07-15-2022 03:24 AM
Hi,
I have the following coprporate clients , windows and ios ,I want to avoid mschap v2 , what is the alternative
and byod clients are windows ios and android
Thanks
Solved! Go to Solution.
07-16-2022 08:59 AM
@bluesea2010 yes the users could just enter their username/password (mschapv2) but that's considered insecure.
For a BYOD environment you can onboard the end users personal endpoints via the ISE BYOD portal and provision a CA signed endpoint certificate as well as configure the network interface and OS native supplicant to utilise this certificate for network access. This functionality requires an ISE Plus license.
07-15-2022 03:33 AM
@bluesea2010 for corporate devices use certificates (EAP-TLS) issued by an internal Cetificate Authority via Group Policies.
For BYOD devices usually you'd use the ISE internal CA.
07-15-2022 03:47 AM
Hi,
So the alternative of mschapv2 is only eap-tls
If I use ise internal ca for byod , how I can i deploy these certificate in BYOD devices
Thanks
07-15-2022 04:12 AM
@bluesea2010 you can use the BYOD portal to enroll for certificates on the BYOD devices. https://community.cisco.com/t5/security-knowledge-base/cisco-ise-byod-prescriptive-deployment-guide/ta-p/3641867#toc-hId-694972267
07-15-2022 08:19 AM
07-15-2022 08:55 AM - edited 07-15-2022 09:00 AM
Hi @bluesea2010 you would need Plus licensing if you use BYOD.
Profiling is not a requirement for BYOD or using certificates for 802.1x authentication if that was your question.
07-15-2022 09:30 AM
Hi,
I could see that BYOD need plus licensing , but in my case I have only base license .
In that case what will I miss in terms of BYOD . (Currently non corporate devices are connecting to the corporate wifi , Can I call this as byod ? )
Thanks
07-15-2022 09:48 AM
Yes, this is precisely the use-case for BYOD.
07-15-2022 10:13 AM
Hi ,
My question why byod need plus licensing , I have only base license but still I am allowing non corporate device. I mean still users can connect their personal devices using dot1x (peap mschapv2)
Thanks
07-15-2022 10:47 AM - edited 07-15-2022 10:47 AM
If you want to use BYOD, ISE requires Plus/Advantage licensing per endpoint.
07-15-2022 09:36 PM
Hi @ahollifield
Sorry I could not make clear my question , sorry for my english . , I don't have plus licenses but still users can connect to the wifi using dot1x peap mschapv2 . Since users can connect their personal devices using base license , why do we need plus license
Thanks
07-16-2022 08:59 AM
@bluesea2010 yes the users could just enter their username/password (mschapv2) but that's considered insecure.
For a BYOD environment you can onboard the end users personal endpoints via the ISE BYOD portal and provision a CA signed endpoint certificate as well as configure the network interface and OS native supplicant to utilise this certificate for network access. This functionality requires an ISE Plus license.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide