10-26-2021 11:42 AM
Hey there,
I am looking to get devices that don't support 802.1x online preferably by using something like MAC filtering without adding another WLAN. We currently have a 802.1x network where a radius server is providing the authorization.
For IOT devices and other things, we use a vlan overwright to put these devices on the vlan we want for isolation. This works great for devices that support 802.1x.
What is the best way to do this for devices that don't support 802.1x??
We are running 5520 WLC's802.1x, WLC, IOT, Wireless LAN Controller, Wireless Security
Thank you,
A
10-26-2021 12:33 PM
If you can not do 802.1x supplicant, either you isolate them to a different VLAN or do MAB Authentication only option you have.
10-26-2021 12:47 PM
I would say to get the best level of security I would suggest combine MAB+iPSK. You can have Dynamic VLAN assignment based on the PSK. If your Radius server allows you to profile and do posture, then you can look at adding tht option as well.
10-26-2021 09:22 PM
My opinion is you create a new ssid and don’t try to get a workaround on your dot1x as you will creating an opening for access which security folks would flag. Like what Arshad mentioned, look at ipsk if you want to have multiple psk’s or simplify it and create an ssid with a psk.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide