<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: cert for machine+ guest access in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/cert-for-machine-guest-access/m-p/3757222#M11825</link>
    <description>&lt;P&gt;Yes you can, there are many guides for EAP-TLS deployment with ISE, here is a new one to get started.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless-mobility/wireless-lan-wlan/213543-configure-eap-tls-flow-with-ise.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/wireless-mobility/wireless-lan-wlan/213543-configure-eap-tls-flow-with-ise.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would recommend building this in a test lab and do all testings.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 04 Dec 2018 02:00:55 GMT</pubDate>
    <dc:creator>Ambuj M</dc:creator>
    <dc:date>2018-12-04T02:00:55Z</dc:date>
    <item>
      <title>cert for machine+ guest access</title>
      <link>https://community.cisco.com/t5/wireless/cert-for-machine-guest-access/m-p/3755973#M11821</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;i am working on a solution to provide internet(only) to our Scanners Android based.&lt;/P&gt;
&lt;P&gt;we have WLC 5520 and ISE for integration. My solution was to configure L2 auth with PSK, since its only internet as we are separating form our internal network (similar to guest&amp;nbsp;WLAN solution)&lt;/P&gt;
&lt;P&gt;But we are also working to find if there is any cert based auth on scanners. i dont want to connect these scanners to AD and access internal network.&lt;/P&gt;
&lt;P&gt;Please help me with the traffic flow if there is any solution.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Satya.Mothukuri&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Mar 2022 07:15:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/cert-for-machine-guest-access/m-p/3755973#M11821</guid>
      <dc:creator>satya mothukuri</dc:creator>
      <dc:date>2022-03-10T07:15:49Z</dc:date>
    </item>
    <item>
      <title>Re: cert for machine+ guest access</title>
      <link>https://community.cisco.com/t5/wireless/cert-for-machine-guest-access/m-p/3756609#M11822</link>
      <description>&lt;P&gt;is it an option to install a non-windows-based PKI?&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_conn_pki/configuration/15-mt/sec-pki-15-mt-book/sec-cert-enroll-pki.html" target="_blank"&gt;&lt;SPAN&gt;Public Key Infrastructure Configuration Guide, Cisco IOS Release 15MT&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;be aware using certificates may have some impact on battery time.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;depending on the implementation on the device type it may need more CPU processing and use more power from the battery&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Dec 2018 07:58:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/cert-for-machine-guest-access/m-p/3756609#M11822</guid>
      <dc:creator>pieterh</dc:creator>
      <dc:date>2018-12-03T07:58:00Z</dc:date>
    </item>
    <item>
      <title>Re: cert for machine+ guest access</title>
      <link>https://community.cisco.com/t5/wireless/cert-for-machine-guest-access/m-p/3757206#M11823</link>
      <description>&lt;P&gt;you will have to first check if the scanners support certificate based authentication ?&lt;/P&gt;
&lt;P&gt;Even if you did user/password (AD) based authentication, the scanners will never talk to AD directly, they will only talk to controller, controller will talk to ISE and ISE will talk to AD for identity verification.&lt;/P&gt;
&lt;P&gt;you can choose to create a new AD group for scanners only and create a internet only authorization&lt;/P&gt;</description>
      <pubDate>Tue, 04 Dec 2018 01:00:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/cert-for-machine-guest-access/m-p/3757206#M11823</guid>
      <dc:creator>Ambuj M</dc:creator>
      <dc:date>2018-12-04T01:00:19Z</dc:date>
    </item>
    <item>
      <title>Re: cert for machine+ guest access</title>
      <link>https://community.cisco.com/t5/wireless/cert-for-machine-guest-access/m-p/3757216#M11824</link>
      <description>Thanks for replying.&lt;BR /&gt;If the scanners support,Should I need to install  the certificate in ISE???&lt;BR /&gt;Also any document on this will be much helpful.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 04 Dec 2018 01:30:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/cert-for-machine-guest-access/m-p/3757216#M11824</guid>
      <dc:creator>satya mothukuri</dc:creator>
      <dc:date>2018-12-04T01:30:52Z</dc:date>
    </item>
    <item>
      <title>Re: cert for machine+ guest access</title>
      <link>https://community.cisco.com/t5/wireless/cert-for-machine-guest-access/m-p/3757222#M11825</link>
      <description>&lt;P&gt;Yes you can, there are many guides for EAP-TLS deployment with ISE, here is a new one to get started.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/wireless-mobility/wireless-lan-wlan/213543-configure-eap-tls-flow-with-ise.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/wireless-mobility/wireless-lan-wlan/213543-configure-eap-tls-flow-with-ise.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would recommend building this in a test lab and do all testings.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Dec 2018 02:00:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/cert-for-machine-guest-access/m-p/3757222#M11825</guid>
      <dc:creator>Ambuj M</dc:creator>
      <dc:date>2018-12-04T02:00:55Z</dc:date>
    </item>
    <item>
      <title>Re: cert for machine+ guest access</title>
      <link>https://community.cisco.com/t5/wireless/cert-for-machine-guest-access/m-p/3757224#M11826</link>
      <description>If the devices are internet only, why even bother using certs?&amp;nbsp; Like the other poster mentioned, first you need to verify that the device can have certificates installed and that EQP-TLS is supported.&amp;nbsp; If its Android, it should, but as long as its not locked down.&amp;nbsp; How would you prevent exporting of the cert on the device to another device?&amp;nbsp; Again, you might be complicating things since this is only internet access.&lt;BR /&gt;&lt;BR /&gt; &lt;BR /&gt;</description>
      <pubDate>Tue, 04 Dec 2018 02:03:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/cert-for-machine-guest-access/m-p/3757224#M11826</guid>
      <dc:creator>Scott Fella</dc:creator>
      <dc:date>2018-12-04T02:03:52Z</dc:date>
    </item>
  </channel>
</rss>

