Thanks for the information. I appreciate that there are two versions of Rasec, radius over TLS and radius over DTLS. I thought your suggestion couldn't possibly be right, I mean why would Cisco take two different approaches in securing Radius....but I tip my hat to you. All the documentation I can find (https://documentation.meraki.com/MR/Encryption_and_Authentication/MR_RADSec) states that Meraki Radsec uses TLS (Only tcp connections can be seen in the packet captures to prove it), whereas and I'm struggling to find an official Cisco ISE document, I did find this article (https://www.wiresandwi.fi/blog/cisco-radsec-part-1-radius-tls-dtls-overview) and it states 'Throughout this series, we will use RADIUS over DTLS for our RadSec implementation, since this is the only mode available for Cisco ISE.' Oh dear......Anyone from Cisco want to jump in and say, 'Don't worry, upgrade to the latest version of ISE and it will support Radius over TLS'..or someone from Meraki instead want to say 'No worries, MR3X supports Radius over DTLS'??? Please.....
... View more