10-01-2018 04:10 PM
Hello,
The organization at the moment uses MDM( lightspeed) for pupils and ACS in order to authenticate employees. They use 2 ssid implementation OPEN/WPA PSK. Now we want use MDM either lighspeed or another in order to profile them fra scratch, so they use EAP-TLS with ISE.
I just wonder in terms of authorization policy set in ISE what kind of criteria againts certificate should be used to differenciate pupils and for example apple TV. (For corportate users is easy as they are in AD already)
Should I use separate endpoint groups with corresponding mac addresses and then just allow devices with valid certificates in order to give them different access. What kind of info a certificate should include.
Solved! Go to Solution.
10-02-2018 08:35 AM
10-02-2018 11:30 AM
If you are registering pupils and Apple devices with the MDM you should have total control at the registration process on how certificates get generated and assigned to devices. When a pupil registers their device to the MDM the certificate request to the CA could contain OU=pupil. When an Apple device registers the certificate request could contain OU=Apple Device. Then in your authorization rules you could do subject contains matching to separate the two.
10-10-2018 04:53 AM
10-02-2018 08:35 AM
10-02-2018 11:30 AM
If you are registering pupils and Apple devices with the MDM you should have total control at the registration process on how certificates get generated and assigned to devices. When a pupil registers their device to the MDM the certificate request to the CA could contain OU=pupil. When an Apple device registers the certificate request could contain OU=Apple Device. Then in your authorization rules you could do subject contains matching to separate the two.
10-10-2018 12:41 AM
Hei Paul,
Thanks for the answer. I seems to be obvious with authorization rules but I just wonder how to create the authentication rules in this case ?
I have an 802.1x authentication rule which matches identity store ---- identity store maches ------certificate authentication profile against AD - this rule is for machines which are in AD. There is an option if user not found ---reject.
Since ipads are not in AD how should I create second authentication rule which maches identity store with certificate authentication profile which is not connected to any identiy store. Should I change the first rule from if user not found continue in order to allow it to go to the second one ? Please see the attached pictures
Best regards,
Piotr
10-10-2018 04:53 AM
10-11-2018 11:45 PM
That realy make sens Paul, thanks :) Can you priovide some screenshots from your policysets both authorization and authentication? Br Piotr
10-10-2018 12:43 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide