08-24-2026 12:00 AM
Hi
We have a Cisco 9800/Cisco Lightweight network. The main wireless profile is used by devices that are a mixed of managed (Intune) and BYOD and runs 802.1x EAP-PEAP using Cisco ISE 3.3 for AAA services. I have been asked to roll out EAP-TLS for the managed devices, while keeping PEAP for the BYOD.
In theory this can be done, but I'm wondering if anyone has rolled this solution out and found that in practice it causes difficulties? Am I better to go down the route of creating separate SSIDs for each device type, each with a single EAP type?
Thanks in advance
Solved! Go to Solution.
08-24-2026 01:34 AM
you can do it with single SSID with different ISE policy with TLS first, if the machine fails TLS it will fall back to PEAP policy.
creating other SSID is also ok but why create additional wireless management overhead when it can be done with single SSID.
08-24-2026 01:34 AM
you can do it with single SSID with different ISE policy with TLS first, if the machine fails TLS it will fall back to PEAP policy.
creating other SSID is also ok but why create additional wireless management overhead when it can be done with single SSID.
08-24-2026 02:14 AM
Thanks ammahend for your response. You say with different ISE policy (I am assuming you mean Policy Sets), however in ISE I can create an Allowed Protocols policy that accepts both PEAP and TLS, and reference it from a single Policy Set, so why would I create two separate Policy Sets?
That aside, my main question was actually, I know it is possible, but has anyone actually implemented it and found it has led to issues with end user devices?
08-24-2026 03:47 AM
- @ac5334 Checkout commands from Client KPI's to investigate client behavior
and look for issues , if any.
Always validate the configuration of your 9800 wireless controller after making
changes with the CLI command show tech wireless and feed the output from that
into WCAE
M.
08-24-2026 07:20 AM
I meant single policy set, 2 separate rules.
i have deployed it, did not run into any issues, from wireless point of view its just 802.1x in both cases. You can built different rules based on eap type conditions.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide