<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Thats odd, the order of the in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-guest-ssid-need-only-web-auth-mobile-device-need-mac-address/m-p/2911241#M36238</link>
    <description>&lt;P&gt;Thats odd, the order of the rules should not matter when the conditions are specific to an SSID, because only the correct rule will match.&lt;/P&gt;
&lt;P&gt;You should try enabling the guest cwa rule, with just Called-Station-ID CONTAINS "Guest-SSID", and then show take a screenshot of the detail log for the mab requests where you say the mobile gets rejected and guests don't get redirected-&lt;/P&gt;</description>
    <pubDate>Thu, 12 May 2016 15:27:33 GMT</pubDate>
    <dc:creator>jan.nielsen</dc:creator>
    <dc:date>2016-05-12T15:27:33Z</dc:date>
    <item>
      <title>ISE Guest SSID need only web auth &amp; Mobile device need mac address auth</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-ssid-need-only-web-auth-mobile-device-need-mac-address/m-p/2911235#M36231</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Can someone help me in segregating two ssid authentication. i) Guest ssid use web authentication (guest sponsor portal) which is working fine.&lt;/P&gt;
&lt;P&gt;ii) Mobile phone ssid use mac address authentication which is partially working. I have done some configuration in ISE and mac filtering enable in WLC.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN style="line-height: normal;"&gt;Rule Name - VIP Wireless&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN style="line-height: normal;"&gt;Conditions - VIP and Radius:Called-Station-ID CONTAINS VIP-SSID&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN style="line-height: normal;"&gt;Permissions - PermitAccess&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN style="line-height: normal;"&gt;I am able to connect VIP-SSID, if my phone mac is in ISE, but if mac address is not in ISE then it is using guest web redirection policy and getting authenticate using guest credential. &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="line-height: normal;"&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="line-height: normal;"&gt;How can we&amp;nbsp; stop this thing that guest web redirection is use only for guest ssid not for mobile. &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="line-height: normal;"&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="line-height: normal;"&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="line-height: normal;"&gt;Kamlesh &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="line-height: normal;"&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 06:45:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-ssid-need-only-web-auth-mobile-device-need-mac-address/m-p/2911235#M36231</guid>
      <dc:creator>kamlenegi</dc:creator>
      <dc:date>2019-03-11T06:45:45Z</dc:date>
    </item>
    <item>
      <title>You need to make your CWA</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-ssid-need-only-web-auth-mobile-device-need-mac-address/m-p/2911236#M36232</link>
      <description>&lt;P&gt;You need to make your CWA redirect rules more specific, like your mobile phone ssid, so add the Called-Station-ID CONTAINS "Guest-SSID" to your redirect rule.&lt;/P&gt;</description>
      <pubDate>Thu, 12 May 2016 08:49:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-ssid-need-only-web-auth-mobile-device-need-mac-address/m-p/2911236#M36232</guid>
      <dc:creator>jan.nielsen</dc:creator>
      <dc:date>2016-05-12T08:49:25Z</dc:date>
    </item>
    <item>
      <title>Hi Nielsen,</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-ssid-need-only-web-auth-mobile-device-need-mac-address/m-p/2911237#M36233</link>
      <description>&lt;P&gt;Hi Nielsen,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I tried that as follows:&lt;/P&gt;
&lt;P&gt;rule name: guest-wireless&lt;/P&gt;
&lt;P&gt;condition: wireless_mab&amp;nbsp; &amp;amp; Called-Station-ID CONTAINS or END-WITH Guest-SSID&lt;/P&gt;
&lt;P&gt;result: centralize web auth......redirect acl .....sponsor guest portal.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Then I was able to connect guest ssid but not web redirection or not able to connect mobile ssid, it was showing connecting.....&lt;/P&gt;
&lt;P&gt;Is there anything I am missing?&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Kamlesh&lt;/P&gt;</description>
      <pubDate>Thu, 12 May 2016 09:01:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-ssid-need-only-web-auth-mobile-device-need-mac-address/m-p/2911237#M36233</guid>
      <dc:creator>kamlenegi</dc:creator>
      <dc:date>2016-05-12T09:01:13Z</dc:date>
    </item>
    <item>
      <title>Try not using two conditions</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-ssid-need-only-web-auth-mobile-device-need-mac-address/m-p/2911238#M36234</link>
      <description>&lt;P&gt;Try not using two conditions for your Called-Station-ID, just use CONTAINS&lt;/P&gt;</description>
      <pubDate>Thu, 12 May 2016 09:09:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-ssid-need-only-web-auth-mobile-device-need-mac-address/m-p/2911238#M36234</guid>
      <dc:creator>jan.nielsen</dc:creator>
      <dc:date>2016-05-12T09:09:09Z</dc:date>
    </item>
    <item>
      <title>Also, are you sure it's not</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-ssid-need-only-web-auth-mobile-device-need-mac-address/m-p/2911239#M36235</link>
      <description>&lt;P&gt;Also, are you sure it's not just your phone that is auto-connecting to the open ssid, when it gets rejected on the VIP SSID, thats a very normal thing for a phone to do ?&lt;/P&gt;</description>
      <pubDate>Thu, 12 May 2016 09:10:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-ssid-need-only-web-auth-mobile-device-need-mac-address/m-p/2911239#M36235</guid>
      <dc:creator>jan.nielsen</dc:creator>
      <dc:date>2016-05-12T09:10:23Z</dc:date>
    </item>
    <item>
      <title>Hi Nielsen,</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-ssid-need-only-web-auth-mobile-device-need-mac-address/m-p/2911240#M36236</link>
      <description>&lt;P&gt;Hi Nielsen,&lt;/P&gt;
&lt;P&gt;I tried one by one both condition in guest rule, one condition at a time.&lt;/P&gt;
&lt;P&gt;Whenever, I am configuring the above condition then mobile phone also getting rejected and guest portal is not getting web redirection.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;What would be the policy sequence, I put Mobile policies first then guest CWA.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Kamlesh&lt;/P&gt;</description>
      <pubDate>Thu, 12 May 2016 09:28:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-ssid-need-only-web-auth-mobile-device-need-mac-address/m-p/2911240#M36236</guid>
      <dc:creator>kamlenegi</dc:creator>
      <dc:date>2016-05-12T09:28:19Z</dc:date>
    </item>
    <item>
      <title>Thats odd, the order of the</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-ssid-need-only-web-auth-mobile-device-need-mac-address/m-p/2911241#M36238</link>
      <description>&lt;P&gt;Thats odd, the order of the rules should not matter when the conditions are specific to an SSID, because only the correct rule will match.&lt;/P&gt;
&lt;P&gt;You should try enabling the guest cwa rule, with just Called-Station-ID CONTAINS "Guest-SSID", and then show take a screenshot of the detail log for the mab requests where you say the mobile gets rejected and guests don't get redirected-&lt;/P&gt;</description>
      <pubDate>Thu, 12 May 2016 15:27:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-ssid-need-only-web-auth-mobile-device-need-mac-address/m-p/2911241#M36238</guid>
      <dc:creator>jan.nielsen</dc:creator>
      <dc:date>2016-05-12T15:27:33Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-ssid-need-only-web-auth-mobile-device-need-mac-address/m-p/2911242#M36239</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Can you drop us a screenshot of your ISE policy rules?&lt;/P&gt;</description>
      <pubDate>Thu, 12 May 2016 15:38:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-ssid-need-only-web-auth-mobile-device-need-mac-address/m-p/2911242#M36239</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2016-05-12T15:38:02Z</dc:date>
    </item>
    <item>
      <title>Hi Nielsen,</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-ssid-need-only-web-auth-mobile-device-need-mac-address/m-p/2911243#M36241</link>
      <description>&lt;P&gt;Hi Nielsen,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Attached is screenshot of policy &amp;amp; live logs.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; line-height: 107%; font-family: 'Calibri',sans-serif;"&gt;When I am changing condition from Wireless_MAB to CONTAINS GUEST-SSID then no one wireless ssid is connecting and match default deny rule. &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; line-height: 107%; font-family: 'Calibri',sans-serif;"&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; line-height: 107%; font-family: 'Calibri',sans-serif;"&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; line-height: 107%; font-family: 'Calibri',sans-serif;"&gt;Thanks &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; line-height: 107%; font-family: 'Calibri',sans-serif;"&gt;Kamlesh&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 13 May 2016 07:00:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-ssid-need-only-web-auth-mobile-device-need-mac-address/m-p/2911243#M36241</guid>
      <dc:creator>kamlenegi</dc:creator>
      <dc:date>2016-05-13T07:00:44Z</dc:date>
    </item>
    <item>
      <title>We need the whole page of the</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-ssid-need-only-web-auth-mobile-device-need-mac-address/m-p/2911244#M36244</link>
      <description>&lt;P&gt;We need the whole page of the details log not just the top of it, if you cant capture that, then you should look for the Called-Station-Id attribute in the detail log of a denied request, it sounds like your WLC is not sending the SSID name in that av-pair, this is configurable in the WLC. That would explain why it's not matching your auth rule conditions&lt;/P&gt;</description>
      <pubDate>Fri, 13 May 2016 07:29:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-ssid-need-only-web-auth-mobile-device-need-mac-address/m-p/2911244#M36244</guid>
      <dc:creator>jan.nielsen</dc:creator>
      <dc:date>2016-05-13T07:29:12Z</dc:date>
    </item>
    <item>
      <title>Hi Nielsen,</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-ssid-need-only-web-auth-mobile-device-need-mac-address/m-p/2911245#M36248</link>
      <description>&lt;P&gt;Hi Nielsen,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I think I am done, now I changed CONTAINS to END-WITH Guest ssid. Then I am able to achieve the requirement. Let me do some more testing, will update you.&lt;/P&gt;
&lt;P&gt;What would be the WLC configuration for av-pair.&lt;/P&gt;
&lt;P&gt;Thanks for your support.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Kamlesh&lt;/P&gt;</description>
      <pubDate>Fri, 13 May 2016 07:56:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-ssid-need-only-web-auth-mobile-device-need-mac-address/m-p/2911245#M36248</guid>
      <dc:creator>kamlenegi</dc:creator>
      <dc:date>2016-05-13T07:56:22Z</dc:date>
    </item>
    <item>
      <title>Hi Nielsen,</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-ssid-need-only-web-auth-mobile-device-need-mac-address/m-p/2911246#M36250</link>
      <description>&lt;P&gt;Hi Nielsen,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;We have done testing in 10-15 mobiles phone and now it is going as per requirement. I think this was not working in "Contains" due to all 4 ssid starting with same name.&lt;/P&gt;
&lt;P&gt;I have done all ssid policy configuration such as:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN style="line-height: normal;"&gt;Rule Name - VIP Wireless&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN style="line-height: normal;"&gt;Conditions - VIP and Radius:Called-Station-ID END-WITH VIP-SSID&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN style="line-height: normal;"&gt;Permissions - PermitAccess&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN style="line-height: normal;"&gt;For guest need to web redirection. &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="line-height: normal;"&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="line-height: normal;"&gt;Now everything is working, thanks for your support Nielsen.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="line-height: normal;"&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="line-height: normal;"&gt;Thanks &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="line-height: normal;"&gt;Kamlesh&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 13 May 2016 10:45:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-ssid-need-only-web-auth-mobile-device-need-mac-address/m-p/2911246#M36250</guid>
      <dc:creator>kamlenegi</dc:creator>
      <dc:date>2016-05-13T10:45:44Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-ssid-need-only-web-auth-mobile-device-need-mac-address/m-p/2911247#M36251</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;In av-pair there is audit session-id, attached is log file.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Kamlesh&lt;/P&gt;</description>
      <pubDate>Fri, 13 May 2016 13:39:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-ssid-need-only-web-auth-mobile-device-need-mac-address/m-p/2911247#M36251</guid>
      <dc:creator>kamlenegi</dc:creator>
      <dc:date>2016-05-13T13:39:08Z</dc:date>
    </item>
    <item>
      <title>Hi</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-guest-ssid-need-only-web-auth-mobile-device-need-mac-address/m-p/2911248#M36252</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Your issue seems to be corrected now.&lt;/P&gt;
&lt;P&gt;Just 1 information: When you have multiple SSID and you want to do different authentication methods, you can activate PolicySet feature. It will allow you to have different authentication and authorization rules depending on your SSIDs.&lt;/P&gt;
&lt;P&gt;With PolicySet, you can differentiate SSIDs by using WLAN-ID as criteria. This WLAN-ID could be seen on your WLC.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;This method is good because you can a better organization view on ISE.&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 13 May 2016 13:39:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-guest-ssid-need-only-web-auth-mobile-device-need-mac-address/m-p/2911248#M36252</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2016-05-13T13:39:09Z</dc:date>
    </item>
  </channel>
</rss>

