08-02-2021 04:32 AM
What is the best method for deploying EAP certificates within a multi-node deployment where users will roam between sites? Each site has an ISE PSN and the Admin and MGMT nodes are in a DC.
The root CA of the certs that are presented to clients during authentication are pushed to the device VIA the MDM solution. If each node is signed individually by the same CA, will the users be able to roam without having to accept another certificate for EAP or is it best to use a multi-node cert with each Node listed as a SAN in the same CSR?
Thanks
Jon
Solved! Go to Solution.
08-06-2021 07:14 PM
You have ensured that the root CA cert for the ISE deployment is on each endpoint so they will trust any of the ISE nodes so that is fantastic. This will work regardless of how you do choose to implement you ISE certs - individual ISE node name per cert or a wildcard cert for the entire deployment.
08-02-2021 04:48 AM
Same Cert should work for your Roaming solution you looking to deploy.
08-02-2021 05:14 AM
Hi balaji.bandi
Thanks for the quick reply, when you say 'same cert'. Do you mean a single cert with each node list as a SAN or each node can have individual certs that are signed by the same CA?
Cheers,
Jon
08-06-2021 07:14 PM
You have ensured that the root CA cert for the ISE deployment is on each endpoint so they will trust any of the ISE nodes so that is fantastic. This will work regardless of how you do choose to implement you ISE certs - individual ISE node name per cert or a wildcard cert for the entire deployment.
08-07-2021 10:24 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide