cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
6902
Views
22
Helpful
17
Replies

Best authentication method for controlling DEVICE access to wlan

Konnan19183
Level 1
Level 1

Hello,

I have a similar question to this thread ( https://supportforums.cisco.com/message/3927713 ) but I'm interested about device control on top of user control. Just like that thread, we are using WPA2-AES Enterprise with PEAP MSCHAPv2, which allow users to log on with their domain credentials. We wanted something simple for our users, so MSCHAPv2 with "single sign on" was optimal to us.

Problem is, we have a new requirement and we need to implement it yesterday. We would like to allow only mobile devices and computers of our choice.

Since we are using MSCHAPv2 which allow every domain user to connect using any device as long as their domain credentials are valid, is there a simple way to control this ?

I guess we could go with MAC filtering, but we have about a thousand laptops. Not a big problem, we could do a regular MAC address inventory using SCCM. It's just that it looks like a brute force tactic to a simple problem. Would a Cisco ACE 4.1 RADIUS server tolerate well a MAC address table with a thousand entries ? What if it goes to two thousands ? Would this be easy to implement ? I'm a bit new to this, is there some documentation I could follow ?

How do people usually do this in an elegant way ? How do you manage and control WLAN access to thousands of device ? I guess they go with TLS with certificates ?

Thank you very much !

Konnan

17 Replies 17

Scott Fella
Hall of Fame
Hall of Fame

I found a thread:)

https://supportforums.cisco.com/thread/2209784

Sent from Cisco Technical Support iPhone App

-Scott
*** Please rate helpful posts ***

Dear Scott,

Thanks for your reply,I check the link that you sent where the ISE version is 1.2, but my ISE version is 2.0.4.018.

So please advise,

Regards,

You might want to post your question on the security forum that handles ISE. I can't help you since I haven't upgraded to 2.0. I don't know if its available or not. They would be able to assist you.

Sent from Cisco Technical Support iPhone App

-Scott
*** Please rate helpful posts ***
Review Cisco Networking for a $25 gift card