cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
625
Views
0
Helpful
2
Replies

Wired dot1x for apple devices

ffadhilpi
Level 1
Level 1

Hi Forum,

I'm trying to help a customer with locking the wired ports to only company asset macbooks. For wireless JAMF is taking care of that for me by checking mdm>>deviceRegisteredStatus=registered but for wired, JAMF does not have the mac address of the dongle (that changes every time you get new dongle).

Authentication with a cert is not an option here. What's another way to identify corp assets on the wired for Macs??

1 Accepted Solution

Accepted Solutions

Craig Hyps
Level 10
Level 10

See Trusted Device + Trusted User section of the following Cisco Live session (BRKSEC-3697 - 2017 Melbourne).

Advanced ISE Services, Tips and Tricks (2017 Melbourne)

The reference version of presentation provided additional details.

Access to CiscoLive.com requires one-time registration (no charge).

/Craig

View solution in original post

2 Replies 2

Craig Hyps
Level 10
Level 10

See Trusted Device + Trusted User section of the following Cisco Live session (BRKSEC-3697 - 2017 Melbourne).

Advanced ISE Services, Tips and Tricks (2017 Melbourne)

The reference version of presentation provided additional details.

Access to CiscoLive.com requires one-time registration (no charge).

/Craig

paul
Level 10
Level 10

If you are using JAMF then join the Macs to AD and then have JAMF configure the MACs to present AD computer credentials just like you do on a Windows device.  No need to even to JAMF MDM integration.