<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic WLC + ISE Web Authentification in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/wlc-ise-web-authentification/m-p/2993780#M38697</link>
    <description>&lt;P&gt;I have configured the Web Authentification on the ISE which connects to the WLC.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My intention is it to create a Guest Portal which requires a username and a password on a web login page. I have managed to get all this working.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/saf.png" class="migrated-markup-image" /&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;When a new client connects to the guest SSID which I have created, the user "must" enter username and password which was created by the sponsor.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;The Problem:&lt;/STRONG&gt;&amp;nbsp;Once I have used a client, went through all the stages (web auth, username password, successfully connected to the internet)...The web login page never returns for the same client. The WLC registers the clients (Samsung Tablet) stores the information.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;First time using the SSID:&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/12_15.png" class="migrated-markup-image" /&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Second time using same SSID:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/23_5.png" class="migrated-markup-image" /&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;What I need is for the Centralized Web Authentication to always ask for the username and password after disconnecting from the network, whether its a returning client or a new client.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;My Policy set:&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/saf2.png" class="migrated-markup-image" /&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 07:00:08 GMT</pubDate>
    <dc:creator>islow1303</dc:creator>
    <dc:date>2019-03-11T07:00:08Z</dc:date>
    <item>
      <title>WLC + ISE Web Authentification</title>
      <link>https://community.cisco.com/t5/network-access-control/wlc-ise-web-authentification/m-p/2993780#M38697</link>
      <description>&lt;P&gt;I have configured the Web Authentification on the ISE which connects to the WLC.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My intention is it to create a Guest Portal which requires a username and a password on a web login page. I have managed to get all this working.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/saf.png" class="migrated-markup-image" /&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;When a new client connects to the guest SSID which I have created, the user "must" enter username and password which was created by the sponsor.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;The Problem:&lt;/STRONG&gt;&amp;nbsp;Once I have used a client, went through all the stages (web auth, username password, successfully connected to the internet)...The web login page never returns for the same client. The WLC registers the clients (Samsung Tablet) stores the information.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;First time using the SSID:&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/12_15.png" class="migrated-markup-image" /&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Second time using same SSID:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/23_5.png" class="migrated-markup-image" /&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;What I need is for the Centralized Web Authentication to always ask for the username and password after disconnecting from the network, whether its a returning client or a new client.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;My Policy set:&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/saf2.png" class="migrated-markup-image" /&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 07:00:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wlc-ise-web-authentification/m-p/2993780#M38697</guid>
      <dc:creator>islow1303</dc:creator>
      <dc:date>2019-03-11T07:00:08Z</dc:date>
    </item>
    <item>
      <title>There is no way to cache</title>
      <link>https://community.cisco.com/t5/network-access-control/wlc-ise-web-authentification/m-p/2993781#M38698</link>
      <description>&lt;P&gt;There is no way to cache guest credentials with ISE because all of the guest logins are session based (based on the specific Radius session on the WLC or Switch).&amp;nbsp; The only real way to get around guests having to enter their credentials on each new session is via device registration &amp;amp; it seems you're configured for THAT too.&lt;BR /&gt;&lt;BR /&gt;Using device registration you can require the guests to log in the first time, their device will be registered (to GuestEndpoints for example), and then your post-CWA rule can be based on membership in GuestEndpoints.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is now completely up to, how purge rule is configured to clear out that registered endpoints. (minimum of 1 day in ISE.) Once the purge happens, the client would be required to log in again. You need to check how this setting is configured on your ISE.&lt;/P&gt;
&lt;P&gt;Rgds,&lt;/P&gt;
&lt;P&gt;Jatin&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;~ Do rate helpful posts.&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Aug 2016 13:45:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wlc-ise-web-authentification/m-p/2993781#M38698</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2016-08-17T13:45:33Z</dc:date>
    </item>
    <item>
      <title>I slightly understand where</title>
      <link>https://community.cisco.com/t5/network-access-control/wlc-ise-web-authentification/m-p/2993782#M38699</link>
      <description>&lt;P&gt;I slightly understand where you coming from...purge rule = 1 day ...&lt;/P&gt;
&lt;P&gt;Device registration = enable&lt;/P&gt;
&lt;P&gt;Yet it doesn't quite solve my problem...&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Major Issue:&lt;/STRONG&gt; What is causing my clients (which I can see under Identities -&amp;gt; EndPoints)&amp;nbsp;to be able to connect to the WLAN SSID Guests even though I have suspended all the guest accounts on my sponsor portal?&lt;/P&gt;
&lt;P&gt;Is it the Policy? Is it the ACL? Is it the guest type settings?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/guest.png" class="migrated-markup-image" /&gt;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/guest_report_1.png" class="migrated-markup-image" /&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Also when a client who was before connected to the Guest SSID, Username is no longer known because the web_authentication doesn't appear so the client just connects and can start surfing...which is not how I imagine a guest access...&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/wlc_report_0.png" class="migrated-markup-image" /&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;As soon as a client (iPhone, Samsung Tablet, Windows Laptop etc.)&amp;nbsp;gets assigned to a Identity Group in ISE (Workstation, Profiled, GuestEndPoints) the Web Authentication gets ignored???&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;When I look at the Authentication report details (Username is shown as the Mac Address instead of the generated Guest Username...?) &amp;nbsp;| guest username: phka-xxxx |&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/auth_det.png" class="migrated-markup-image" /&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Is the Autorisation part getting ignored now that the clients became part of Identity groups?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I cannot figure out where the problem actually lies because (must be something on the ISE cuz the WLC settings seem fine according to the cisco Documentations)&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Hope you can help further...&lt;/P&gt;</description>
      <pubDate>Wed, 17 Aug 2016 15:46:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wlc-ise-web-authentification/m-p/2993782#M38699</guid>
      <dc:creator>islow1303</dc:creator>
      <dc:date>2016-08-17T15:46:32Z</dc:date>
    </item>
    <item>
      <title>Managed to solve my Problem!</title>
      <link>https://community.cisco.com/t5/network-access-control/wlc-ise-web-authentification/m-p/2993783#M38700</link>
      <description>&lt;P&gt;Managed to solve my Problem! If anybody has a similar issue feel free to ask...&lt;/P&gt;</description>
      <pubDate>Fri, 26 Aug 2016 10:05:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wlc-ise-web-authentification/m-p/2993783#M38700</guid>
      <dc:creator>islow1303</dc:creator>
      <dc:date>2016-08-26T10:05:33Z</dc:date>
    </item>
    <item>
      <title>Hi - old post, but would like</title>
      <link>https://community.cisco.com/t5/network-access-control/wlc-ise-web-authentification/m-p/2993784#M38701</link>
      <description>&lt;P&gt;Hi - old post, but would like to know how you solved this issue?&lt;/P&gt;
&lt;P&gt;Having same challenge. Suspend user account, guest device is registered, and device auth rule still authorizes device.&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Aug 2017 10:26:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wlc-ise-web-authentification/m-p/2993784#M38701</guid>
      <dc:creator>Thomas Husum</dc:creator>
      <dc:date>2017-08-15T10:26:42Z</dc:date>
    </item>
    <item>
      <title>Re: Hi - old post, but would like</title>
      <link>https://community.cisco.com/t5/network-access-control/wlc-ise-web-authentification/m-p/3173824#M38703</link>
      <description>&lt;P&gt;Hi Thomas,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Once the guest is authenticated, the ISE will go through a second authorization.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In this second authorization, we need to return a profile so the guest is permitted access to the network. &amp;nbsp;I used usecase: "Guestflow" to easily match the second authorization.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is my Authorization Policy (which has been working ever since)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-right" image-alt="ise-guest-authz.png" style="width: 803px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/139iBD83F57DE2508EF5/image-size/large?v=v2&amp;amp;px=999" role="button" title="ise-guest-authz.png" alt="ise-guest-authz.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PS: Please give Feedback if this was helpful.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Tue, 22 Aug 2017 06:32:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/wlc-ise-web-authentification/m-p/3173824#M38703</guid>
      <dc:creator>islow1303</dc:creator>
      <dc:date>2017-08-22T06:32:34Z</dc:date>
    </item>
  </channel>
</rss>

