cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
528
Views
0
Helpful
2
Replies

How do I require client and machine Cert when using EAP-TLS on wireless?

paulle
Cisco Employee
Cisco Employee

I have the same policy in ISE being used for both wired and wireless authorization. In the wired auths I see both user and computer certificates but on the wireless side I only ever see computer certs being used. How do I change this behavior so that it matches the wired ?

1 Accepted Solution

Accepted Solutions

Colby LeMaire
VIP Alumni
VIP Alumni

If the computers are only sending computer certificates on Wireless, that is a supplicant configuration issue.  You can create a Wireless GPO to push out the correct supplicant settings.  If using the built-in Microsoft supplicant, there is an option to do "Machine or User Authentication".  It is probably configured to do "Machine Authentication Only".  

View solution in original post

2 Replies 2

Colby LeMaire
VIP Alumni
VIP Alumni

If the computers are only sending computer certificates on Wireless, that is a supplicant configuration issue.  You can create a Wireless GPO to push out the correct supplicant settings.  If using the built-in Microsoft supplicant, there is an option to do "Machine or User Authentication".  It is probably configured to do "Machine Authentication Only".  

hslai
Cisco Employee
Cisco Employee

Like Colby.LeMaire said, this depends on the supplicants. Even with Windows native supplicants, the auth mode is configured for individual wireless networks and wired connections.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: