u/Jeff-IT

▲ 3 r/k12sysadmin+1 crossposts

SCEP MDM Profile being removed and issuing new certs

Hey guys, could use some assistance.

I use Manage Engine MDM.

My setup is

  1. Offline RootCA
  2. Domain joined intCA signed by root
  3. SCEP server on a separate box, using AD CS

I am in the process of creating an NDES/SCEP for our mac devices and ipads. I got this working.

  1. Device on IT vlan
  2. Run profile in MDM
  3. Profile installs, device gets certificate.

I noticed the next day the VPN profile was gone, and the the certificate was gone on the device as well. I look in the MDM logs and see "ndes server not reachable". The certificate still exists in the IntCA under issued certs

I go back to the device and see i left it on the guest network, which has no access to the ndes server.

So my guess here is the device checked in with the MDM, couldn't reach ndes and just removed the profile it already had? I don't know why it tried to reinstall this profile as nothing changed. So I repushed the profile and it caused the device to get a brand new cert, rather then using the one it had.

This is where im stuck. This seems like a pretty big issue i don't know how to solve. We have some remote employees, and its sounding like SCEP/NDES needs to be accessed from the public internet. Otherwise when they are home, they will lose their SCEP, their VPN and then get a brand new cert if i get them reconnected.

Can someone give me some times? Maybe i missed something? Any advice?

reddit.com
u/Jeff-IT — 13 hours ago

MacOS native IKEv2 Split Tunnel

Anyone have any luck getting a split tunnel to work? I’m about to make a new full tunnel just for Mac’s.

We have ME MDM.
Fortigate 200F running 7.4
Mac’s on 15.7.5 and 26.2-26.4

I got the split tunnel working on my domain devices via a script. The script installs the vpn and sets the routes needed in the split. The macs are not a part of the domain

In Mac’s I don’t have this option. I tried to do it manually and saw there is no option when making a new VPN to set split tunnel, but there is for L2TP.

So I went to the MDM and added a profile to install the VPN. ME MDM has no option to turn on split tunneling. The profile works and the vpn installs and connects, I see it in the vpn client list. But split tunnel is not on.

My only other guess is this needs to be done with a MDM custom config profile rather than a MDM VPN configuration. But I’m not sure if I’m on the right track, or if I missed something obvious.

reddit.com
u/Jeff-IT — 3 days ago