01-15-2014 04:42 AM - edited 03-10-2019 09:16 PM
Hello
What is the best practice to authenticate a 802.1x printer in Cisco ISE?
The printer can store a certificate for authentication and support EAP-TLS.
Thanks for answer.
Marco
Solved! Go to Solution.
05-12-2014 06:18 AM
Please refer to authentication policies
www.cisco.com/c/en/us/td/docs/security/ise/1-2/user_guide/ise_user_guide/ise_auth_pol.html#pgfId-1146222
05-13-2014 07:04 AM
Hi,
I use certificates (EAP-TLS) to authenticate Sharp printers. It seems to work. I havn't heard anything else from the printer guys.
/Philip
05-12-2014 06:18 AM
Please refer to authentication policies
www.cisco.com/c/en/us/td/docs/security/ise/1-2/user_guide/ise_user_guide/ise_auth_pol.html#pgfId-1146222
05-13-2014 04:07 AM
well use MAB for printers.
05-13-2014 07:04 AM
Hi,
I use certificates (EAP-TLS) to authenticate Sharp printers. It seems to work. I havn't heard anything else from the printer guys.
/Philip
05-28-2014 04:59 AM
ISE Deployment Best Practices
https://www.ciscolive.com/online/connect/sessionDetail.ww?SESSION_ID=4381
05-28-2014 11:45 AM
EAP-TLS is the way to go. It is way way way more secure than MAB and profiling. However, the question is "How much of a hassle is it going to be to put a certificate on each printer?" Moreover, "What methods do I have (if any) to renew those certificates when they expire?" If have to manually generate a CSR and install a cert on each printer then it can quickly become an administrative overhead nightmare. With that being said, you can use MAB and profiling but just make sure that you lock down the access that those printers get. For instance, do they need access to the internet? Do they need access to anything else but the print server and/or open to all IPs access but only on the printing ports.
I hope this puts you in the right direction!
Thank you for rating helpful posts!
06-21-2016 01:19 PM
I agree with Neno, I would suggest MAB with a limited authorization result, only what the printers need to access in the network
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide