Showing posts with label BYOD. Show all posts
Showing posts with label BYOD. Show all posts

Thursday, 13 November 2014

Cisco ISE 1.3

After much anticipation Cisco has finally released Identity Services Engine version 1.3 for general release.  1.3 promises to address many of the shortfalls of previous versions ISE such as easier BYOD certificate  management through its own inbuilt Certificate Authority, the ability to join more than one Active Directory (I know you could join more through an LDAP connector but the native client is cool) and improved guest portal design functionality.

Cisco ISE version 1.3 release notes can be read here
    

Upgrading

The upgrade process seems quite stable, in my deployment I backed up the ISE configuration to my NAS repository (scheduled and highly recommended to have this set up).  I reimaged my VM appliance with the new 1.3 ISO rather than upgrade the 1.2 appliance just as personally I feel a fresh installation is always a better approach. 







 

Once the ADE-OS appliance is installed it runs through the setup guide to get you up and running, after this completed and ISE is fully installed I restored the 1.2 config back to the new 1.3 deployment.  Note this restore process only works with 1.2 backups not earlier releases.

Logging onto the ISE GUI after the restore revealed the ISE had not joined the AD domain, this was a documented feature and after a quick AD join the administrative logon for AD users was restored.
The configuration looked complete and in most areas was identical to the previous release.

First Impressions

There  are some nice new GUI views portal customisation as well as the internal CA functionality, this was easy to setup and test and the original NDES integration to AD remained active until the new internal CA was selected under the NSP profile (see below).  Testing with an iPad worked first time with the new ISE provisioned certificate working as the original AD NDES one had and matched the authorisation policy (which verified the CN and MAC address of the client matched).


 

The newly provisioned certificates can then be managed through the ISE CA




All in all I am impressed with the updates to ISE 1.3, it is starting to become a much more user friendly system and should go some way to push the ease of management and security for BYOD access.

Friday, 20 June 2014

Cisco Wireless LAN timeouts

This is just a quick post to explain the functionality of the timeouts on Cisco Wireless Controllers, the subject is well documented but here is a plain english breakdown of their operation and impact when set incorrectly.

In this example we have an issue with Guest users having to login to Cisco ISE on a regular basis which is causing annoyance.  The cause of this will be down to two timers defined on the Cisco Wireless LAN Controller (Version 7.6 in this case).


Client Idle Timeout - Default 300 seconds


Configurable both globally and now under the WLAN - Timeout triggered after a period of inactivity, more relevant to mobile devices such as iOS (iPhone, iPad) and Android. 
The default idle timeout value of 5 minutes (300 seconds) may be too low for some devices (whilst some applications continually send constant data constantly refreshing the session this may not always be the case).  When a user brings the device out of sleep they are forced to log back in on the ISE web portal.

I have had good results setting this to 1 hour (3600 seconds).


Session Timeout - Default 3600 seconds


Configurable under WLAN - This is an absolute value and if defined here will cause a session reauth once expired, if using RADIUS this trigger an 802.1x reauthentication, if this is a MAB enabled SSID used for CWA this will clear the session and restart the CWA process.  I recommend not enabling this on the WLC but defining it on the ISE (or other RADIUS server).  For example using guest user account time profiles on ISE will send the session timeout in the RADIUS response which forces the WLC to clear down the session after the guest user's period of access is expired. 
If you want to set it statically on the WLC then I recommend a value of 7200 seconds or greater.