11-26-2017 01:44 AM
Hi All,
We have a customer requirement where they have VDI as well as laptop users who connect to random ports. Please advise what is the best way to securely deploy ISE in such an environment. I was thinking of having MAB for VDI and dot1X for laptop users and Also was wondering if we can have easyconnect for vdi and dot1x for laptop users. please advise.
Solved! Go to Solution.
11-26-2017 05:12 AM
Hi Arun,
I dont think there is really a straight answer here as different types of methods can be used , however keep in mind easyconnect relies on kerebos authentications.
An example for MAB would be to Whitelist or Blacklist based on Profiles.
Dot1x needs a bit more "fine tuning" if Certs are being used and Network Device configurations , but is considered one of the most secured methods.
If your laptops are windows based then easyconnect could be a more simpler solution .
Thanks,
Danny
11-26-2017 05:12 AM
Hi Arun,
I dont think there is really a straight answer here as different types of methods can be used , however keep in mind easyconnect relies on kerebos authentications.
An example for MAB would be to Whitelist or Blacklist based on Profiles.
Dot1x needs a bit more "fine tuning" if Certs are being used and Network Device configurations , but is considered one of the most secured methods.
If your laptops are windows based then easyconnect could be a more simpler solution .
Thanks,
Danny
11-27-2017 08:50 PM
Thanks Danny for your response! will try your suggestions. Was wondering if you have any use case for VDI thin client users.
11-27-2017 04:30 AM
This should work fine
I’m not quite sure how your VDI use case will work, if the vdi client machine doesn’t support Dot1x but it does login to the domain so that IP address of local client is mapped to a domain user then that might work as well
Please lab it up
11-28-2017 08:25 AM
Sure Jason! Will lab it up.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide