<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Connection for corporate ssid for non domain devices in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/connection-for-corporate-ssid-for-non-domain-devices/m-p/4575974#M239889</link>
    <description>&lt;P&gt;how we can add an exception to ISE when a tablet(not domain joined) could access corporate WIFI? Using eap peap.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is very urgent for me if anyone can send me setup&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 22 Mar 2022 12:39:55 GMT</pubDate>
    <dc:creator>jain.manish94</dc:creator>
    <dc:date>2022-03-22T12:39:55Z</dc:date>
    <item>
      <title>Connection for corporate ssid for non domain devices</title>
      <link>https://community.cisco.com/t5/wireless/connection-for-corporate-ssid-for-non-domain-devices/m-p/4575974#M239889</link>
      <description>&lt;P&gt;how we can add an exception to ISE when a tablet(not domain joined) could access corporate WIFI? Using eap peap.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is very urgent for me if anyone can send me setup&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Mar 2022 12:39:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/connection-for-corporate-ssid-for-non-domain-devices/m-p/4575974#M239889</guid>
      <dc:creator>jain.manish94</dc:creator>
      <dc:date>2022-03-22T12:39:55Z</dc:date>
    </item>
    <item>
      <title>Re: Connection for corporate ssid for non domain devices</title>
      <link>https://community.cisco.com/t5/wireless/connection-for-corporate-ssid-for-non-domain-devices/m-p/4576079#M239891</link>
      <description>&lt;P&gt;how is your authentication, in this case you need to do MAB Authentication.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Mar 2022 14:30:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/connection-for-corporate-ssid-for-non-domain-devices/m-p/4576079#M239891</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2022-03-22T14:30:28Z</dc:date>
    </item>
    <item>
      <title>Re: Connection for corporate ssid for non domain devices</title>
      <link>https://community.cisco.com/t5/wireless/connection-for-corporate-ssid-for-non-domain-devices/m-p/4576085#M239892</link>
      <description>&lt;P&gt;Plz tell me anyone which i can implement easily&lt;/P&gt;</description>
      <pubDate>Tue, 22 Mar 2022 14:33:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/connection-for-corporate-ssid-for-non-domain-devices/m-p/4576085#M239892</guid>
      <dc:creator>jain.manish94</dc:creator>
      <dc:date>2022-03-22T14:33:38Z</dc:date>
    </item>
    <item>
      <title>Re: Connection for corporate ssid for non domain devices</title>
      <link>https://community.cisco.com/t5/wireless/connection-for-corporate-ssid-for-non-domain-devices/m-p/4576101#M239893</link>
      <description>&lt;P&gt;We want to use Samsung tablet, iPhone, TV with that corporate SSID plz suggest any good configuration. I heard about BYOD but don know the concept.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can we this this BYOD for all non domain devices ?&lt;/P&gt;</description>
      <pubDate>Tue, 22 Mar 2022 14:48:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/connection-for-corporate-ssid-for-non-domain-devices/m-p/4576101#M239893</guid>
      <dc:creator>jain.manish94</dc:creator>
      <dc:date>2022-03-22T14:48:34Z</dc:date>
    </item>
    <item>
      <title>Re: Connection for corporate ssid for non domain devices</title>
      <link>https://community.cisco.com/t5/wireless/connection-for-corporate-ssid-for-non-domain-devices/m-p/4576123#M239897</link>
      <description>&lt;P&gt;not sure what WLC and what Radius you using : here is latest Cat9800 controller config :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/config-guide/b_wl_16_10_cg/mac-authentication-bypass.html" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/213922-configure-mac-authentication-ssid-on-cis.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you looking webauth :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/115732-central-web-auth-00.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/115732-central-web-auth-00.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Mar 2022 15:11:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/connection-for-corporate-ssid-for-non-domain-devices/m-p/4576123#M239897</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2022-03-22T15:11:43Z</dc:date>
    </item>
    <item>
      <title>Re: Connection for corporate ssid for non domain devices</title>
      <link>https://community.cisco.com/t5/wireless/connection-for-corporate-ssid-for-non-domain-devices/m-p/4576126#M239898</link>
      <description>&lt;P&gt;If I talk about wlc using legacy devices 4400 wlc with 7.2 or 7.0 version.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Radius i am using Cisco ise with 3.0 version.&lt;/P&gt;&lt;P&gt;Now plz let me know what options are available to complete the setup&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Mar 2022 15:14:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/connection-for-corporate-ssid-for-non-domain-devices/m-p/4576126#M239898</guid>
      <dc:creator>jain.manish94</dc:creator>
      <dc:date>2022-03-22T15:14:21Z</dc:date>
    </item>
    <item>
      <title>Re: Connection for corporate ssid for non domain devices</title>
      <link>https://community.cisco.com/t5/wireless/connection-for-corporate-ssid-for-non-domain-devices/m-p/4576159#M239901</link>
      <description>&lt;P&gt;7.2 is too old for me, but the above mentioned URL still valid for you to deploy and test it.&lt;/P&gt;
&lt;P&gt;(if you are not sure, then we suggest to hire a consultant who can integrate for you)&lt;/P&gt;</description>
      <pubDate>Tue, 22 Mar 2022 15:57:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/connection-for-corporate-ssid-for-non-domain-devices/m-p/4576159#M239901</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2022-03-22T15:57:56Z</dc:date>
    </item>
    <item>
      <title>Re: Connection for corporate ssid for non domain devices</title>
      <link>https://community.cisco.com/t5/wireless/connection-for-corporate-ssid-for-non-domain-devices/m-p/4576883#M239922</link>
      <description>&lt;P&gt;My corporate laptop is using one corporate SSID. Using eap peap&lt;/P&gt;&lt;P&gt;Can I make any policy over Cisco ise to allow some non domain device mac address who want to connect our this corporate SSID?&lt;/P&gt;&lt;P&gt;Any other option plz let me know.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Mar 2022 09:41:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/connection-for-corporate-ssid-for-non-domain-devices/m-p/4576883#M239922</guid>
      <dc:creator>jain.manish94</dc:creator>
      <dc:date>2022-03-23T09:41:37Z</dc:date>
    </item>
    <item>
      <title>Corp SSID for domain joined devices and for non domain devices both</title>
      <link>https://community.cisco.com/t5/wireless/connection-for-corporate-ssid-for-non-domain-devices/m-p/4577861#M240001</link>
      <description>&lt;P&gt;Hello Team,&lt;/P&gt;&lt;P&gt;I am using single said corporate SSID for corporate device which has been joining domain and using eap peap. With same SSID i want to connect some samsung tablet which are not domain joined devices.here i am thinking below steps could you plz help me if i am thinking correct or not.&lt;/P&gt;&lt;P&gt;_---------------------------&lt;/P&gt;&lt;P&gt;if you have a domain joined laptop with AD user.&lt;/P&gt;&lt;P&gt;Laptop tries to join corp SSID.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;WLC send the request to ISE to check&lt;/P&gt;&lt;P&gt;ISE checks that the laptop is domain joined perfect&lt;/P&gt;&lt;P&gt;then ISE checks if the AD user is valid&lt;/P&gt;&lt;P&gt;then ISE authenticate the user and he has access to the internal network + internet&lt;/P&gt;&lt;P&gt;correct?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-------------------------&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;now you have a tablet which is not domain joined but has AD user&lt;/P&gt;&lt;P&gt;tablet tries to join corp SSID&lt;/P&gt;&lt;P&gt;WLC send the request to ISE to check&lt;/P&gt;&lt;P&gt;ISE checks that the laptop is not domain joined and not allow the access to internal network + internet&lt;/P&gt;&lt;P&gt;correct?&lt;/P&gt;&lt;P&gt;-----------------------------------------------------&lt;/P&gt;&lt;P&gt;and now, you add OR Condition to ISE where it checks if the device is domain join&lt;/P&gt;&lt;P&gt;so&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;condition will be:&lt;/P&gt;&lt;P&gt;Is device domain joined or is device mac address from the list?&lt;/P&gt;&lt;P&gt;Yes - allow, no- deny&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ow you have a tablet which is not domain joined but has AD user&lt;/P&gt;&lt;P&gt;tablet tries to join corp SSID&lt;/P&gt;&lt;P&gt;WLC send the request to ISE to check&lt;/P&gt;&lt;P&gt;ISE checks that the tab is not domain joined, but the MAC address is on the list -&amp;gt; allow&lt;/P&gt;&lt;P&gt;then ISE checks if the AD user is valid&lt;/P&gt;&lt;P&gt;then ISE authenticate the user and he has access to the internal network + internet.&lt;/P&gt;&lt;P&gt;-----------------------------&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-----------------------------------------------------------------&lt;BR /&gt;over the wlc i have configured&amp;nbsp;[WPA2][Auth(802.1X)] for the corp ssid.&lt;/P&gt;&lt;P&gt;----------------------&lt;/P&gt;&lt;P&gt;if my understanding is correct&amp;nbsp;&lt;/P&gt;&lt;P&gt;because here i am using same corp ssid for both devices which are domain joined and some are not domain joined but making some policy over the cisco ISE for mac addressess&lt;/P&gt;</description>
      <pubDate>Thu, 24 Mar 2022 14:18:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/connection-for-corporate-ssid-for-non-domain-devices/m-p/4577861#M240001</guid>
      <dc:creator>jain.manish94</dc:creator>
      <dc:date>2022-03-24T14:18:02Z</dc:date>
    </item>
    <item>
      <title>Re: Corp SSID for domain joined devices and for non domain devices bot</title>
      <link>https://community.cisco.com/t5/wireless/connection-for-corporate-ssid-for-non-domain-devices/m-p/4578189#M240029</link>
      <description>&lt;P&gt;unless you are using AnyConnect or EAP-TEAP your not going to be able to check both machine and user credentials. As you need eap chaining to do two different authentications.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Would suggest:&lt;/P&gt;&lt;P&gt;EAP-TLS (User certificates deployed via Group Policy to laptops) - these get corp access&lt;/P&gt;&lt;P&gt;EAP-PEAP (users with the BYOD user group) get access to BYOD&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You could potentially look at other RADIUS attributes that a corporate device provides and see if one of them is able to be used in the policy, but i havent seen that work well before&lt;/P&gt;</description>
      <pubDate>Thu, 24 Mar 2022 23:53:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/connection-for-corporate-ssid-for-non-domain-devices/m-p/4578189#M240029</guid>
      <dc:creator>Haydn Andrews</dc:creator>
      <dc:date>2022-03-24T23:53:22Z</dc:date>
    </item>
  </channel>
</rss>

