For the complete documentation index, see llms.txt. This page is also available as Markdown.

ISE Weak Network Authentication Method

Detects users authenticating to Cisco ISE using weak or cleartext authentication protocols such as PAP, CHAP, MSCHAPv1, or EAP-MD5. These protocols transmit credentials with minimal protection, making them vulnerable to interception and replay attacks. Certificate-based methods like EAP-TLS or PEAP provide significantly stronger security.

Recommended Actions

Configure ISE authentication policies to require EAP-TLS, PEAP, or EAP-FAST for all network access. Disable PAP, CHAP, MSCHAPv1, and EAP-MD5 in the allowed protocols configuration for your policy sets. Investigate whether the weak authentication is caused by legacy devices that cannot support stronger protocols and plan their replacement.

Compatibility

Cisco ISE

Last updated