04-12-2024 07:59 AM
So I'd like to use ISE to authenticate then authorise a device based on an external CA presented during 802.1x. I'd also like ISE to use an OCSP check for the validity of this cert.
What are the steps to get this to work? Do i need to import the root ca into ISE? How do i configure ISE to use OCSP?
What would the authentication match statement look like?
04-12-2024 08:10 AM
@netops4 you import the root certificate to ISE "trusted certificates" under that certificate you configure certificate status validation to use OCSP.
For AuthC match you can match on EAP-TLS, for AuthZ you can match on an attribute from the certificate (certificate template, issuer etc).
If you want to perform a lookup against AD you can also use a Certificate Authentication Profile (CAP).
04-17-2024 07:22 AM
If its a distributed deployment of ISE. Is it just a case of literally importing the root ca to the Primary Admin node? Or do i need to do somehow get the cert onto all the PSNs too?
04-17-2024 07:56 AM
You just need to do that on the PAN.
04-12-2024 08:14 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide