<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi Jan, in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/self-registering-guest-flow-re-authentication/m-p/2907838#M36255</link>
    <description>&lt;P&gt;Hi Jan,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Sorry for the delay.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks for confirming &amp;nbsp;- makes sense.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Is there a direct relation between user &amp;nbsp;- &amp;nbsp;device? Eg. If a user is deleted - are all his registered&amp;nbsp;devices deleted?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Restricted access &amp;nbsp;(eg. certain hours) is&amp;nbsp;not possible with this kind of flow I suppose. --&amp;gt; authz needed to be based on guest type?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thx&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 17 May 2016 14:10:04 GMT</pubDate>
    <dc:creator>davy.timmermans</dc:creator>
    <dc:date>2016-05-17T14:10:04Z</dc:date>
    <item>
      <title>self registering guest flow - re-authentication?</title>
      <link>https://community.cisco.com/t5/network-access-control/self-registering-guest-flow-re-authentication/m-p/2907836#M36253</link>
      <description>&lt;P&gt;In all&amp;nbsp;examples of device self registration - authentication seems to be done only after the coa after registration?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;auth:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;mab : user not found - continue&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;authz:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;if guestendpoint and ssid 'guest' =&amp;gt; accept&lt;/P&gt;
&lt;P&gt;if &amp;nbsp;ssid 'guest' : accept + cwa&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thus once a guest device is registered - it's not required to authenticicate&amp;nbsp;anymore? Unless the endpoint is deleted?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 06:45:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/self-registering-guest-flow-re-authentication/m-p/2907836#M36253</guid>
      <dc:creator>davy.timmermans</dc:creator>
      <dc:date>2019-03-11T06:45:40Z</dc:date>
    </item>
    <item>
      <title>Not exactly, it's correct</title>
      <link>https://community.cisco.com/t5/network-access-control/self-registering-guest-flow-re-authentication/m-p/2907837#M36254</link>
      <description>&lt;P&gt;Not exactly, it's correct that the guest will only use a browser to sign in the first time, but if they get disconnected, they will instead be authenticated by their mac address. The guest device's mac address will be placed in the endpoint group you told it to in the guest config. This group contains the mac address of authorized guests, and should be purged at some set interval, to remove those devices access to the guest network.&lt;/P&gt;</description>
      <pubDate>Thu, 12 May 2016 15:36:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/self-registering-guest-flow-re-authentication/m-p/2907837#M36254</guid>
      <dc:creator>jan.nielsen</dc:creator>
      <dc:date>2016-05-12T15:36:52Z</dc:date>
    </item>
    <item>
      <title>Hi Jan,</title>
      <link>https://community.cisco.com/t5/network-access-control/self-registering-guest-flow-re-authentication/m-p/2907838#M36255</link>
      <description>&lt;P&gt;Hi Jan,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Sorry for the delay.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks for confirming &amp;nbsp;- makes sense.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Is there a direct relation between user &amp;nbsp;- &amp;nbsp;device? Eg. If a user is deleted - are all his registered&amp;nbsp;devices deleted?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Restricted access &amp;nbsp;(eg. certain hours) is&amp;nbsp;not possible with this kind of flow I suppose. --&amp;gt; authz needed to be based on guest type?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thx&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 17 May 2016 14:10:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/self-registering-guest-flow-re-authentication/m-p/2907838#M36255</guid>
      <dc:creator>davy.timmermans</dc:creator>
      <dc:date>2016-05-17T14:10:04Z</dc:date>
    </item>
  </channel>
</rss>

