cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
606
Views
0
Helpful
3
Replies

BYOD without ISE?

EvaldasOu
Level 4
Level 4

Hi guys,

Can you suggest any other products/solutions if ISE is just too much expensive or just does not scale?

For example if we have 5-10 APs and we want to use BYOD services, use secure EAP-TLS tunnel on our WiFi network. How to get yours iPad secure?

1 Accepted Solution

Accepted Solutions

Scott Fella
Hall of Fame
Hall of Fame

Just use radius... You can use either Microsoft Radius or even ACS to do EAP-TLS or any EAP type security. I use PEAP because I don't want to install a cert on my iPad:). Radius would tie into AD and you can set your policies there. You will not have any profiling, so radius will not know what device is what. That is what ISE does.

Sent from Cisco Technical Support iPhone App

-Scott
*** Please rate helpful posts ***

View solution in original post

3 Replies 3

Scott Fella
Hall of Fame
Hall of Fame

Just use radius... You can use either Microsoft Radius or even ACS to do EAP-TLS or any EAP type security. I use PEAP because I don't want to install a cert on my iPad:). Radius would tie into AD and you can set your policies there. You will not have any profiling, so radius will not know what device is what. That is what ISE does.

Sent from Cisco Technical Support iPhone App

-Scott
*** Please rate helpful posts ***

Thank you Scott! As always!

No problem... If you are a Microsoft shop it would be cheaper to just bring up a new Microsoft radius server or add the IAS/NPS role to an existing server.

Sent from Cisco Technical Support iPhone App

-Scott
*** Please rate helpful posts ***
Review Cisco Networking for a $25 gift card