04-23-2024 10:22 PM
We have a chicken & egg situation where ISE requires a user's login and the presence of a user cert from AD before the user can be permitted to connect to the corporate wifi. But the user needs to connect to wifi to get the cert.
One solution i have read is to have a 2 phase login. A user with just an AD machine member cert will fail the standard login. ISE can then drop through to a secondary auth which requires user/pass & machine cert. When this is successful, user is dropped into a staging vlan on their switch+AP. The staging vlan only allows connection to what is needed to load the required cert. Group policy and login scripts will recognise the presence of the staging vlan, load the client with the needed cert, and then reboot the client.
I'm using ISE v3.2 and a 9800 vWLC. Assuming flexconnect mode for APs with local switching at the AP end, i cant see how to get an AP+SSID to drop a single client into different vlans depending on auth results. Is there a guide available for this kind of thing?
04-23-2024 10:31 PM
>....load the client with the needed cert, and then reboot the client.
- Hmm, normally in 'standard company environments' the needed machine cert(s) are part of the standard installation , done by company IT dept when providing a windows PC to the end user (e.g.)
M.
04-23-2024 11:16 PM
Indeed the machine cert is available. However the customer is requiring that an individual user cert be present before a client can be permitted to connect to the corporate wifi proper.
04-23-2024 11:43 PM
- A big part of it is also an ISE procedure , I would therefore advise to post the question also in :
https://community.cisco.com/t5/network-access-control/bd-p/discussions-network-access-control
M.
04-24-2024 06:38 AM
> i cant see how to get an AP+SSID to drop a single client into different vlans depending on auth results
Use VLAN Override: https://www.cisco.com/c/en/us/support/docs/wireless-mobility/wlan-security/217043-configure-dynamic-vlan-assignment-with-c.html
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide