<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Is it possible to allow only devices with certificates to authenticate on 802.1x? in ExtremeCloud IQ</title>
    <link>https://community.extremenetworks.com/t5/extremecloud-iq/is-it-possible-to-allow-only-devices-with-certificates-to/m-p/71384#M1136</link>
    <description>&lt;P&gt;We have corporate SSID configured with 802.1x and most of our company assets have a certificate that allows them to connect. But, anyone with AD credentials can connect using their username/password on devices without a cert installed.&amp;nbsp; &amp;nbsp; &amp;nbsp;We want to require a certificate on the device in order for it to be able to connect to the corporate SSID.&amp;nbsp; We’ve had issues with users connecting personal devices using their username/password and we want to prevent this.&lt;/P&gt;</description>
    <pubDate>Fri, 16 Jul 2021 23:32:16 GMT</pubDate>
    <dc:creator>gshipp</dc:creator>
    <dc:date>2021-07-16T23:32:16Z</dc:date>
    <item>
      <title>Is it possible to allow only devices with certificates to authenticate on 802.1x?</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq/is-it-possible-to-allow-only-devices-with-certificates-to/m-p/71384#M1136</link>
      <description>&lt;P&gt;We have corporate SSID configured with 802.1x and most of our company assets have a certificate that allows them to connect. But, anyone with AD credentials can connect using their username/password on devices without a cert installed.&amp;nbsp; &amp;nbsp; &amp;nbsp;We want to require a certificate on the device in order for it to be able to connect to the corporate SSID.&amp;nbsp; We’ve had issues with users connecting personal devices using their username/password and we want to prevent this.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jul 2021 23:32:16 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq/is-it-possible-to-allow-only-devices-with-certificates-to/m-p/71384#M1136</guid>
      <dc:creator>gshipp</dc:creator>
      <dc:date>2021-07-16T23:32:16Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to allow only devices with certificates to authenticate on 802.1x?</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq/is-it-possible-to-allow-only-devices-with-certificates-to/m-p/71385#M1137</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can’t recall if built-in XIQ RADIUS can work with EAP-TLS but you can always force XIQ APs to forward auth requests to your NAC/RADIUS server (like NPS or EAC or any other) and over there you’ll have to allow only EAP-TLS and not PEAP if you don’t want to permit user credentials to be allowed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that helps,&lt;/P&gt;&lt;P&gt;Tomasz&lt;/P&gt;</description>
      <pubDate>Sat, 24 Jul 2021 02:22:52 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq/is-it-possible-to-allow-only-devices-with-certificates-to/m-p/71385#M1137</guid>
      <dc:creator>Tomasz</dc:creator>
      <dc:date>2021-07-24T02:22:52Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to allow only devices with certificates to authenticate on 802.1x?</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq/is-it-possible-to-allow-only-devices-with-certificates-to/m-p/71386#M1138</link>
      <description>&lt;P&gt;Hi &lt;USER-MENTION data-id="6884494"&gt;@Tomasz&lt;/USER-MENTION&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I’ve the same issue. Anyone with their AD credential they can login to personal device as well. How to prevent this personal device login over AD credential? They only want to allow corporate device.&lt;/P&gt;&lt;P&gt;We can control via the MAC based filter but they more than 3500 devices.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Aug 2021 11:49:43 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq/is-it-possible-to-allow-only-devices-with-certificates-to/m-p/71386#M1138</guid>
      <dc:creator>Prashath</dc:creator>
      <dc:date>2021-08-11T11:49:43Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to allow only devices with certificates to authenticate on 802.1x?</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq/is-it-possible-to-allow-only-devices-with-certificates-to/m-p/71387#M1139</link>
      <description>&lt;P&gt;Hi Prashath,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Well, host-based auth with certificates (EAP-TLS) seem to be an option here.&lt;/P&gt;&lt;P&gt;Otherwise, in case of user-based auth you will have to have some other way to verify if the device is corporate or not.&lt;/P&gt;&lt;P&gt;If we used Extreme Access Control, there should be an option to import a list of MAC addresses. I didn’t try to create End-system group that big though (but worth trying if host-based auth is not possible).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that helps,&lt;/P&gt;&lt;P&gt;Tomasz&lt;/P&gt;</description>
      <pubDate>Thu, 12 Aug 2021 04:13:36 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq/is-it-possible-to-allow-only-devices-with-certificates-to/m-p/71387#M1139</guid>
      <dc:creator>Tomasz</dc:creator>
      <dc:date>2021-08-12T04:13:36Z</dc:date>
    </item>
  </channel>
</rss>

