a week ago - last edited a week ago
Hi all!!
Recently I've been looking for a solution to onboard BYOD (unmanaged devices) to our 802.1X SSID. We service thousands of students using a wide variety of devices with different requirements to login to our Wi-Fi, and we are looking for a paid solution that creates downloadable config profiles/agents to install the required settings and RADIUS certificate on the device without requiring the end-user to know how to configure EAP methods.
Issues we are facing in finding a new solution:
Vendors we are evaluating, and issues with them:
I have read several academic papers about this very issue, and have looked at other universities with public KB articles indicating that they face similar problems. As of 2025, is there still no good solution?
(We have not yet evaluated Cisco ISE, as my understanding is that is more of a NAC than an onboarding portal. We aren't looking for a wireless NAC at this time, as that would be overkill and probably really expensive? If anyone thinks ISE would be a good solution for this please let me know! We also have not yet evaluated Aruba Clearpass, for the same reasons. I heard Clearpass has a module called Clearpass Onboard, but I imagine we cannot use that without getting the full version of ClearPass. If anyone has experience with ClearPass please also let me know!)
Monday - last edited Tuesday
With eduroam cat you can provision additional SSID besides eduroam.
edited to add: if your organization is federated in Eduroam or plans to do it soon, then you will have a dedicated config area in cat.eduroam.org (no need to maintain a dedicate infrastructure on prem) where you will configure 802.1X parameters for your institution's eduroam network (PEAP, or EAP-TTLS or whatever) as well as additional networks and their authentication params.
Besides, your user will be able to config their devices with the geteduroam.org app, check it out.
Where (which country) is your organization based?