- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-10-2022 09:41 AM
Hello team,
Can any one help me to setup BYOD using ISE from starting point by point.
Plz if any good documents.
Solved! Go to Solution.
- Labels:
-
ISE
-
Wireless LAN Controller
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-10-2022 11:15 PM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-10-2022 10:01 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-10-2022 10:43 PM
what is the configuration from wlc end.
in this link there is only ise configuration.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-10-2022 11:15 PM
hope this helps.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-10-2022 11:42 PM
can i use foreign and anchor setup on this. ?
i have two wlc one is my primary and second one is my anchor wlc.
can i use this kind of setup if yes then what would be configuration and where need to be done.
mean to say on primary or anchor wlc. ?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-12-2022 12:04 PM - edited 04-12-2022 12:26 PM
I have not done it myself and can't find a document specifically for BYOD in Foreign-Anchor setup.
keep in mind that different people perceive BYOD in different ways, I have seen countless people call guest devices as BYOD (which is not incorrect)
In Cisco's terms, BYOD is when internal users bring their own devices and as organizations want to give flexibility to work and access internal resources on some well provisioned personal devices, that's why it involves certificate provisioning for these devices via ISE and integration with some form of MDM to ensure device check.
Guest is a different case and it makes sense to tunnel all traffic to Anchor in DMZ, because you don't want guest devices to access anything internal, not even DHCP or DNS, once tunnel to DMZ, traffic can not come back in to inside (low to high) unless allowed explicitly and can only go out to internet (high to low).
So its important to know if you are planning to deploy BYOD or Guest with Anchor setup in DMZ.
if you are trying to do guest here is a link.
if you still plan to do BYOD with anchor setup, you can try the flow logic is still same. I haven't tried it myself yet.
hope this helps.
