<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic AAA NPS encryption in ICX Switches</title>
    <link>https://community.ruckuswireless.com/t5/ICX-Switches/AAA-NPS-encryption/m-p/33590#M2114</link>
    <description>If I want credentials sent to a Windows NPS server to be encrypted and not in the clear text, is it just the value for "key", or do we need something else? I think we should be using TLS but I can't find more information. We are using SSH to login which is encrypted but I'm worried about the credentials sent to the NSP server. We are using ICX 7450 and 7250 switches.</description>
    <pubDate>Thu, 08 Oct 2020 19:00:52 GMT</pubDate>
    <dc:creator>bob_heathote</dc:creator>
    <dc:date>2020-10-08T19:00:52Z</dc:date>
    <item>
      <title>AAA NPS encryption</title>
      <link>https://community.ruckuswireless.com/t5/ICX-Switches/AAA-NPS-encryption/m-p/33590#M2114</link>
      <description>If I want credentials sent to a Windows NPS server to be encrypted and not in the clear text, is it just the value for "key", or do we need something else? I think we should be using TLS but I can't find more information. We are using SSH to login which is encrypted but I'm worried about the credentials sent to the NSP server. We are using ICX 7450 and 7250 switches.</description>
      <pubDate>Thu, 08 Oct 2020 19:00:52 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/ICX-Switches/AAA-NPS-encryption/m-p/33590#M2114</guid>
      <dc:creator>bob_heathote</dc:creator>
      <dc:date>2020-10-08T19:00:52Z</dc:date>
    </item>
    <item>
      <title>Re: AAA NPS encryption</title>
      <link>https://community.ruckuswireless.com/t5/ICX-Switches/AAA-NPS-encryption/m-p/33591#M2115</link>
      <description>Well, unfortunately Windows NPS supports RADIUS, so this is not really an ICX issue that can be fixed by Comscope or Ruckus but rather a protocol limitation.&amp;nbsp; In fact ANY vendor including direct competitors such as HP/ProCurve and Cisco that login to NPS use RADIUS as well and have the same weakness.&amp;nbsp; It might be better if it at least used PEAP, but I have never had that working outside of Wireless Authentication, which is another topic altogether.&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;If you want to do full credential encryption you might prefer TACACS+ or perhaps LDAPS /w TLS.&amp;nbsp; Regardless, you are going to need something more robust than NPS.&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;What comes to mind is ClearPass and the Identify Services Engine (ISE).&amp;nbsp; I am pretty sure NPS is being deprecated much like IAS was years ago.&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Good luck.</description>
      <pubDate>Fri, 09 Oct 2020 04:46:20 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/ICX-Switches/AAA-NPS-encryption/m-p/33591#M2115</guid>
      <dc:creator>netwizz</dc:creator>
      <dc:date>2020-10-09T04:46:20Z</dc:date>
    </item>
    <item>
      <title>Re: AAA NPS encryption</title>
      <link>https://community.ruckuswireless.com/t5/ICX-Switches/AAA-NPS-encryption/m-p/33592#M2116</link>
      <description>Thanks for the great reply.&amp;nbsp;</description>
      <pubDate>Fri, 09 Oct 2020 17:47:19 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/ICX-Switches/AAA-NPS-encryption/m-p/33592#M2116</guid>
      <dc:creator>bob_heathote</dc:creator>
      <dc:date>2020-10-09T17:47:19Z</dc:date>
    </item>
  </channel>
</rss>

