Cisco ISE

Technical Articles

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US

Requirements
  • Cisco Identity Services Engine (ISE) 3.3

  • EAP-TLS authentication for your network

  • The public key of the root certificate that issued Jamf Pro's TLS certificate

  • Experience with identity management, certificates, and policy sets in Cisco ISE. For more information, see the Cisco Identity Services Engine 3.3 documentation from Cisco.

  1. In Cisco ISE, add or edit a certificate authentication profile within external identity sources and do the following:
    1. In the Use Identity From section, select Certificate Attribute.
    2. Choose Subject Alternative Name from the pop-up menu.

    This setting allows the GUID to be retrieved from the certificate.

  2. On the System > Certificates > Trusted Certificates page, import the certificate file of the root certificate that issued Jamf Pro's TLS certificate, and select Trust for authentication within ISE during upload. This setting establishes a trusted connection between Cisco ISE and Jamf Pro.
    Note:

    (Cloud-Hosted) If your Jamf Pro instance is cloud-hosted and is leveraging Jamf Cloud's wildcard certificate (*.jamfcloud.com), import the certificate file for Amazon's root CA, "Amazon Root CA 1", which is available from Amazon Trust Services: https://www.amazontrust.com/repository/.

  3. Add or edit the external MDM server, and ensure that "Cert - SAN URI, GUID" is enabled.
    Note:

    Jamf recommends enabling only the "Cert - SAN URI, GUID" device identifier.

  4. Add or edit policy sets:
    1. Define the following conditions for when the policy set should be applied:
      DEVICE·Device Type EQUALS All Device Types
      Normalised Radius·RadiusFlowType EQUALS Wireless802_1x
    2. Include the following condition in your authentication policy sets:
      Network Access·EapAuthentication EQUALS EAP-TLS
    3. Select the name of the certificate authentication profile that you configured earlier, and then select "Use" from the pop-up menu.
    4. Add an authorization policy with the following condition:
      MDM·DeviceCompliantStatus EQUALS Compliant
Note:

You may have additional conditions configured for your environment. For example, if you have multiple external MDM servers set up, you must add a condition that specifies which one you want to use.