12-13-2018 10:32 AM
Hello all,
Troy here and I am new to this. Please excuse some of my grammatical errors. I am one of the system admin in a school district with over 15000 students and employees. We have Cisco ISE ver 2.3 and have policies in place for each group per ssid. Our ISE is also joined to AD and our users are able to authenticate through ISE to access the network, however, we want to be able to allow only known devices in AD and allow the users' credentials to access the network via wireless 802.1x. We want to avoid unknown devices from access our network if they are not known in AD. How can we write a policy in ISE to work or will we need to stand up an MDM solution?
Solved! Go to Solution.
12-13-2018 08:20 PM
12-17-2018 08:40 PM
12-13-2018 02:24 PM
12-13-2018 07:29 PM
Hi Francesco,
The known devices are AD Joined and we are 1:1 in the district. We have not created policies for MAB Object in ISE. Our students in middle and high schools connects their personal devices to the network that are not AD Joined. We want prevent their ability to use those devices. What solution do you have and can it be done in ISE?
Thanks,
12-13-2018 08:20 PM
12-14-2018 07:44 AM
Users and machine authenticate based on AD. However our policy is allowing none AD devices to connect even though there is policy set for user and domain computers. We do not have a GPO setup for AD joined computers for WiFi. The information provided below does make sense.
Thanks,
Troy
12-14-2018 09:57 PM
12-17-2018 11:02 AM
12-17-2018 08:40 PM
12-18-2018 06:21 AM
Hi Francesco,
This is correct.
To link a user authentication based on a previous machine authentication, you would need:
- eap chaining
- Cisco ISE MAR (ise caching authentication)
- machine authentication + ise passive-id for user second factor.
There are no other ways to avoid a user to authenticate on the network if not using corporate machine.
Is that clear? The above information you provided is what we want to happen.
Thanks,
Troy
12-18-2018 06:26 AM
Hi Francesco,
With Cisco ISE MAR, will we need the mac address of said devices or could the policy be written to included Ad Joined?
Thanks,
12-19-2018 07:23 PM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide