cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements
The ISE 2.5 Beta software is now available! Join the ISE Beta Community to try it in your lab!
115
Views
0
Helpful
1
Replies
Highlighted
Explorer

ISE internal CA for VPN Clients

We have around 1500 vpn clients and would like to utilize the internal CA on ISE to issue/revoke certificates.  Is this a supported deployment?  We have different authentication methods for specific vpn users (AD/RSA) and utilize a certificate map to trigger the tunnel group and ISE authentication policies to match.  We would like to be able utilize scep from the ASA to ISE to issue specific client certs.  We have this working but don't want to deploy if using the internal ISE CA in this fashion is not advise/supported.

 

Thanks,

 

Joe

1 REPLY
RJI Collaborator
Collaborator

Re: ISE internal CA for VPN Clients

Hi there,

I tested this exact scenario a couple of years ago, from memory I did get this working, but did not go ahead with it in production. The ISE CA is featureless and the ISE Certificates are just intended for BYOD scenarios, so I personally wouldn't use it for what you want to use it for.

 

If possible I'd go for a Microsoft CA, use NDES role as the SCEP server and this will give you everything you want.

HTH

CreatePlease to create content
Ask the Expert- DMVPN on Cisco routers