11-09-2017 02:37 AM - edited 02-21-2020 10:38 AM
Morning,
I'm trying to use ISE's internal CA with SCEP to issue unique Certificates to some iPads so we can do EAP-TLS on the Wireless.
We're pushing the SCEP config to the client via a separate MDM platform, we can see the client hitting the SCEP URL on ISE (via TCPDump), but it never gets a Cert and there's very little (ie, nothing!) in the logs to help troubleshoot. Logging in the ISE seems minimal (any clues on what logs to look at?) and the ISE config guides for this kind of thing are all old and reference external CAs only.
When I put the SCEP URL the client is trying to access in my browser, it returns this;
SCEP URL: http://ISE-FQDN:9090/auth/caservice/pkiclient.exe?operation=GetCACert&message=ISE-Hostname
Error: "Block scep enrollment as the traffic does not come from network device
Any tips please?!
Cheers,
Richard
09-23-2020 02:55 AM
Hello Richard, I know it's some time ago but I had the same issue.
You get the "Block scep enrollment as the traffic does not come from network device" if the device ip is not known in the network devices list.
Just add the ip of the device or MDM in Administration -> Network Resources -> Network devices.
08-27-2021 09:53 AM
Hi
I was wondering if you ever got this working without the MDM... I am trying to simply do a SCEP enrolment into ISE with the internal CA (my lab runs all personas) but am having issues wondering what a potential enrollment password could be. I know no way of configuring these settings within ISE.
Can you please assist with some guidance on where I could start looking? Recommend any good resources to consult.
Thanks,
Chris
08-28-2021 06:59 AM
08-30-2021 09:26 AM
Thanks Mohammed,
But I am using the internal ISE CA and not an external MS.
I have this post opened to explain my situation...
My endpoints are not MS clients but Dell ThinOS - and I don't have an MDM but the Wyse Management Suite (WMS). I'm trying to request a certificate from ISE PSN but unsure its properly configured to permit it... As I don't see any RA type certificate in my trusted store on ISE.
I do have the ip address of my endpoint defined in the network devices page - but unsure how I will be able to deploy long term with this requirement as I am trying to setup some automation with SCEP to hundreds of Dell endpoints.
Thanks,
Chris
08-27-2021 09:55 AM
Hi Richard,
You posted this awhile ago...
I'm trying somewhat do the same using Dell Wyse Thin Client endpoints... but no MDM involved. I added its IP to the network devices and it did allow me further but I don't know how the set the variables the "Registration Authority" needs to properly enrol into the ISE Internal-CA. Did you get something working?
Thanks,
Chris
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide