cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
767
Views
10
Helpful
4
Replies

ISE Policy to differentiate Windows and Apple

paul46
Level 1
Level 1

Implementing wireless solution on ISE 2.3. Let me provide some details before I ask the question. 

 

Want to authenticate windows machines using EAP-TLS via unique certificate. For all Apple iOS devices, want to authenticate via AirWatch. There will be two SSIDs - WiFiWindows and WiFiApple

 

For Windows

1. A corporate device connects to WiFiWindows and presents certificate

2. ISE validates certificates and provides corporate access

 

for Apple

1. An iOS device connects to WiFiApple

2. ISE makes an API call to MDM (AirWatch) and checks device's registration status

3. If device is registered, corporate certificates is installed on devices to get full corporate access

 

question

How to prevent Apple iOS devices to join WiFiWindows? In other words, windows and apple have same corporate certificate, but when Apple device joins WiFiWindows, access should be denied. 

 

1 Accepted Solution

Accepted Solutions

I an sure that you can match the oui portion of the radius
calling-station-id to detect apple device versus dell for example.

But detecting the os require profiling as its detected with snmp traps and
nmap scans

View solution in original post

4 Replies 4

In your authorization rule you can combine Airespace-WLAN-ID with Endpoint
Identity Group. For example in your WLC if your win-ssid is having id 1 and
you are profiling your windows endpoints in win-identity-group. In this
case you authorization rule should match Airespace-WLAN-ID=1 & Endpoint
Identity Group=win-identity-group

Thanks Mohammed

 

Is there any solution without profiling? 

I an sure that you can match the oui portion of the radius
calling-station-id to detect apple device versus dell for example.

But detecting the os require profiling as its detected with snmp traps and
nmap scans

Thank you Mohammed

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: