<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE, BYOD: guest clients provisioning in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-byod-guest-clients-provisioning/m-p/2249691#M112284</link>
    <description>&lt;P&gt;Hello!&lt;/P&gt;&lt;P&gt;The question is about provisioning different types of wifi clients through the ISE Guest portal.&lt;/P&gt;&lt;P&gt;ISE 1.1.4, WLC 7.4.100 (Guest WLAN uses MAB)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Suppose, there are two groups of wireless clients:&lt;/P&gt;&lt;P&gt;1) guest user, which credentials are created through the ISE Sponsor Portal&lt;/P&gt;&lt;P&gt;2) domain user, who has credentials in ActiveDirectory&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The aim is to provision domain user, and not provision guest user.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When client connects to Guest SSID and opens the browser, he is redirected to ISE Guest portal.&lt;/P&gt;&lt;P&gt;When client uses domain user, he is provisioned, and when uses guest credentials he is not provisioned&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How ISE understands, that &lt;SPAN style="font-size: 10pt;"&gt;domain user must be provisioned and &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;guest user must &lt;STRONG&gt;not&lt;/STRONG&gt; be provisioned if Web portal is configured to provision everyone?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;(Web Portal -&amp;gt; Settings -&amp;gt; Enable Self-Provisioning flow)&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 26 Mar 2019 00:30:32 GMT</pubDate>
    <dc:creator>Jaaazman777</dc:creator>
    <dc:date>2019-03-26T00:30:32Z</dc:date>
    <item>
      <title>ISE, BYOD: guest clients provisioning</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-byod-guest-clients-provisioning/m-p/2249691#M112284</link>
      <description>&lt;P&gt;Hello!&lt;/P&gt;&lt;P&gt;The question is about provisioning different types of wifi clients through the ISE Guest portal.&lt;/P&gt;&lt;P&gt;ISE 1.1.4, WLC 7.4.100 (Guest WLAN uses MAB)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Suppose, there are two groups of wireless clients:&lt;/P&gt;&lt;P&gt;1) guest user, which credentials are created through the ISE Sponsor Portal&lt;/P&gt;&lt;P&gt;2) domain user, who has credentials in ActiveDirectory&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The aim is to provision domain user, and not provision guest user.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When client connects to Guest SSID and opens the browser, he is redirected to ISE Guest portal.&lt;/P&gt;&lt;P&gt;When client uses domain user, he is provisioned, and when uses guest credentials he is not provisioned&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How ISE understands, that &lt;SPAN style="font-size: 10pt;"&gt;domain user must be provisioned and &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;guest user must &lt;STRONG&gt;not&lt;/STRONG&gt; be provisioned if Web portal is configured to provision everyone?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;(Web Portal -&amp;gt; Settings -&amp;gt; Enable Self-Provisioning flow)&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Mar 2019 00:30:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-byod-guest-clients-provisioning/m-p/2249691#M112284</guid>
      <dc:creator>Jaaazman777</dc:creator>
      <dc:date>2019-03-26T00:30:32Z</dc:date>
    </item>
    <item>
      <title>ISE, BYOD: guest clients provisioning</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-byod-guest-clients-provisioning/m-p/2249692#M112298</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The answer is that typically you either know that MAC address or you have someting installed (NAC agent?) and fulfill some requirements. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Alternative, you can perform CWA first (and...)&lt;/P&gt;&lt;P&gt;Then if user is part of guest users -&amp;gt; allow internet only access&lt;/P&gt;&lt;P&gt;If user is part of AD -&amp;gt; send him to do registration. &lt;/P&gt;&lt;P&gt;Authorization policy allows you to use "identity group" as part of condition. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If device registered -&amp;gt; allow full access. (just an idea). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;M.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Jun 2013 13:59:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-byod-guest-clients-provisioning/m-p/2249692#M112298</guid>
      <dc:creator>Marcin Latosiewicz</dc:creator>
      <dc:date>2013-06-20T13:59:31Z</dc:date>
    </item>
    <item>
      <title>ISE, BYOD: guest clients provisioning</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-byod-guest-clients-provisioning/m-p/2249693#M112349</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please check the following links - they may provide a resolution to your issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/solutions/collateral/ns340/ns414/ns742/ns744/docs/howto_61_byod_provisioning.pdf"&gt;http://www.cisco.com/en/US/solutions/collateral/ns340/ns414/ns742/ns744/docs/howto_61_byod_provisioning.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.thesecurityblogger.com/?tag=enhanced-client-provisioning"&gt;http://www.thesecurityblogger.com/?tag=enhanced-client-provisioning&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Jun 2013 02:40:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-byod-guest-clients-provisioning/m-p/2249693#M112349</guid>
      <dc:creator>mmangat</dc:creator>
      <dc:date>2013-06-21T02:40:55Z</dc:date>
    </item>
    <item>
      <title>ISE, BYOD: guest clients provisioning</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-byod-guest-clients-provisioning/m-p/2249694#M112382</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;for guest you can use CWA...&lt;/P&gt;&lt;P&gt;for domain user, i don't understand what you want... but if you want posture checking and provisioned, you can use NAC Agent or web Agent... ( if there is no NAC Agent installed, you will be provisioned) &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Jun 2013 07:16:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-byod-guest-clients-provisioning/m-p/2249694#M112382</guid>
      <dc:creator>myanznki</dc:creator>
      <dc:date>2013-06-24T07:16:42Z</dc:date>
    </item>
  </channel>
</rss>

