cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
351
Views
2
Helpful
4
Replies

user auth without user cert?

jmcgrady1
Level 1
Level 1

We have a chicken & egg situation where ISE requires a user's login and the presence of a user cert from AD before the user can be permitted to connect to the corporate wifi. But the user needs to connect to wifi to get the cert.

One solution i have read is to have a 2 phase login. A user with just an AD machine member cert will fail the standard login. ISE can then drop through to a secondary auth which requires user/pass & machine cert. When this is successful, user is dropped into a staging vlan on their switch+AP. The staging vlan only allows connection to what is needed to load the required cert.  Group policy and login scripts will recognise the presence of the staging vlan, load the client with the needed cert, and then reboot the client.

I'm using ISE v3.2 and a 9800 vWLC.  Assuming flexconnect mode for APs with local switching at the AP end, i cant see how to get an AP+SSID to drop a single client into different vlans depending on auth results.  Is there a guide available for this kind of thing?

4 Replies 4

marce1000
VIP
VIP

 

             >....load the client with the needed cert, and then reboot the client.
  - Hmm, normally in 'standard company environments' the needed machine cert(s) are part of the standard installation , done by company IT dept when providing a windows PC  to the end user (e.g.) 

 M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

Indeed the machine cert is available. However the customer is requiring that an individual user cert be present before a client can be permitted to connect to the corporate wifi proper. 

 

 - A big part of it is also an ISE procedure , I would therefore advise to post the question also in :
                             https://community.cisco.com/t5/network-access-control/bd-p/discussions-network-access-control

 M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

Rich R
VIP
VIP

i cant see how to get an AP+SSID to drop a single client into different vlans depending on auth results

Use VLAN Override: https://www.cisco.com/c/en/us/support/docs/wireless-mobility/wlan-security/217043-configure-dynamic-vlan-assignment-with-c.html

Review Cisco Networking for a $25 gift card