07-07-2022 01:30 AM
Hi,
I have cisco ise base license , and one ssid with dot1x authentication.
If anyone use corporate device ,I want put them in vlan 10 if not I want put them guest vlan or just give them internet access
or just give them the privilege's of guest users
Thanks
07-07-2022 03:43 AM
look at the guide below you may help you :
07-07-2022 03:57 AM - edited 07-07-2022 03:58 AM
Hi,
The above is dynamic acl ,this will not help
07-07-2022 04:16 AM
You can achieve that by configuring a specific authorization rule that will match the corp devices traffic, where you will also have an authorization profile associated to that rule which in turn will have the VLAN10 configured. For the devices that won't match the corp rule you can rely on the default authorization rule and associate an authorization profile where you have the guest VLAN defined. Alternatively, you can create a custom rule that would match those personal devices and place them into the guest VLAN, however, this won't be an easy one as you wouldn't know all the device types and attributes of those personal devices to make a 100% match. If you want to be more specific in what to allow and deny for the personal device then you can define an dACL and configure it in the authorization profile that would be then associated to the personal devices authorization rule. Regarding the way to deal with the dACLs in this case it depends on what WLC you have, if you have an old one then the dACL should be created on the WLC and referenced in ISE authorization profile in the airespace ACL name section. However, if you have the 9800 WLC then you can define the ACL on ISE itself in the same way you do this for the switches.
07-08-2022 03:15 PM
"Corporate Device" implies the use of a digital certificate for authentication to identify it as a managed endpoint.
Are your corporate endpoints provisioned with wired or wireless network profiles to use a digital certificate for authentication with 802.1X or a specific SSID?
If not, you will need an MDM or other computer management tool to configure it (SCCM, etc).
You may configure the Guest VLAN as the default VLAN on a switch. See ISE Secure Wired Access Prescriptive Deployment Guide .
For wireless, you should be using a totally separate Guest SSID to clearly indicate guest services. See ISE Guest Access Prescriptive Deployment Guide .
07-15-2022 03:13 AM
Hi,
You mean to use EAP-TLS (certificate based authentication ) for corporate devices ,In that case how to do byod devices ?
Thanks
07-15-2022 07:12 AM
MDM >>>> BYOD
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide