<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE WLC 4400 configuration in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-wlc-4400-configuration/m-p/2322869#M154225</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Charles,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;this is great information, thanks for linking this.&lt;/P&gt;&lt;P&gt;However, to be a bit more specific on the need of this deployment...&lt;/P&gt;&lt;P&gt;The customer is looking to do webauth for guests. Setting up all the clients for dot1x may not be possible as the client count could reach into the hundreds.&amp;nbsp; Not to mention, this is for a trade show, and the clients won't be on-site until the day of the show. So getting everyone to configure the service may not be accomplishable. &lt;/P&gt;&lt;P&gt;The customers main requirement is the use of an AUP, and being able to monitor. Ideally, they would like to posture, as this has been a manual procedure, but are aware that this is unlikely.&lt;/P&gt;&lt;P&gt;Any thoughts on what i may be able to accomplish?&lt;/P&gt;&lt;P&gt;I tried setting up radius authZ profiles for webauth, using the controller to authenticate and ISE for authorization, but this isn't working as planned&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 28 Aug 2013 05:27:00 GMT</pubDate>
    <dc:creator>MMstre</dc:creator>
    <dc:date>2013-08-28T05:27:00Z</dc:date>
    <item>
      <title>ISE WLC 4400 configuration</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-wlc-4400-configuration/m-p/2322867#M154194</link>
      <description>&lt;P&gt;Up until now, my experience has been with 5500 controllers and ISE.&lt;/P&gt;&lt;P&gt;My customer is using 4400 controller, on 7.0.240 code.&lt;/P&gt;&lt;P&gt;I cannot locate any documents referencing 4400 controller configuration for webauth, named ACLs, posturing, etc...&lt;/P&gt;&lt;P&gt;Does anyone know of any documents, or have experience that can assist with this configuration?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 03:49:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-wlc-4400-configuration/m-p/2322867#M154194</guid>
      <dc:creator>MMstre</dc:creator>
      <dc:date>2019-03-11T03:49:29Z</dc:date>
    </item>
    <item>
      <title>ISE WLC 4400 configuration</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-wlc-4400-configuration/m-p/2322868#M154213</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Michael,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Depending on the version of ISE software you are running, you may be in luck.&amp;nbsp; The information below is for 1.1.x.&amp;nbsp; If you are using v 1.2, you may have to tweak a bit.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In this first document, you can see the WLC 4400 is supported and Local Web Auth is supported, with the following caveat:&amp;nbsp; “Wireless (An ISE Inline Posture node is required if the WLC does not support CoA as discussed in Footnote #4. WLCs with the code specified in this table do support CoA without an ISE Inline Posture node)”&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/docs/security/ise/1.1/compatibility/ise_sdt.html#wp55038"&gt;http://www.cisco.com/en/US/docs/security/ise/1.1/compatibility/ise_sdt.html#wp55038&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Of course, with an IPN, your posturing&amp;nbsp; (and CoA) is handled here.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;DACLs are also supported on the WLC 4400.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Per User ACLs are covered in the following document:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/products/ps6366/products_configuration_example09186a00808b041e.shtml"&gt;http://www.cisco.com/en/US/products/ps6366/products_configuration_example09186a00808b041e.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think you will find that if you substitute the ACS pages with the corresponding ISE interface pages, this can be done.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please feel free to ask any additional or follow-up questions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, please let me know if this fixes your issue.&amp;nbsp; If it does, please rate this answer and mark your question as Answered.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Charles Moreton&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Aug 2013 21:15:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-wlc-4400-configuration/m-p/2322868#M154213</guid>
      <dc:creator>Charlie Moreton</dc:creator>
      <dc:date>2013-08-27T21:15:42Z</dc:date>
    </item>
    <item>
      <title>ISE WLC 4400 configuration</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-wlc-4400-configuration/m-p/2322869#M154225</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Charles,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;this is great information, thanks for linking this.&lt;/P&gt;&lt;P&gt;However, to be a bit more specific on the need of this deployment...&lt;/P&gt;&lt;P&gt;The customer is looking to do webauth for guests. Setting up all the clients for dot1x may not be possible as the client count could reach into the hundreds.&amp;nbsp; Not to mention, this is for a trade show, and the clients won't be on-site until the day of the show. So getting everyone to configure the service may not be accomplishable. &lt;/P&gt;&lt;P&gt;The customers main requirement is the use of an AUP, and being able to monitor. Ideally, they would like to posture, as this has been a manual procedure, but are aware that this is unlikely.&lt;/P&gt;&lt;P&gt;Any thoughts on what i may be able to accomplish?&lt;/P&gt;&lt;P&gt;I tried setting up radius authZ profiles for webauth, using the controller to authenticate and ISE for authorization, but this isn't working as planned&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Aug 2013 05:27:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-wlc-4400-configuration/m-p/2322869#M154225</guid>
      <dc:creator>MMstre</dc:creator>
      <dc:date>2013-08-28T05:27:00Z</dc:date>
    </item>
    <item>
      <title>ISE WLC 4400 configuration</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-wlc-4400-configuration/m-p/2322870#M154247</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;AUP is a sub of Posturing, but posturing is not a good idea for guest flows.&amp;nbsp; I would create an AUP with an Any role and use the ISE for both Authenticate and Authorize.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have linked the following document so that you may see the different AUP Configurations available.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/docs/security/ise/1.0/user_guide/ise10_pos_pol.html"&gt;http://www.cisco.com/en/US/docs/security/ise/1.0/user_guide/ise10_pos_pol.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is a quick chart to look at, as well:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/8/0/0/153008-ISE_AUP.PNG" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;Again,&amp;nbsp; please let me know if this fixes your issue.&amp;nbsp; If it does, please rate this answer and mark your question as Answered.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Charles Moreton&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Aug 2013 15:10:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-wlc-4400-configuration/m-p/2322870#M154247</guid>
      <dc:creator>Charlie Moreton</dc:creator>
      <dc:date>2013-08-28T15:10:07Z</dc:date>
    </item>
    <item>
      <title>ISE WLC 4400 configuration</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-wlc-4400-configuration/m-p/2322871#M154268</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Charles,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you sure this is a correct statement ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;DACLs are also supported on the WLC 4400 ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;__________________________________________________________________________________________ &lt;BR /&gt;"Satisfaction does not come from knowing the solution, it comes from knowing why." - Rosalind Franklin &lt;BR /&gt;__________________________________________________________________________________________ &lt;BR /&gt;‎"I'm in a serious relationship with my Wi-Fi. You could say we have a connection."&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Aug 2013 17:11:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-wlc-4400-configuration/m-p/2322871#M154268</guid>
      <dc:creator>George Stefanick</dc:creator>
      <dc:date>2013-08-28T17:11:29Z</dc:date>
    </item>
    <item>
      <title>ISE WLC 4400 configuration</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-wlc-4400-configuration/m-p/2322872#M154313</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;According to this matrix, they are supported with a caveat "Wireless (An ISE Inline Posture node is required&amp;nbsp; if the WLC does not support CoA as discussed in Footnote #4. WLCs with&amp;nbsp; the code specified in this table do support CoA without an ISE Inline&amp;nbsp; Posture node)"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So the WLC 4400 is NOT itself processing or using the DACL&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/docs/security/ise/1.1/compatibility/ise_sdt.html#wp55038"&gt;http://www.cisco.com/en/US/docs/security/ise/1.1/compatibility/ise_sdt.html#wp55038&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Aug 2013 17:15:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-wlc-4400-configuration/m-p/2322872#M154313</guid>
      <dc:creator>Charlie Moreton</dc:creator>
      <dc:date>2013-08-28T17:15:52Z</dc:date>
    </item>
    <item>
      <title>ISE WLC 4400 configuration</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-wlc-4400-configuration/m-p/2322873#M154367</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Michael,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My experience is not the hardware but the code is the differentiater . 4400 cant go past 7.0 code. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you are looking for a simple guest AUP. Why not just take ISE out of the mix and do a AUP on the controller. You can upload a custom page and have a simple click here&amp;nbsp; or you could use a generic account. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Why the trouble of ISE for a simple AUP guest ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;__________________________________________________________________________________________ &lt;BR /&gt;"Satisfaction does not come from knowing the solution, it comes from knowing why." - Rosalind Franklin &lt;BR /&gt;__________________________________________________________________________________________ &lt;BR /&gt;‎"I'm in a serious relationship with my Wi-Fi. You could say we have a connection."&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Aug 2013 17:16:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-wlc-4400-configuration/m-p/2322873#M154367</guid>
      <dc:creator>George Stefanick</dc:creator>
      <dc:date>2013-08-28T17:16:25Z</dc:date>
    </item>
    <item>
      <title>ISE WLC 4400 configuration</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-wlc-4400-configuration/m-p/2322874#M154402</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Unifed controllers only use NAMED ACLs. ISE uses a radius attriubute to impose the named ACL from the wlc onto the client. &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;__________________________________________________________________________________________ &lt;BR /&gt;"Satisfaction does not come from knowing the solution, it comes from knowing why." - Rosalind Franklin &lt;BR /&gt;__________________________________________________________________________________________ &lt;BR /&gt;‎"I'm in a serious relationship with my Wi-Fi. You could say we have a connection."&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Aug 2013 17:18:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-wlc-4400-configuration/m-p/2322874#M154402</guid>
      <dc:creator>George Stefanick</dc:creator>
      <dc:date>2013-08-28T17:18:54Z</dc:date>
    </item>
    <item>
      <title>ISE WLC 4400 configuration</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-wlc-4400-configuration/m-p/2322875#M154475</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Chalres that chart is a type o ? States dACL but (4) says different ..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SUP style="color: #000000; font-family: Arial, Helvetica, sans-serif; text-indent: -24px;"&gt;&lt;A href="http://www.cisco.com/en/US/docs/security/ise/1.1/compatibility/ise_sdt.html#wp76182" style="color: #3366cc;"&gt;4&lt;/A&gt; &lt;/SUP&gt;&lt;/P&gt;&lt;P&gt;Wireless LAN Controllers (WLCs) do not support downloadable ACLs (dACLs), but support named ACLs. WLCs prior to release 7.0.116.0 do not support CoA and require deployment of an ISE Inline Posture Node to support posture services. Use of Inline Posture Node requires WLC version 7.0.98 or later. Autonomous AP deployments (no WLC) also require deployment of an Inline Posture Node for posture support. Profiling services are currently supported for 802.1X-authenticated WLANs only on the WLC with CoA support. HREAP is not supported. WLCs do not currently support MAC Authentication Bypass (MAB).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;__________________________________________________________________________________________ &lt;BR /&gt;"Satisfaction does not come from knowing the solution, it comes from knowing why." - Rosalind Franklin &lt;BR /&gt;__________________________________________________________________________________________ &lt;BR /&gt;‎"I'm in a serious relationship with my Wi-Fi. You could say we have a connection."&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Aug 2013 17:22:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-wlc-4400-configuration/m-p/2322875#M154475</guid>
      <dc:creator>George Stefanick</dc:creator>
      <dc:date>2013-08-28T17:22:54Z</dc:date>
    </item>
  </channel>
</rss>

