booleantrue, falseNotrue
eap_ms_chap_v2Booleantrue, falseNotrue
eap_ms_chap_v2_pwd_changeBooleantrue, falseNotrue
eap_ms_chap_v2_pwd_change_retriesIntegermin: 0, max: 3No1

eap_tls (ise.network_access.policy_elements.allowed_protocols)

NameTypeConstraintMandatoryDefault Value
auth_of_expired_certsBooleantrue, falseNofalse
enable_stateless_session_resumeBooleantrue, falseNofalse
session_ticket_ttlIntegermin: 1No
session_ticket_ttl_unitChoiceSECONDSMINUTES, HOURS, DAYS, WEEKSNo
session_ticket_percentageIntegermin: 1, max: 100No

eap_fast (ise.network_access.policy_elements.allowed_protocols)

NameTypeConstraintMandatoryDefault Value
eap_ms_chap_v2Booleantrue, falseNotrue
eap_ms_chap_v2_pwd_changeBooleantrue, falseNotrue
eap_ms_chap_v2_pwd_change_retriesIntegermin: 0, max: 3No1
eap_gtcBooleantrue, falseNotrue
eap_gtc_pwd_changeBooleantrue, falseNotrue
eap_gtc_pwd_change_retriesIntegermin: 0, max: 3No1
eap_tlsBooleantrue, falseNotrue
eap_tls_auth_of_expired_certsBooleantrue, falseNofalse
use_pacsBooleantrue, falseNotrue
use_pacs_tunnel_pac_ttlIntegermin: 1, max: 10000No90
use_pacs_tunnel_pac_ttl_unitsChoiceSECONDSMINUTES, HOURS, DAYS, WEEKSNoDAYS
use_pacs_use_proactive_pac_update_precentageIntegermin: 1, max: 100No10
use_pacs_allow_anonym_provisioningBooleantrue, falseNofalse
use_pacs_allow_authen_provisioningBooleantrue, falseNofalse
use_pacs_accept_client_certBooleantrue, falseNofalse
use_pacs_server_returnsBooleantrue, falseNofalse
use_pacs_allow_machine_authenticationBooleantrue, falseNofalse
use_pacs_machine_pac_ttlIntegermin: 1, max: 10000No1
use_pacs_machine_pac_ttl_unitsChoiceSECONDSMINUTES, HOURS, DAYS, WEEKSNoWEEKS
use_pacs_stateless_session_resumeBooleantrue, falseNofalse
enable_eap_chainingBooleantrue, falseNofalse

peap (ise.network_access.policy_elements.allowed_protocols)

NameTypeConstraintMandatoryDefault Value
eap_ms_chap_v2Booleantrue, falseNotrue
eap_ms_chap_v2_pwd_changeBooleantrue, falseNotrue
eap_ms_chap_v2_pwd_change_retriesIntegermin: 0, max: 3No1
eap_gtcBooleantrue, falseNofalse
eap_gtc_pwd_changeBooleantrue, falseNofalse
eap_gtc_pwd_change_retriesIntegermin: 0, max: 3No1
eap_tlsBooleantrue, falseNotrue
eap_tls_auth_of_expired_certsBooleantrue, falseNofalse
require_cryptobindingBooleantrue, falseNofalse
peap_v0Booleantrue, falseNofalse

Examples

ise:
network_access:
policy_elements:
allowed_protocols:
- name: Global Protocols
description: Allowed protocols
eap_tls:
auth_of_expired_certs: false
enable_stateless_session_resume: true
session_ticket_ttl: 5
session_ticket_ttl_unit: DAYS
session_ticket_percentage: 5
eap_fast:
eap_ms_chap_v2: true
eap_ms_chap_v2_pwd_change: true
eap_ms_chap_v2_pwd_change_retries: 3
eap_gtc: true
eap_gtc_pwd_change: true
eap_gtc_pwd_change_retries: 3
eap_tls: true
eap_tls_auth_of_expired_certs: false
use_pacs: true
use_pacs_tunnel_pac_ttl: 90
use_pacs_tunnel_pac_ttl_units: DAYS
use_pacs_use_proactive_pac_update_precentage: 90
use_pacs_allow_anonym_provisioning: true
use_pacs_allow_authen_provisioning: true
use_pacs_accept_client_cert: true
use_pacs_server_returns: true
use_pacs_allow_machine_authentication: true
use_pacs_machine_pac_ttl: 1
use_pacs_machine_pac_ttl_units: WEEKS
use_pacs_stateless_session_resume: false
enable_eap_chaining: false
eap_ttls:
pap_ascii: true
chap: true
ms_chap_v1: true
ms_chap_v2: true
eap_md5: true
eap_ms_chap_v2: true
eap_ms_chap_v2_pwd_change: true
eap_ms_chap_v2_pwd_change_retries: 1
teap:
eap_ms_chap_v2: true
eap_ms_chap_v2_pwd_change: true
eap_ms_chap_v2_pwd_change_retries: 3
eap_tls: true
eap_tls_auth_of_expired_certs: false
accept_client_cert_during_tunnel_est: true
enable_eap_chaining: false
allow_downgrade_msk: true
request_basic_pwd_auth: false
process_host_lookup: true
allow_pap_ascii: true
allow_chap: false
allow_ms_chap_v1: false
allow_ms_chap_v2: false
allow_eap_md5: true
allow_leap: false
allow_eap_tls: true
allow_eap_ttls: true
allow_eap_fast: true
allow_peap: false
allow_teap: true
allow_preferred_eap_protocol: true
preferred_eap_protocol: EAP_FAST
eap_tls_l_bit: false
allow_weak_ciphers_for_eap: false
require_message_auth: false
five_g: false