cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
799
Views
1
Helpful
4
Replies

Off-Prem Onboarding without an MDM

pethomas
Cisco Employee
Cisco Employee

Hi Guys

Is there a work flow available to onboard a device remotely? 

The context is a school district would like to remotely onboard student devices before the beginning of a new school year.  They currently do not have an MDM.  The students will already have a AD account at the school.

Thanks

Peter

1 Accepted Solution

Accepted Solutions

Jason Kunst
Cisco Employee
Cisco Employee

Windows, MacOS, and Android (when Android user connected to VPN over local

WiFI) should work for BYOD using AC with ACIDEX support starting in ASA 9.2..1

and AC 3.1MR5.

It required the Anyconnect to pass along the internal MAC address (not the VPN tunnel).

View solution in original post

4 Replies 4

Jason Kunst
Cisco Employee
Cisco Employee

Windows, MacOS, and Android (when Android user connected to VPN over local

WiFI) should work for BYOD using AC with ACIDEX support starting in ASA 9.2..1

and AC 3.1MR5.

It required the Anyconnect to pass along the internal MAC address (not the VPN tunnel).

Thanks Jason - just so I get this right - is this correct?

1: The school could publish an AnyConnect installer on a public site

2: The student then install AnyConnect and then Authenticate to the ASA using AD credentials

3: Assuming split tunneling is disallowed, ISE/ASA will initiate the onboarding (Certs and SPW) process (using the wireless Mac address that has been passed down using ACIDEX)

Thanks

Peter

the 1st step is not required as the Asa hosts anyconnect already

they would simply need to web to the asa to start a connection and then download the package via that site

once package downloaded they would initiate VPN connection

once vpn established they could require (through redirect) that the device goes through byod flow

Thanks Jason

cheers

Peter