<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 802.1x - Apple Workstation in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/802-1x-apple-workstation/m-p/5154228#M590995</link>
    <description>&lt;P&gt;The answer might depend on how the rest of the environment&amp;nbsp; (windows endpoints?) are being authenticated and authorized.&lt;BR /&gt;I favor trying to use a similar authentication flow for both win &amp;amp; mac based user workstations, simplifies troubleshooting at later stages.&lt;BR /&gt;If you're using machine/computer certificates to authenticate the windows machines, you could create a new certificate template specifically for the macs and authenticate &amp;amp; authorized based on that.&lt;BR /&gt;(I know of few environments that do this.)&lt;/P&gt;
&lt;P&gt;And/or you could look into issuing user certs &amp;amp; use those.&lt;/P&gt;
&lt;P&gt;And as Arne points out, you maintain this configuration via Jamf.&lt;/P&gt;</description>
    <pubDate>Wed, 31 Jul 2024 21:19:15 GMT</pubDate>
    <dc:creator>Jonatan Jonasson</dc:creator>
    <dc:date>2024-07-31T21:19:15Z</dc:date>
    <item>
      <title>802.1x - Apple Workstation</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-apple-workstation/m-p/5154052#M590985</link>
      <description>&lt;P&gt;Trying to identify the best way to authentication and authorize Apple endpoints on a Wired interface to Cisco ISE.&lt;/P&gt;&lt;P&gt;Environment:&lt;/P&gt;&lt;P&gt;1. Macs are AD bound&lt;/P&gt;&lt;P&gt;2. Macs are managed via Jamf&lt;/P&gt;&lt;P&gt;3. There is NO local computer certificate&lt;/P&gt;&lt;P&gt;4. Users log into macs with a PIV card&lt;/P&gt;&lt;P&gt;How would you go about authenticating and authorizing them?&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jul 2024 13:29:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-apple-workstation/m-p/5154052#M590985</guid>
      <dc:creator>ryanbess</dc:creator>
      <dc:date>2024-07-31T13:29:50Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x - Apple Workstation</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-apple-workstation/m-p/5154225#M590994</link>
      <description>&lt;P&gt;As far as I know, MACOS doesn't have any GUI support for creating 802.1X supplicant profiles, other than EAP-PEAP (username/password). This means, if you want to, e.g., use client certificate authentication, &lt;A href="https://support.apple.com/en-au/guide/deployment/depc47f60521/web" target="_self"&gt;then you must do this via JAMF and have the profile pushed&lt;/A&gt; to each managed MACOS device. Not sure what kind of a PIV card you're using - but in either case, if there is an 802.1X supplicant EAP method that can read the username from such a thing, then you might be able to use it.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jul 2024 21:02:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-apple-workstation/m-p/5154225#M590994</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2024-07-31T21:02:32Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x - Apple Workstation</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-apple-workstation/m-p/5154228#M590995</link>
      <description>&lt;P&gt;The answer might depend on how the rest of the environment&amp;nbsp; (windows endpoints?) are being authenticated and authorized.&lt;BR /&gt;I favor trying to use a similar authentication flow for both win &amp;amp; mac based user workstations, simplifies troubleshooting at later stages.&lt;BR /&gt;If you're using machine/computer certificates to authenticate the windows machines, you could create a new certificate template specifically for the macs and authenticate &amp;amp; authorized based on that.&lt;BR /&gt;(I know of few environments that do this.)&lt;/P&gt;
&lt;P&gt;And/or you could look into issuing user certs &amp;amp; use those.&lt;/P&gt;
&lt;P&gt;And as Arne points out, you maintain this configuration via Jamf.&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jul 2024 21:19:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-apple-workstation/m-p/5154228#M590995</guid>
      <dc:creator>Jonatan Jonasson</dc:creator>
      <dc:date>2024-07-31T21:19:15Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x - Apple Workstation</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-apple-workstation/m-p/5154237#M590996</link>
      <description>&lt;P&gt;do you know of any way to use EAP-PEAP to authenticate the mac computer account.&amp;nbsp; &amp;nbsp;This is a function that can be done for windows via mschapv2.&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jul 2024 21:32:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-apple-workstation/m-p/5154237#M590996</guid>
      <dc:creator>ryanbess</dc:creator>
      <dc:date>2024-07-31T21:32:18Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x - Apple Workstation</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-apple-workstation/m-p/5154238#M590997</link>
      <description>&lt;P&gt;yes we are trying to follow a similar approach for our windows endpoints but the not having certs on box (i.e. computer certs) is really hindering us.&amp;nbsp; So much as i can find there is very limited things on the internet that define how to effectively do the things on mac.&amp;nbsp; Windows, yeah there's tons of youtube, blogs, etc that do this....thus the post here to get folks thoughts given the environment described in the origional post.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jul 2024 21:34:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-apple-workstation/m-p/5154238#M590997</guid>
      <dc:creator>ryanbess</dc:creator>
      <dc:date>2024-07-31T21:34:15Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x - Apple Workstation</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-apple-workstation/m-p/5154272#M591004</link>
      <description>&lt;P&gt;I have limited experience with MACOS - many years ago I used the Apple Configurator app on the MAC to create an 802.1X WLAN profile for an iPhone. It was a tedious affair and proved to me that this job is best done with an MDM.&amp;nbsp; Have a look on the JAMF console to see what options you have.&lt;/P&gt;
&lt;P&gt;EAP-PEAP (MSCHAPv2) does not require any MDM - if you associate your MAC to an SSID with Enterprise 802.1X configured, and talking to a RADIUS server that offers EAP-PEAP, then the MAC will open a username/password dialogue. If the RADIUS server does not offer the EAP-PEAP method, then your out of luck.&amp;nbsp; Be careful with username/password - if the password changes frequently, then it causes havoc with your network authenticated users (e.g. if the password is changed on the MAC, but they forget to change the password on the MACOS supplicant config - in the Windows world this is common when users have their AD creds on mobile devices - they tend to lock out their AD accounts)&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jul 2024 22:44:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-apple-workstation/m-p/5154272#M591004</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2024-07-31T22:44:38Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x - Apple Workstation</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-apple-workstation/m-p/5154281#M591005</link>
      <description>&lt;P&gt;I send ypu PM check it&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jul 2024 23:20:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-apple-workstation/m-p/5154281#M591005</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-07-31T23:20:48Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x - Apple Workstation</title>
      <link>https://community.cisco.com/t5/network-access-control/802-1x-apple-workstation/m-p/5154694#M591025</link>
      <description>&lt;P&gt;&lt;A href="https://cs.co/ise-berg#apple" target="_blank"&gt;https://cs.co/ise-berg#apple&lt;/A&gt; lists the official configuration docs from Apple for provisioning their devices.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Aug 2024 19:20:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/802-1x-apple-workstation/m-p/5154694#M591025</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2024-08-01T19:20:56Z</dc:date>
    </item>
  </channel>
</rss>

