
58 |Onboard ClearPass Guest 3.9 | Deployment Guide
Figure 9 ClearPass Onboard Network Architecture when Using ClearPass Guest
The user experience for device provisioning is the same in Figure 9 and Figure 7 on page 56, however there
are implementation differences between these approaches:
When using the ClearPass Guest RADIUS server for provisioning and authentication, EAP-TLS and
PEAP authentication must be configured.
Navigate to RADIUS > Authentication > EAP & 802.1X to configure a server certificate and the
appropriate EAP types for the ClearPass Guest RADIUS server.
ClearPass Policy Manager supports a rich policy definition framework. If you have complex policies to
enforce, multiple authentication or authorization sources that define user accounts, or you need features
beyond those available in the ClearPass Guest RADIUS server, you should deploy Policy Manager for
authentication.
The ClearPass Onboard Process
Devices Supporting Over-the-Air Provisioning
ClearPass Onboard supports secure device provisioning for iOS 4, iOS 5, and recent versions of Mac OS X
(10.7 “Lion” and later). These are collectively referred to as “iOS devices”.
The Onboard process for iOS devices is shown in Figure 10 on page 59.
Comentarios a estos manuales