11-19-2024 10:08 AM
Hi
We want use ISE for our mobie phones using Cerificate authentication (no portal ) can we just get generate a CSR on ISE get it signed and then use in rules to authenticate phones, obviously the phones will have a cert signed by the same CA.?
Is there a link to a good document at all
Thanks
11-19-2024 10:18 AM - edited 11-19-2024 10:20 AM
@benolyndav the best way to dsitribute certificates to mobile devices is using MDM, however if you do not have an MDM you can use the ISE certificate provisioning portal - https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/200534-ISE-2-0-Certificate-Provisioning-Portal.html or BYOD portal https://community.cisco.com/t5/security-knowledge-base/cisco-ise-byod-prescriptive-deployment-guide/ta-p/3641867
11-19-2024 12:10 PM
@Rob Ingram We do have an MDM and are hoping to push the cert out via the MDM, I proably didnt explain accuratley, could we use interna;/eternal CA? what certs do i need/use? any links for this please or suggestions.
Thanks
11-19-2024 12:14 PM
@benolyndav if you have an external MDM then that MDM would be integrated into a CA. From ISE perspective, you'd need to trust the CA that issued the certificates to the mobile devices.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide