<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE, WLC: web auth, blocking user account in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-wlc-web-auth-blocking-user-account/m-p/2216483#M126361</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Practical tests show that &lt;/P&gt;&lt;P&gt;- ISE does not send&lt;SPAN style="font-size: 10pt;"&gt; CoA automatically, when you delete or suspend user account.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;- When account is expired by timer, CoA works well.&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;In other words, when we give &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;DefaultOneHour profile to user account, after one our ISE expires the account and sends CoA to the client.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 26 Jun 2013 12:48:47 GMT</pubDate>
    <dc:creator>Jaaazman777</dc:creator>
    <dc:date>2013-06-26T12:48:47Z</dc:date>
    <item>
      <title>ISE, WLC: web auth, blocking user account</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-wlc-web-auth-blocking-user-account/m-p/2216477#M126325</link>
      <description>&lt;P&gt;Hello!&lt;/P&gt;&lt;P&gt;We are implementing BYOD concept with ISE (1.1.4) and WLC 5508 (7.4.100).&lt;/P&gt;&lt;P&gt;On WLC there is SSID(WLAN) with &lt;SPAN style="font-size: 10pt;"&gt;MAC filtering &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;without L2 security. For authentication user is redirected to the ISE Guest Portal. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Credentials are created at the ISE sponsor portal.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;We create user account in ISE sponsor portal with one hour lease. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;In 10 minutes we delete (or block)&amp;nbsp; user credentials. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;In spite of it the user is still able to work. Even if we manually disconnect client and reconnect it again, client opens the browser and &lt;SPAN style="font-size: 10pt;"&gt;there is no redirection to the ISE web auth page.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;This happens because WLC thinks, that client is still associated. &lt;/P&gt;&lt;P&gt;There are &lt;SPAN style="font-size: 10pt;"&gt;session and idle timeout &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;timers in WLC WLAN, &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;but they can't solve the problem of automatic client session removing.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From my point of you, ISE must send some kind of reauth request to the user &lt;SPAN style="font-size: 10pt;"&gt;after account deletion&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;, to make user authentication &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;impossible &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;In practice, ISE doesn't tell wlc or user, that client sesssion is blocked.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How the user account blocking process can be automated without manually deleting the client session from WLC client database?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Mar 2019 00:30:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-wlc-web-auth-blocking-user-account/m-p/2216477#M126325</guid>
      <dc:creator>Jaaazman777</dc:creator>
      <dc:date>2019-03-26T00:30:37Z</dc:date>
    </item>
    <item>
      <title>Re: ISE, WLC: web auth, blocking user account</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-wlc-web-auth-blocking-user-account/m-p/2216478#M126327</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I can't remember precisely, but once guest account timed out or admin deactivate it, ISE should send CoA to WLC, please check user guide.&lt;BR /&gt;&lt;BR /&gt;You get redirected successfully so I would think you are correct with WLC config, with radius nac and aaa override.&lt;BR /&gt;&lt;BR /&gt;check ISE live log whether it send CoA to WLC first.&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPad App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Jun 2013 16:10:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-wlc-web-auth-blocking-user-account/m-p/2216478#M126327</guid>
      <dc:creator>Shaoqin Li</dc:creator>
      <dc:date>2013-06-25T16:10:00Z</dc:date>
    </item>
    <item>
      <title>Re: ISE, WLC: web auth, blocking user account</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-wlc-web-auth-blocking-user-account/m-p/2216479#M126329</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="margin-top: px; margin-bottom: px; line-height: normal;"&gt;Shaogin is absolutely right. After the endpoint is created or updated, a success page appears, followed by a CoA termination being sent to the NAD/WLC. There is some problem with ISE configuration please cross check. For more detail you can see the below link.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/docs/security/ise/1.1/user_guide/ise_guest_pol.html"&gt;http://www.cisco.com/en/US/docs/security/ise/1.1/user_guide/ise_guest_pol.html&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 26 Jun 2013 03:40:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-wlc-web-auth-blocking-user-account/m-p/2216479#M126329</guid>
      <dc:creator>Ravi Singh</dc:creator>
      <dc:date>2013-06-26T03:40:20Z</dc:date>
    </item>
    <item>
      <title>Re: ISE, WLC: web auth, blocking user account</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-wlc-web-auth-blocking-user-account/m-p/2216480#M126330</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for reply!&lt;/P&gt;&lt;P&gt;sending CoA to WLC after deleting guest account really seems to be true way &lt;span class="lia-unicode-emoji" title=":grinning_face_with_big_eyes:"&gt;😃&lt;/span&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;After the endpoint is created or updated, a success page appears, followed by a CoA termination being sent to the NAD/WLC&lt;/PRE&gt;&lt;P&gt;Is it a default behaviour of the ISE?&lt;/P&gt;&lt;P&gt;I didn't find the information about enabling or disabling this function&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 26 Jun 2013 08:05:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-wlc-web-auth-blocking-user-account/m-p/2216480#M126330</guid>
      <dc:creator>Jaaazman777</dc:creator>
      <dc:date>2013-06-26T08:05:04Z</dc:date>
    </item>
    <item>
      <title>Re: ISE, WLC: web auth, blocking user account</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-wlc-web-auth-blocking-user-account/m-p/2216481#M126332</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes this is the default behaviour of ISE.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 26 Jun 2013 08:08:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-wlc-web-auth-blocking-user-account/m-p/2216481#M126332</guid>
      <dc:creator>Ravi Singh</dc:creator>
      <dc:date>2013-06-26T08:08:11Z</dc:date>
    </item>
    <item>
      <title>Re: ISE, WLC: web auth, blocking user account</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-wlc-web-auth-blocking-user-account/m-p/2216482#M126334</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It seems that there is some bug about CoA when deleting Guest accounts&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE border="1" cellpadding="0" cellspacing="0" style="width: 80%; border: 1pt outset gray;"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD style="border: inset gray 1.0pt; padding: 2.25pt 2.25pt 2.25pt 2.25pt;" valign="top"&gt;&lt;P style="margin-top: .75pt; margin-right: 0cm; margin-bottom: 4.5pt; margin-left: 0cm;"&gt;&lt;A href="https://www.cisco.com/cisco/psn/bssprt/bss?searchType=bstbugidsearch&amp;amp;page=bstBugDetail&amp;amp;BugID=CSCuc82135" rel="nofollow" target="_blank"&gt;CSCuc82135&lt;/A&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD style="border: inset gray 1.0pt; padding: 2.25pt 2.25pt 2.25pt 2.25pt;" valign="top"&gt;&lt;P style="margin-top: .75pt; margin-right: 0cm; margin-bottom: 4.5pt; margin-left: 0cm;"&gt;Guests need to be removed from the network on Suspend/Delete/Expiration&lt;/P&gt;&lt;P style="margin-top: .75pt; margin-right: 0cm; margin-bottom: 4.5pt; margin-left: 0cm;"&gt;When a guest user is deleted from the system, the RADIUS sessions&amp;nbsp;&amp;nbsp; associated with that guest user still exists.&lt;/P&gt;&lt;P style="margin-top: .75pt; margin-right: 0cm; margin-bottom: 4.5pt; margin-left: 0cm;"&gt;Workaround&amp;nbsp;&amp;nbsp; Reissue the Change of Authorization using the&amp;nbsp;&amp;nbsp; session information from Monitoring reports for the sessions associated with&amp;nbsp;&amp;nbsp; that guest user.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/docs/security/ise/1.1.1/release_notes/ise111_rn.html#wp411891" rel="nofollow"&gt;http://www.cisco.com/en/US/docs/security/ise/1.1.1/release_notes/ise111_rn.html#wp411891&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;from BUG Toolkit there is &lt;SPAN style="font-size: 10pt;"&gt;&lt;STRONG&gt;Release-Pending&lt;/STRONG&gt; in "Fixed-in" option.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 26 Jun 2013 08:49:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-wlc-web-auth-blocking-user-account/m-p/2216482#M126334</guid>
      <dc:creator>Jaaazman777</dc:creator>
      <dc:date>2013-06-26T08:49:36Z</dc:date>
    </item>
    <item>
      <title>Re: ISE, WLC: web auth, blocking user account</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-wlc-web-auth-blocking-user-account/m-p/2216483#M126361</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Practical tests show that &lt;/P&gt;&lt;P&gt;- ISE does not send&lt;SPAN style="font-size: 10pt;"&gt; CoA automatically, when you delete or suspend user account.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;- When account is expired by timer, CoA works well.&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;In other words, when we give &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;DefaultOneHour profile to user account, after one our ISE expires the account and sends CoA to the client.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 26 Jun 2013 12:48:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-wlc-web-auth-blocking-user-account/m-p/2216483#M126361</guid>
      <dc:creator>Jaaazman777</dc:creator>
      <dc:date>2013-06-26T12:48:47Z</dc:date>
    </item>
  </channel>
</rss>

