cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
266
Views
0
Helpful
2
Replies

Exposing the BYOD Portal to users from home

An interesting scenario has been posed my way, I am hopeful that I can get some insight from the community. 

We are currently investigating the use of ISE 1.3 or 1.4 to deploy certificates to end-user devices utilizing the BYOD Portals and supplicant provisioning. Unfortunately the requirements shifted recently and we have been asked to provide certificate deployment off network and without the use of VPN. 

Is it possible to expose the supplicant provisioning portals outside of a cisco ISE environment ?

Is there a way to get the endpoints MAC address to the ISE portal from the outside world ?

Thanks

2 Replies 2

nspasov
Cisco Employee
Cisco Employee

I don't think this is possible. You need a supported NAD (Network Access Device) which in Radius acts as the "authenticator" for the on-boarding/provisioning process to work. 

This sounds like a good fit for an MDM solution. You can integrate the MDM with your PKI and AD architectures and provide a URL where users can go, authenticate and get provisioned with certificates. Then once they are on site they can properly authenticate through ISE.

 

Thank you for rating helpful posts!

Venkatesh Attuluri
Cisco Employee
Cisco Employee

no its not possible to get supplicant provisioning portals outside of a cisco ISE environment