MobileIron Quick Integration Guide. for PacketFence version 4.5.1



Similar documents
Checkpoint firewall Quick Integration Guide. for PacketFence version 4.6.0

OpenDaylight & PacketFence install guide. for PacketFence version 4.5.0

Cloud Services MDM. Control Panel Provisioning Guide

GlobalSign Integration Guide

New User Enrollment Processes for Online Banking Services

Getting Started with StoreGrid Cloud

Advanced Configuration Steps

How to generate an APNs Certificate to use the Apple MDM protocol via the portal

DESLock+ Basic Setup Guide Version 1.20, rev: June 9th 2014

Mobile Iron User Guide

IRMACS Setup. Your IRMACS is available internally by the IMAP protocol. The server settings used are:

UP L18 Enhanced MDM and Updated Protection Hands-On Lab

Streamline Mobile Telecom Management with DATALERT! And MobileIron

Getting Started - MDM Setup

User Guide Microsoft Exchange Remote Test Instructions

Integrating Cisco ISE with GO!Enterprise MDM Quick Start

Comodo Mobile Device Manager Software Version 3.0

Setup Guide for PrestaShop and BlueSnap

setup information for most domains hosted with InfoRailway.

Configuring Single Sign-on from the VMware Identity Manager Service to WebEx

EMR Link Server Interface Installation

Defender Token Deployment System Quick Start Guide

Configuring Single Sign-on from the VMware Identity Manager Service to Dropbox

Device Enrollment Guide

WHMCS LUXCLOUD MODULE

Swisscom Mobile Device Services Quick Start Guide: Set-up Remote Management basic. Mobile Device Services Februar 2014

Product Manual. MDM On Premise Installation Version 8.1. Last Updated: 06/07/15

Setup Guide for Magento and BlueSnap

Specops Command. Installation Guide

DreamFactory on Microsoft SQL Azure

Windows Clients and GoPrint Print Queues

Basic Exchange Setup Guide

HP LeftHand SAN Solutions

eschoolpad for ipad INSTALLATION GUIDE v3.0 Prepared by: Avrio Solutions Company Limited

Comodo Mobile Device Manager Software Version 1.0

SPC Connect Configuration Manual V1.0

Dell Mobile Management. Apple Device Enrollment Program

Windows Intune Walkthrough: Windows Phone 8 Management

Good MDM Integration with Cisco Identity Service Engine. Secure Access How -To Guides Series

Zendesk SSO with Cloud Secure using MobileIron MDM Server and Okta

How to configure the TopCloudXL WHMCS plugin (version 2+) Update: Version: 2.2

Administering Jive Mobile Apps

Integrating Citrix EasyCall Gateway with SwyxWare

Preparing for GO!Enterprise MDM On-Demand Service

Web based training for field technicians can be arranged by calling These Documents are required for a successful install:

Biznet GIO Cloud Connecting VM via Windows Remote Desktop

Getting Started Guide: Getting the most out of your Windows Intune cloud

Configuring an IP (SIP) Polycom Soundstation on the Avaya IP Office

DESlock+ Basic Setup Guide ENTERPRISE SERVER ESSENTIAL/STANDARD/PRO

GO!Enterprise MDM Device Application User Guide Installation and Configuration for ios with TouchDown

Basic Exchange Setup Guide

Using the Apple Configurator and MaaS3360

Configuring Single Sign-On from the VMware Identity Manager Service to Office 365

Employee Active Directory Self-Service Quick Setup Guide

Sophos Mobile Control Installation guide

Installation Guide. . All right reserved. For more information about Specops Inventory and other Specops products, visit

ICONICS Using the Azure Cloud Connector

Mobility Manager 9.5. Installation Guide

Richmond Systems. SupportDesk Web Interfaces - Quick Start Guide

How to install phpbb forum on NTU student club web server

Office 365 Windows Intune Administration Guide

ONSITE TRACK EASY Campbell Arnott s Contractor Management Portal Portal User Guide: Employee Registration & Induction Bookings

Booth Gmail Configuration

GRAVITYZONE HERE. Deployment Guide VLE Environment

Knoa MicroStrategy Web Configuration Table of contents

APNS Certificate generating and installation

Configuring an ios App Store application

GO!Enterprise MDM Device Application User Guide Installation and Configuration for ios Devices

VMware Identity Manager Administration

District 211 Technology. ipad Setup Instructions

Connecting With Lifesize Cloud

Instructions Android Smartphone & Tablet Page 1

Exchange ActiveSync (EAS)

RMM/MDM. Quick Reference Guide

Citrix XenMobile Mobile Device Management

IIS, FTP Server and Windows

AVG Business SSO Partner Getting Started Guide

Connecting to Manage Your MS SQL Database

Architecture and Data Flow Overview. BlackBerry Enterprise Service Version: Quick Reference

WA2192 Introduction to Big Data and NoSQL. Classroom Setup Guide. Web Age Solutions Inc. Copyright Web Age Solutions Inc. 1

AVG Business Secure Sign On Active Directory Quick Start Guide

Creating Home Directories for Windows and Macintosh Computers

Lync Online Deployment Guide. Version 1.0

3rd Party VoIP Phone Setup Guide (Panasonic b)

FLX VoIP Registering with Avaya IP Office 500

Leica Geosystems Software Licensing Introduction & Installation

Citrix Virtual Classroom. Deliver file sharing and synchronization services using Citrix ShareFile. Self-paced exercise guide

QUANTIFY INSTALLATION GUIDE

Kaltura On-Prem Evaluation Package - Getting Started

The full setup includes the server itself, the server control panel, Firebird Database Server, and three sample applications with source code.

ManageEngine Desktop Central. Mobile Device Management User Guide

Connecting With Lifesize Cloud

Procurement Services Supplier Registration & Sourcing [SRS] Supplier Registration Guide 30 th May 2014

Deploying Intellicus Portal on IBM WebSphere

Microsoft Entourage 2008 / Microsoft Exchange Server Installation and Configuration Instructions

Customer Tips. Configuring Color Access on the WorkCentre 7328/7335/7345 using Windows Active Directory. for the user. Overview

How to connect to NAU s WPA2 Enterprise implementation in a Residence Hall:

EINTE LAB EXERCISES LAB EXERCISE #5 - SIP PROTOCOL

XenMobile Integration with Cisco Identity Service Engine. Secure Access How -To Guides Series

RingCentral Office. Configure Aastra phones with RingCentral

Transcription:

MobileIron Quick Integration Guide for PacketFence version 4.5.1

MobileIron Quick Integration Guide by Inverse Inc. Version 4.5.1 - Nov 2014 Copyright 2014 Inverse inc. Permission is granted to copy, distribute and/or modify this document under the terms of the GNU Free Documentation License, Version 1.2 or any later version published by the Free Software Foundation; with no Invariant Sections, no Front-Cover Texts, and no Back-Cover Texts. A copy of the license is included in the section entitled "GNU Free Documentation License". The fonts used in this guide are licensed under the SIL Open Font License, Version 1.1. This license is available with a FAQ at: http:// scripts.sil.org/ofl Copyright Łukasz Dziedzic, http://www.latofonts.com, with Reserved Font Name: "Lato". Copyright Raph Levien, http://levien.com/, with Reserved Font Name: "Inconsolata".

Table of Contents About this Guide... 1 Assumptions... 2 Quick installation... 3 Step 1: Configure MobileIron... 3 Step 2: Create an API user... 4 Step 3: Gather the boarding host... 6 Step 4: Configure PacketFence... 6 Step 5: Add the necessary passthroughs... 8 Step 6: Test... 9 Copyright 2014 Inverse inc. iii

Chapter 1 About this Guide This guide has been created in order to help sales engineers, product managers, or network specialists demonstrate the PacketFence capabilities on-site with an existing or potential customer. It can also provide guidelines to setup a proof of concept for a potential PacketFence deployment using the MobileIron mobile device manager. Copyright 2014 Inverse inc. About this Guide 1

Chapter 2 Assumptions You have a configured PacketFence environment with working test equipment; You have access to a MobileIron cloud account. Copyright 2014 Inverse inc. Assumptions 2

Quick installation Step 1: Configure MobileIron First of all you will need to configure the basic functionality of MobileIron using their documentation. MDM profile One important step is to enable the MDM profile like in this screenshot. Note that this will require you to create an MDM certificate with Apple. Refer to the MobileIron documentation for specifics about this step. Copyright 2014 Inverse inc. Quick installation 3

Step 2: Create an API user Next, we will need a user that has the rights to access the MobileIron API in order to verify the state of the devices directly from PacketFence. First go in the USERS & DEVICES tab and then in Users and click Add local user. Now enter the information about your user and note the user ID and password for usage in the PacketFence configuration, then hit Save. Copyright 2014 Inverse inc. Quick installation 4

Now go in the ADMIN tab, check the box next to your newly created user and then in Actions select Assign to Space. Select the Global space at the top and then check API at the bottom. You should now see API in the roles list of your newly created user when viewing the users list. Copyright 2014 Inverse inc. Quick installation 5

Step 3: Gather the boarding host To find the boarding host, add a fake device to MobileIron and at the end of the process you will see the registration instructions. In it you will find the boarding host and port for the PacketFence configuration. In this case, the boarding host is m.mobileiron.net and the boarding port is 50291. Step 4: Configure PacketFence In PacketFence, MDM are refered to as provisioners. This will walk you through adding MobileIron as a provisioner. Create the provisioner Login in the PacketFence administration interface, then go in the Configuration tab, then in Provisioners. Click Add provisioner then select mobileiron. Copyright 2014 Inverse inc. Quick installation 6

Now configure this new provisioner with the information you got above. The Provisioning ID is the friendly name of the provisioner. The Username is the user you created with API access above. The password is the password of the API user. The host is the domain name of the instance + your account name if you have a cloud account (ex: m.mobileiron.net/accountname) Now add the download URI for the agent. See below for more details. The Boarding host is the host that you got in step 3. The Boarding port is the port that you got in step 3. Here are the URIs that should work by default. Replace accountname by your real account/instance name at MobileIron. Android: https://m.mobileiron.net/accountname/c/d/android.html IOS devices: https://m.mobileiron.net/accountname/c/d/ios.html Windows: https://m.mobileiron.net/accountname/enrollmentserver/discovery.svc Add the provisioner to the portal profile In order for the provisionner to be used by your captive portal you need to add it in its configuration. Go in Portal Profiles, then select the portal you want to modify and add mobileiron as a provisioner. Copyright 2014 Inverse inc. Quick installation 7

Step 5: Add the necessary passthroughs Next, still in the PacketFence administration console, go in Trapping in the left menu, then scroll then to Passthroughs. Check the Passthrough box above the field and add the following domains to the passthrough list. m.mobileiron.net *.itunes.apple.com itunes.apple.com play.google.com *.play.google.com Copyright 2014 Inverse inc. Quick installation 8

Restart PacketFence In order to enable the boarding passthrough for the device enrollment, you will need to restart the iptables service of PacketFence. You can do this using the command line by doing /usr/local/pf/bin/pfcmd service iptables restart or in the administration interface under Status / Services. Step 6: Test You can now test that MobileIron is mandatory after the device registration. Connect a device to your test network and register like you normally would. At the end of the registration process you will be presented a page asking you to install the MobileIron on your device. After you install the agent click Continue. If your access is enabled than this means the connectivity between Packet- Fence and MobileIron is good. Copyright 2014 Inverse inc. Quick installation 9