Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Enjoy members-only rewards and discounts
  • Create and access a list of your products
  • Manage your Dell EMC sites, products, and product-level contacts using Company Administration.

Dell Hybrid Client version 2403 Administrator's Guide

PDF

Configure the EAP-TLS machine mode authentication

Prerequisites

  • Ensure that you have enabled SCEP using Wyse Management Suite and the SCEP certificate is already enrolled. See, Configure SCEP.
  • If you are using a CA certificate, ensure that the CA certificate is available for authentication.
  • Ensure that the user certificate and the private key certificate are available for authentication.

Steps

  1. Log in to Wyse Management Suite.
  2. Go to the Groups & Configs page, and select your preferred device policy group.
  3. Click Edit Policies > Dell Hybrid Client 2.x.
    The Configuration Control | Dell Hybrid Client 2.x page is displayed.
  4. Click the Advanced tab.
  5. Expand Network Configuration, and click 802-1x Authentication.
  6. Click the Enable 802-1x toggle key to enable the 802-1x authentication for wired connection on the Ethernet 0 port.
  7. From the Authentication Type drop-down list, select TLS.
  8. From the Authentication Mode drop-down list, select Machine.
    NOTE:Guest, Domain user and Local users are supported for TLS machine mode authentication.
  9. Enter the SCEP certificate name.
  10. To use a CA certificate, click the CA Certificate Required toggle key.
  11. Enter any Password in Private Key password field to encrypt/Decrypt the SCEP certificates during 802.1x Authentication.
  12. Click Save & Publish.

Next steps

Log in to the Dell Hybrid Client-powered device as a domain user or local user. The 802.1x launcher is triggered and the 802-1 authentication automatically starts.

If log in is successful, the user certificate is enrolled via SCEP and the device gets IP address from the protected LAN. If log in is unsuccessful, the 802.1x authentication fails and the device remains in the Guest LAN.

When you log out or restart, the device will move to guest LAN by sending an EAPOL logoff to switch and disable the 802.1x configuration.


Rate this content

Accurate
Useful
Easy to understand
Was this article helpful?
0/3000 characters
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please select whether the article was helpful or not.
  Comments cannot contain these special characters: <>()\