I’m trying to use Meraki's inbuilt ability to use EAP/TLS authentication. I’m also using MR57 APs, which have Wi_fi 6 capability and will use WPA3 encryption.
I’ve been looking at the document https://documentation.meraki.com/General_Administration/Cross-Platform_Content/Configuring_EAP-TLS_W... (and lots of others, thanks Dr Google!) and understand I must create a secure SSID (sl-corp) and an on-boarding SSID (sl-corp-on-boarding).
I also understand that I must set the access control for sl-corp to Meraki Cloud Authentication and select Systems Manager Sentry WiFi:
All good so far: From the above, I believe that devices attempting to authenticate to the SSID will only be successful after a mutual exchange of certificates with the Meraki system. But its the backend part of this I'm missing: how lo get certificates on the client devices and get them to recognise the certificates from ther network.
The document goes on to say:
3.Select the device tags to be associated with EAP-TLS. This automatically creates a Systems Manager profile for the SL-corp SSID to use EAP-TLS and installs a client certificate from the Dashboard for each client (this profile will appear under Systems Manager > Manage > Settings). Note that wireless authentication settings should be provisioned from either the SSID side, as described in this article, or the MDM profile side in Systems Manager > Manage > Settings and not both.
My questions are
“where do the device tags come from?” What is described above seems reasonable: Systems Manager will look for a pre-selected tag on a device and when it finds the authenticating device has the right tag, it will authenticate that device with EAP/TLS. Is there a single good document that shows how to set up Systems Manager and make it work in some detail?
There is an "sl-corp-on-boarding" SSID mentioned but I can'see how it should be built or how it should be used?
I want to use Wi-Fi 6, so the WPA Encryption mode will be forced to WPA3. Are there any considerations or will that just work?
Probably some newbie questions here guys, I’ve done .1x /EAP/TLS with ISE, and I know what I want to do with the Meraki, its just I don’t know how to do it!
Thaks for any help
Roo