ISE Weak Network Authentication Method
Last updated
Detects users authenticating to Cisco ISE using weak or cleartext authentication protocols such as PAP, CHAP, MSCHAPv1, or EAP-MD5. These protocols transmit credentials with minimal protection, making them vulnerable to interception and replay attacks. Certificate-based methods like EAP-TLS or PEAP provide significantly stronger security.
Recommended Actions
Configure ISE authentication policies to require EAP-TLS, PEAP, or EAP-FAST for all network access. Disable PAP, CHAP, MSCHAPv1, and EAP-MD5 in the allowed protocols configuration for your policy sets. Investigate whether the weak authentication is caused by legacy devices that cannot support stronger protocols and plan their replacement.
Compatibility
Cisco ISE
Last updated