586
Views
0
Helpful
2
Replies

Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-07-2019 01:32 AM - edited 05-07-2019 01:35 AM
Hi Team,
Do we have any guidance or Cisco best practices or Cisco guide about configuring DOt1X on large scale enterprise to configure EAP options on MACOS, customer is asking,
Solved! Go to Solution.
Labels:
- Labels:
-
Identity Services Engine (ISE)
1 Accepted Solution
Accepted Solutions
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-07-2019 09:24 AM
I have been involved in leveraging Airwatch to authenticate iphones and macs at scale. Airwatch is able to provision user certs from AD with scep and push them down along with network connection profiles and trust chain.
I say user certs because at least last year when I was going this, Airwatch was not hostname aware, it only had a user tied to a device. It works very well doing user cert eap-tls this way. One caveat would be on macbooks though, the user had to select which certificate they wanted to authenticate with if there were multiple.
I say user certs because at least last year when I was going this, Airwatch was not hostname aware, it only had a user tied to a device. It works very well doing user cert eap-tls this way. One caveat would be on macbooks though, the user had to select which certificate they wanted to authenticate with if there were multiple.
2 Replies 2
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-07-2019 02:33 AM
Please follow this 802.1X Network Authentication for Mac.
-Aravind
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-07-2019 09:24 AM
I have been involved in leveraging Airwatch to authenticate iphones and macs at scale. Airwatch is able to provision user certs from AD with scep and push them down along with network connection profiles and trust chain.
I say user certs because at least last year when I was going this, Airwatch was not hostname aware, it only had a user tied to a device. It works very well doing user cert eap-tls this way. One caveat would be on macbooks though, the user had to select which certificate they wanted to authenticate with if there were multiple.
I say user certs because at least last year when I was going this, Airwatch was not hostname aware, it only had a user tied to a device. It works very well doing user cert eap-tls this way. One caveat would be on macbooks though, the user had to select which certificate they wanted to authenticate with if there were multiple.
