My infrastructure is finally configured to support 802.1x machine auth. I'm excited to deploy. Im late to the party but I finally made it.
Final testing is in progress now. Im trying to test every scenario that might happen once in production. My Jamf 802.1x profile seems to work most of the time, but there are a few scenarios that fail during testing.
1) Laptops running FileVault 2 don't authenticate until the user logs in (no machine pre-auth). I assume I have to disable login window pass-through to allow FV2 and 802.1x to peacefully co-exist. This will make users authenticate twice. Is this correct?
2) If I reboot my Mac laptop, 802.1x works 100% of the time. But if I simply log out (not reboot) and attempt to log in again, I get the red dot warning "No network accounts available" message in the login window.
3) Does the wi-fi interface need to be at the top of the Service Order list in the Network preference pane? I have noticed that if the interfaces are in the wrong order, there might be times when a I cant use Wi-fi or Ethernet, and thus I am forced to use cached credentials (or I am 'locked-out' of laptop). If this is the case - how do you for Mac laptops to use Wi-fi before other interfaces? Script? Profile? Policy?
4) If the 802.1x says "connected" in the Network preference pane GUI, does that mean the computer is authenticated, or that the end user is authenticated?
4) Do you manage 802.1 from a dedicated Network Location Set?
My environment is fairly vanilla:
-Jamf 10.3..1
-Mostly macOS 10.12 & macOS 10.13
-AD (2012 R2 functional level)
-Manage Mobile accounts
-Cisco ISE Radius and WLC
-Profile has (2) payloads: AD Certificate payload and Network settings payload (WPA2 Enterprise & PEAP/TLS)
-All Macs already have my PKI certificate server trust chain in the System Keychain