<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Access Manager and EAP-TLS in Cloud Networking Platform</title>
    <link>https://community.cisco.com/t5/cloud-networking-platform/access-manager-and-eap-tls/m-p/5408027#M3109</link>
    <description>&lt;P&gt;I got a quote for Access Manager, and the pricing is ridiculous. The fact that I have to pay the amount of money they quoted me so I can securely do NAC on their hardware is ridiculous. &lt;/P&gt;</description>
    <pubDate>Thu, 29 Jan 2026 22:05:00 GMT</pubDate>
    <dc:creator>rhinkamper1</dc:creator>
    <dc:date>2026-01-29T22:05:00Z</dc:date>
    <item>
      <title>Access Manager and EAP-TLS</title>
      <link>https://community.cisco.com/t5/cloud-networking-platform/access-manager-and-eap-tls/m-p/5408019#M3101</link>
      <description>&lt;P&gt;I'm currently evaluating Meraki Access Manager for EAP-TLS certificate-based authentication, and I'm a bit unclear on the CA requirements.&lt;/P&gt;&lt;P&gt;Some earlier articles I've come across suggest that third-party or external CAs may not be required, implying that Meraki might handle certificate issuance internally. However, in the Access Manager interface, I only see an option to upload CA certificates, which seems to indicate we’d need to bring our own PKI.&lt;/P&gt;&lt;P&gt;Can someone clarify:&lt;BR /&gt;Do we need to use our own Certificate Authority (e.g., Microsoft CA, SecureW2, etc.) for EAP-TLS authentication with Access Manager, or is there a built-in Meraki CA that can issue and manage certificates for clients?&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Jul 2025 10:03:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-networking-platform/access-manager-and-eap-tls/m-p/5408019#M3101</guid>
      <dc:creator>stu84773</dc:creator>
      <dc:date>2025-07-11T10:03:24Z</dc:date>
    </item>
    <item>
      <title>Re: Access Manager and EAP-TLS</title>
      <link>https://community.cisco.com/t5/cloud-networking-platform/access-manager-and-eap-tls/m-p/5408020#M3102</link>
      <description>&lt;P&gt;No, Meraki Access Manager does not currently include a built-in Certificate Authority (CA) to issue client certificates.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Meraki does provide its own &lt;/SPAN&gt;&lt;STRONG&gt;RADIUS server certificate&lt;/STRONG&gt;&lt;SPAN&gt; (used by Access Manager and local RADIUS on MR) that you can download and install on client devices to ensure trust during the TLS handshake.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://documentation.meraki.com/Access_Manager/Access_Manager_Configuration_Guides/Access_Manager_-_EAP-TLS_Client_Configuration_%28Windows%2C_macOS_and_iOS%29" target="_blank" rel="noopener nofollow noreferrer"&gt;Access Manager - EAP-TLS Client Configuration (Windows, macOS and iOS) - Cisco Meraki Documentation&lt;/A&gt;&lt;/P&gt;&lt;P&gt;However, when you use Meraki MDM, you can use Meraki certificates.&lt;/P&gt;&lt;P&gt;&lt;A href="https://documentation.meraki.com/General_Administration/Cross-Platform_Content/Configuring_EAP-TLS_Wireless_Authentication_with_Systems_Manager_Sentry_Wifi#Configuring_EAP-TLS_using_Systems_Manager_Sentry_WiFi_Security" target="_blank" rel="noopener nofollow noreferrer"&gt;https://documentation.meraki.com/General_Administration/Cross-Platform_Content/Configuring_EAP-TLS_Wireless_Authentication_with_Systems_Manager_Sentry_Wifi#Configuring_EAP-TLS_using_Systems_Manager_Sentry_WiFi_Security&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Jul 2025 10:24:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-networking-platform/access-manager-and-eap-tls/m-p/5408020#M3102</guid>
      <dc:creator>aleabrahao</dc:creator>
      <dc:date>2025-07-11T10:24:18Z</dc:date>
    </item>
    <item>
      <title>Re: Access Manager and EAP-TLS</title>
      <link>https://community.cisco.com/t5/cloud-networking-platform/access-manager-and-eap-tls/m-p/5408021#M3103</link>
      <description>&lt;P&gt;Check this: &lt;/P&gt;&lt;P&gt;&lt;A href="https://documentation.meraki.com/Access_Manager/Access_Manager_Configuration_Guides/Access_Manager_Certificate_Based_Authentication_-_EAP-TLS_with_Entra_ID_Lookup" target="_blank" rel="noopener nofollow noreferrer"&gt;Access Manager Certificate Based Authentication - EAP-TLS with Entra ID Lookup - Cisco Meraki Docume...&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://documentation.meraki.com/Access_Manager/Access_Manager_Configuration_Guides/Access_Manager_-_EAP-TLS_Client_Configuration_(Windows%2C_macOS_and_iOS)" target="_blank" rel="noopener nofollow noreferrer"&gt;Access Manager - EAP-TLS Client Configuration (Windows, macOS and iOS) - Cisco Meraki Documentation&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 11 Jul 2025 13:34:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-networking-platform/access-manager-and-eap-tls/m-p/5408021#M3103</guid>
      <dc:creator>Blue_Bird</dc:creator>
      <dc:date>2025-07-11T13:34:55Z</dc:date>
    </item>
    <item>
      <title>Re: Access Manager and EAP-TLS</title>
      <link>https://community.cisco.com/t5/cloud-networking-platform/access-manager-and-eap-tls/m-p/5408022#M3104</link>
      <description>&lt;P&gt;I am using a root certificate from one of our Windows domain controllers and I am getting this error.  Any thoughts?&lt;/P&gt;&lt;DIV class=""&gt;Failure/ Rejection info&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;Reason&lt;/DIV&gt;&lt;/DIV&gt;&lt;P class=""&gt;The provided certificate is untrusted. This might be due to its signer being disabled, extra or duplicate certificates in the chain, or another untrusted reason.&lt;/P&gt;&lt;P class=""&gt; &lt;/P&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;Suggested action&lt;/DIV&gt;&lt;/DIV&gt;&lt;P class=""&gt;Verify that the certificate chain does not contain duplicate or unnecessary certificates. Additionally, refer to the certificates page to ensure the signer is enabled and the chain is valid.&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Fri, 11 Jul 2025 21:29:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-networking-platform/access-manager-and-eap-tls/m-p/5408022#M3104</guid>
      <dc:creator>eduardo-nunez</dc:creator>
      <dc:date>2025-07-11T21:29:52Z</dc:date>
    </item>
    <item>
      <title>Re: Access Manager and EAP-TLS</title>
      <link>https://community.cisco.com/t5/cloud-networking-platform/access-manager-and-eap-tls/m-p/5408023#M3105</link>
      <description>&lt;P&gt;Meraki Access Manager does not include a CA.&lt;/P&gt;&lt;P&gt;However, Meraki Systems Manager does - and Meraki Access Manager can use those certificates.&lt;/P&gt;&lt;P&gt;&lt;A href="https://documentation.meraki.com/SM/Profiles_and_Settings/Certificates_in_Meraki_Systems_Manager" target="_blank" rel="nofollow noopener noreferrer"&gt;https://documentation.meraki.com/SM/Profiles_and_Settings/Certificates_in_Meraki_Systems_Manager&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://documentation.meraki.com/SM/Profiles_and_Settings/Certificates_Payload_(Pushing_Certificates)" target="_blank" rel="nofollow noopener noreferrer"&gt;https://documentation.meraki.com/SM/Profiles_and_Settings/Certificates_Payload_(Pushing_Certificates)&lt;/A&gt;&lt;/P&gt;&lt;P&gt;I've also set it up using Microsoft Intune CloudPKI.&lt;/P&gt;&lt;P&gt;You could use a Microsoft CA server in an AD environment and configure group policy to deploy certificates to machines/users.&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jul 2025 01:21:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-networking-platform/access-manager-and-eap-tls/m-p/5408023#M3105</guid>
      <dc:creator>Philip D'Ath</dc:creator>
      <dc:date>2025-07-14T01:21:14Z</dc:date>
    </item>
    <item>
      <title>Re: Access Manager and EAP-TLS</title>
      <link>https://community.cisco.com/t5/cloud-networking-platform/access-manager-and-eap-tls/m-p/5408024#M3106</link>
      <description>&lt;P&gt;I am working through this myself as there is no documentation on how to do this with a Windows CA. But what I have come up with so far is.&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;You have to setup user certificate auto enrollment.&lt;/LI&gt;&lt;LI&gt;Take special note of how you manually configure the Wifi connection and configure your GPO accordingly. &lt;A href="https://documentation.meraki.com/Access_Manager/Access_Manager_Configuration_Guides/Access_Manager_-_EAP-TLS_Client_Configuration_(Windows%2C_macOS_and_iOS)" target="_blank" rel="nofollow noopener noreferrer"&gt;https://documentation.meraki.com/Access_Manager/Access_Manager_Configuration_Guides/Access_Manager_-_EAP-TLS_Client_Configuration_(Windows%2C_macOS_and_iOS)&lt;/A&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;I have gotten it to work with an endpoint certificate, and I am now working on the user part with Entra. &lt;/P&gt;</description>
      <pubDate>Tue, 12 Aug 2025 20:08:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-networking-platform/access-manager-and-eap-tls/m-p/5408024#M3106</guid>
      <dc:creator>rhinkamper1</dc:creator>
      <dc:date>2025-08-12T20:08:55Z</dc:date>
    </item>
    <item>
      <title>Re: Access Manager and EAP-TLS</title>
      <link>https://community.cisco.com/t5/cloud-networking-platform/access-manager-and-eap-tls/m-p/5408025#M3107</link>
      <description>&lt;P&gt;Take a look at this access manager + cloud pki guide&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.hypershift.com/blog/meraki-intune-cloud-pki" target="_blank" rel="nofollow noopener noreferrer"&gt;https://www.hypershift.com/blog/meraki-intune-cloud-pki&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Aug 2025 23:24:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-networking-platform/access-manager-and-eap-tls/m-p/5408025#M3107</guid>
      <dc:creator>gary5555</dc:creator>
      <dc:date>2025-08-20T23:24:36Z</dc:date>
    </item>
    <item>
      <title>Re: Access Manager and EAP-TLS</title>
      <link>https://community.cisco.com/t5/cloud-networking-platform/access-manager-and-eap-tls/m-p/5408026#M3108</link>
      <description>&lt;P&gt;Make sure upload and *Enable* your CA, then have your client configured to use a cert issues by your CA, create a access rule to match the CA [like common name]&lt;/P&gt;</description>
      <pubDate>Thu, 11 Sep 2025 14:54:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-networking-platform/access-manager-and-eap-tls/m-p/5408026#M3108</guid>
      <dc:creator>edondurguti</dc:creator>
      <dc:date>2025-09-11T14:54:52Z</dc:date>
    </item>
    <item>
      <title>Re: Access Manager and EAP-TLS</title>
      <link>https://community.cisco.com/t5/cloud-networking-platform/access-manager-and-eap-tls/m-p/5408027#M3109</link>
      <description>&lt;P&gt;I got a quote for Access Manager, and the pricing is ridiculous. The fact that I have to pay the amount of money they quoted me so I can securely do NAC on their hardware is ridiculous. &lt;/P&gt;</description>
      <pubDate>Thu, 29 Jan 2026 22:05:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-networking-platform/access-manager-and-eap-tls/m-p/5408027#M3109</guid>
      <dc:creator>rhinkamper1</dc:creator>
      <dc:date>2026-01-29T22:05:00Z</dc:date>
    </item>
    <item>
      <title>Re: Access Manager and EAP-TLS</title>
      <link>https://community.cisco.com/t5/cloud-networking-platform/access-manager-and-eap-tls/m-p/5408028#M3110</link>
      <description>&lt;P&gt;The prices are a bit lower than ISE session licenses.  And I do believe an ISE like environment is running the radius services.&lt;BR /&gt;&lt;BR /&gt;They could of course do a little extra effort and provide full blown profiling and perhaps an optional native cloud PKI so you don't need to rely on MS Cloud PKI or SCEPman.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Jan 2026 13:10:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-networking-platform/access-manager-and-eap-tls/m-p/5408028#M3110</guid>
      <dc:creator>joey.debra</dc:creator>
      <dc:date>2026-01-30T13:10:51Z</dc:date>
    </item>
  </channel>
</rss>

