cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1163
Views
2
Helpful
4
Replies

user auth without user cert?

jmcgrady1
Level 4
Level 4

We have a chicken & egg situation where ISE requires a user's login and the presence of a user cert from AD before the user can be permitted to connect to the corporate wifi. But the user needs to connect to wifi to get the cert.

One solution i have read is to have a 2 phase login. A user with just an AD machine member cert will fail the standard login. ISE can then drop through to a secondary auth which requires user/pass & machine cert. When this is successful, user is dropped into a staging vlan on their switch+AP. The staging vlan only allows connection to what is needed to load the required cert.  Group policy and login scripts will recognise the presence of the staging vlan, load the client with the needed cert, and then reboot the client.

I'm using ISE v3.2 and a 9800 vWLC.  Assuming flexconnect mode for APs with local switching at the AP end, i cant see how to get an AP+SSID to drop a single client into different vlans depending on auth results.  Is there a guide available for this kind of thing?

4 Replies 4

Mark Elsen
Hall of Fame
Hall of Fame

 

             >....load the client with the needed cert, and then reboot the client.
  - Hmm, normally in 'standard company environments' the needed machine cert(s) are part of the standard installation , done by company IT dept when providing a windows PC  to the end user (e.g.) 

 M.



-- Let everything happen to you  
       Beauty and terror
      Just keep going    
       No feeling is final
Reiner Maria Rilke (1899)

Indeed the machine cert is available. However the customer is requiring that an individual user cert be present before a client can be permitted to connect to the corporate wifi proper. 

 

 - A big part of it is also an ISE procedure , I would therefore advise to post the question also in :
                             https://community.cisco.com/t5/network-access-control/bd-p/discussions-network-access-control

 M.



-- Let everything happen to you  
       Beauty and terror
      Just keep going    
       No feeling is final
Reiner Maria Rilke (1899)

Rich R
VIP
VIP

i cant see how to get an AP+SSID to drop a single client into different vlans depending on auth results

Use VLAN Override: https://www.cisco.com/c/en/us/support/docs/wireless-mobility/wlan-security/217043-configure-dynamic-vlan-assignment-with-c.html

------------------------------
Please click Helpful if this post helped you and Accept as Solution (drop down menu at top right of this reply) if this answered your query.
------------------------------
TAC recommended codes for AireOS WLC's   and   TAC recommended codes for 9800 WLC's
Best Practices for AireOS WLC's,   Best Practices for 9800 WLC's   and   Cisco Wireless compatibility matrix
Check your 9800 WLC config with Wireless Config Analyzer using "show tech wireless" output or "config paging disable" then "show run-config" output on AireOS and use Wireless Debug Analyzer to analyze your WLC client debugs
Field Notice: FN63942 APs and WLCs Fail to Create CAPWAP Connections Due to Certificate Expiration
Field Notice: FN72424 Later Versions of WiFi 6 APs Fail to Join WLC - Software Upgrade Required
Field Notice: FN72524 IOS APs stuck in downloading state after 4 Dec 2022 due to Certificate Expired
- Fixed in 8.10.196.0, latest 9800 releases, 8.5.182.12 (8.5.182.13 for 3504) and 8.5.182.109 (IRCM, 8.5.182.111 for 3504)
Field Notice: FN70479 AP Fails to Join or Joins with 1 Radio due to Country Mismatch, RMA needed
Field Notice: FN74383 APs Running 17.12.4/5/6/6a May Run Out of Flash Space Preventing Upgrades
How to avoid boot loop due to corrupted image on Wave 2 and Catalyst 11ax Access Points (CSCvx32806)
Field Notice: FN74035 - Wave2 APs DFS May Not Detect Radar After Channel Availability Check Time
Leo's list of bugs affecting 2800/3800/4800/1560 APs
Default AP console baud rate from 17.12.x is 115200 - introduced by CSCwe88390
Review Cisco Networking for a $25 gift card