10-02-2018 01:16 AM
Dears,
My Customer is seeking to enable Dot1x on Managed and Unmanaged devices (Windows and MAC OSX).In order to provide a secure access to Customer network, Supplicants should be provisioned to endpoints to support dot1x settings prior to implementation, However pushing these agents from ISE may fails as user should have administrative privilege.
Table 44: Supplicant – Supplicant Types TBD
|
Devices Type |
OS |
Authentication Supplicant |
Posture Agent |
||
|
|
|
Supplicant |
Deployment |
Agent |
Deployment |
|
Managed Devices for Employee |
Windows |
AnyConnect Network Access Manager |
GPO |
ISE-Posture Agent |
GPO |
|
MAC OS |
MAC OS Native Supplicant |
GPO |
ISE-Posture Agent |
GPO |
|
|
Unmanaged Devices for Employee/Non-Employee |
Windows |
Windows Native Supplicant |
Manual |
ISE Temporal Agent |
Manual |
|
MAC OS |
MAC OS Native Supplicant |
Manual |
ISE Temporal Agent |
Manual |
|
So what I am asking for are
Thanks again for your time and hope get your response ASAP.
10-02-2018 08:08 AM
How does the customer expect to deploy macOS supplicants via GPO? I assume this really means MDM policy (such as jamf (formerly Casper suite)?
There are a slew of documents that exist (and books, in fact) on this topic. https://community.cisco.com/t5/security-documents/identity-services-engine-ise-community-resources/ta-p/3621621#Resources for starters.
Aaron
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide