The finer points of System Manager

Solved
The_Roo
Getting noticed

The finer points of System Manager

I am trying to improve my understanding of System Manager and System Manager Sentry when used for Wireless Authentication.

As I understand it, a corporate WLAN can be protected by dot1x and EAP/TLS by setting the WLAN's SSID to "802.1X with Meraki RADIUS" and any device that subsequently attempts to associate with the SSID will be authenticated by System Manager Sentry using mutual exchange of certificates. If there are no appropriate certificates on the device, the association will be blocked. If the device has the correct certificates, the authentication is transparent to the device user and association occurs. That seems straightforward, if I’ve understood it right.

I also understand that, to deliver certificates to client devices, and prepare them to access the corporate WLAN I can create an "onboarding" WLAN (open security and only Internet access) by setting the Sign-On Method on the SSID to "System Manager Sentry". Then, when a client device is associated with that SSID, the Meraki system will interrogate the device to find whether it has been onboarded. If it has not, System Manager will prompt the user to provide on-boarding credentials, at which time certificates will be loaded and the device will be prepared to access the corporate WLAN. Again, that seems straightforward, if I’ve understood it right.

But….there are a couple of things I can’t get clear in my head. I’m looking at a document “Configuring EAP-TLS Wireless Authentication with Systems Manager Sentry Wifi” The document mentions tag and profile creation, but I don’t understand how that works. I just can’t get my head round point 3, do I need to create tags and profiles, or does it happen automatically? Is there more to configuration than I mention in the first two paragraphs? Have I missed something critical.

 

Thanks for any help

Roo

1 Accepted Solution
PhilipDAth
Kind of a big deal
Kind of a big deal

> I just can’t get my head round point 3, do I need to create tags and profiles

 

Do you need to create tags - no.  You can simply apply it to all Systems Manager devices in the network (and you can create multiple Systems Manager networks).

 

Do you need to create a profile - probably not.  Enabling a sentry-based WiFi network will automatically create a configuration in Systems Manager.  Just set that to deploy to all devices.

https://documentation.meraki.com/SM/Deployment_Guides/Systems_Manager_Sentry_Overview#Method_1:_Auto... 

 

View solution in original post

2 Replies 2
alemabrahao
Kind of a big deal
Kind of a big deal

Take a look at this.

 

New to Systems Manager? Start Here!

 

https://community.meraki.com/t5/Mobile-Device-Management/New-to-Systems-Manager-Start-Here/m-p/10080...

 

 

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
PhilipDAth
Kind of a big deal
Kind of a big deal

> I just can’t get my head round point 3, do I need to create tags and profiles

 

Do you need to create tags - no.  You can simply apply it to all Systems Manager devices in the network (and you can create multiple Systems Manager networks).

 

Do you need to create a profile - probably not.  Enabling a sentry-based WiFi network will automatically create a configuration in Systems Manager.  Just set that to deploy to all devices.

https://documentation.meraki.com/SM/Deployment_Guides/Systems_Manager_Sentry_Overview#Method_1:_Auto... 

 

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels