<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE 2.3 - Guest Portal not working with AD in portal sequence in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-2-3-guest-portal-not-working-with-ad-in-portal-sequence/m-p/3869499#M441530</link>
    <description>&lt;P&gt;All due respect, I've read through that guide half a dozen times or so and it is most definitely not a one-size-fits-all solution.&amp;nbsp; I'm dealing with a long-deployed wireless environment and an ISE environment that's a few years old.&amp;nbsp; I asked a very specific question (the third one thus far in this forum) and again have been met with this easily found PDF prescriptive deployment guide which would be awesome if I had nothing in place and was deploying for the first time.&amp;nbsp; That's not the case.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"keeping it simple" with that guide would require essentially tearing out what we already have and redoing it.&amp;nbsp; The section from the guide I linked to in my original post indicates simply adding an identity source to the existing sequence should work for the situation I describe, but it's not working.&lt;/P&gt;</description>
    <pubDate>Fri, 07 Jun 2019 14:16:28 GMT</pubDate>
    <dc:creator>jcatanzaro9</dc:creator>
    <dc:date>2019-06-07T14:16:28Z</dc:date>
    <item>
      <title>ISE 2.3 - Guest Portal not working with AD in portal sequence</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-guest-portal-not-working-with-ad-in-portal-sequence/m-p/3869159#M441528</link>
      <description>&lt;P&gt;Working on trying to use the guest portal to allow employees to authenticate with AD credentials for same level of access as sponsored guest users (internet only).&amp;nbsp; Guest portal configured to use sequence with Guest Users first, followed by CORP (AD).&amp;nbsp; Going off of this guide:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/solutions/Enterprise/Borderless_Networks/Unified_Access/BYOD_Design_Guide/BYOD_Basic_Access_Use_Case.html" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/td/docs/solutions/Enterprise/Borderless_Networks/Unified_Access/BYOD_Design_Guide/BYOD_Basic_Access_Use_Case.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Section:&amp;nbsp;&lt;/P&gt;&lt;H3&gt;Extending Web Auth to Use Microsoft AD when Authenticating Employees with Personal Devices&lt;/H3&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Seems to be everything is correct but the authentication fails when using my AD creds in the guest portal no matter which AD group I call out in the AuthZ rule.&amp;nbsp; AuthC rule is using wireless MAB, AuthZ says if you come in through guest flow, called station 'Guest' and CORP:External Groups equals (desired AD grouop) then AuthZ profile with Access-Accept and InternetOnly Airespace ACL.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Every time i try it says authentication failed, but I can't seem to find any logging on the portal authentications to indicate why this is failing.&amp;nbsp; Has anyone set this up this way and if so where am I going wrong?&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jun 2019 20:52:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-guest-portal-not-working-with-ad-in-portal-sequence/m-p/3869159#M441528</guid>
      <dc:creator>jcatanzaro9</dc:creator>
      <dc:date>2019-06-06T20:52:55Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.3 - Guest Portal not working with AD in portal sequence</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-guest-portal-not-working-with-ad-in-portal-sequence/m-p/3869170#M441529</link>
      <description>I would recommend keeping it simple and starting with this guide - &lt;A href="https://community.cisco.com/t5/security-documents/ise-guest-access-prescriptive-deployment-guide/ta-p/3640475" target="_blank"&gt;https://community.cisco.com/t5/security-documents/ise-guest-access-prescriptive-deployment-guide/ta-p/3640475&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Also under &lt;A href="http://cs.co/ise-guest" target="_blank"&gt;http://cs.co/ise-guest&lt;/A&gt; there are other examples talking about employee internet access.&lt;BR /&gt;</description>
      <pubDate>Thu, 06 Jun 2019 21:29:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-guest-portal-not-working-with-ad-in-portal-sequence/m-p/3869170#M441529</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2019-06-06T21:29:47Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.3 - Guest Portal not working with AD in portal sequence</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-guest-portal-not-working-with-ad-in-portal-sequence/m-p/3869499#M441530</link>
      <description>&lt;P&gt;All due respect, I've read through that guide half a dozen times or so and it is most definitely not a one-size-fits-all solution.&amp;nbsp; I'm dealing with a long-deployed wireless environment and an ISE environment that's a few years old.&amp;nbsp; I asked a very specific question (the third one thus far in this forum) and again have been met with this easily found PDF prescriptive deployment guide which would be awesome if I had nothing in place and was deploying for the first time.&amp;nbsp; That's not the case.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"keeping it simple" with that guide would require essentially tearing out what we already have and redoing it.&amp;nbsp; The section from the guide I linked to in my original post indicates simply adding an identity source to the existing sequence should work for the situation I describe, but it's not working.&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jun 2019 14:16:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-guest-portal-not-working-with-ad-in-portal-sequence/m-p/3869499#M441530</guid>
      <dc:creator>jcatanzaro9</dc:creator>
      <dc:date>2019-06-07T14:16:28Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.3 - Guest Portal not working with AD in portal sequence</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-guest-portal-not-working-with-ad-in-portal-sequence/m-p/3869531#M441531</link>
      <description>The simple examples there in the guide of the policies should be able to be tweaked with what you have going on.&lt;BR /&gt;&lt;BR /&gt;The Default identity source sequence and guest portal works with AD authentication. Perhaps you start by not calling out the group?  The following works with AD login with guest identity source sequence mapped to AD.&lt;BR /&gt;&lt;BR /&gt;If guest flow then permit access&lt;BR /&gt;if MAB then redirect to portal&lt;BR /&gt;&lt;BR /&gt;What release you're on, show pictures of your authentication and authorization polices. Any associated configurations related? Perhaps the AD groups you have called out under External Identities?&lt;BR /&gt;Under &lt;A href="http://cs.co/ise-guest" target="_blank"&gt;http://cs.co/ise-guest&lt;/A&gt; there are several employee mentions perhaps one fits your specifics or is close?&lt;BR /&gt;The guide on page 21 step 4 shows a sample authorization policy which works with GUEST and AD login.&lt;BR /&gt;If all else fails work with the TAC, information on how to get help in the community is at &lt;A href="http://cs.co/ise-help" target="_blank"&gt;http://cs.co/ise-help&lt;/A&gt;. trying to help we need info like:&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Fri, 07 Jun 2019 14:59:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-guest-portal-not-working-with-ad-in-portal-sequence/m-p/3869531#M441531</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2019-06-07T14:59:55Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.3 - Guest Portal not working with AD in portal sequence</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-guest-portal-not-working-with-ad-in-portal-sequence/m-p/3869547#M441532</link>
      <description>So the issue is when using AD creds I get authentication failed on the portal. Only problem is i don't see the failed authentications anywhere in the live log or reports to figure out *what* is failing.&lt;BR /&gt;&lt;BR /&gt;Version is 2.3 as the title states, not positive which patch right now. One AuthC policy if Wireless-MAB then Guest-Portal-Sequence for identity. AuthZ policies configured as outlined in that guide, the current working guest authZ profile is if MAB AND guest WLAN-ID then Portal Redirect, and then authZ for authenticated user is if use-case equal guest flow AND called station is Guest, AND identity group is guest-endpoints, then permit access.&lt;BR /&gt;&lt;BR /&gt;One piece that I don't have turned on is "apply cisco ISE default settings" and the NAC state is None on that particular WLAN. Like I said that's working so I'm leary of making changes to it and would probably prefer to use a separate SSID for employee devices but redirect to the same portal.</description>
      <pubDate>Fri, 07 Jun 2019 15:16:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-guest-portal-not-working-with-ad-in-portal-sequence/m-p/3869547#M441532</guid>
      <dc:creator>jcatanzaro9</dc:creator>
      <dc:date>2019-06-07T15:16:08Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.3 - Guest Portal not working with AD in portal sequence</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-guest-portal-not-working-with-ad-in-portal-sequence/m-p/3869628#M441533</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/206092"&gt;@jcatanzaro9&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;So the issue is when using AD creds I get authentication failed on the portal. Only problem is i don't see the failed authentications anywhere in the live log or reports to figure out *what* is failing.&lt;BR /&gt;&lt;BR /&gt;JAK &amp;gt; i am not sure either because with my setup if i put in wrong username password for AD it will fail and show me that in Operations radius live logs&lt;BR /&gt;&lt;BR /&gt;Version is 2.3 as the title states, not positive which patch right now. One AuthC policy if Wireless-MAB then Guest-Portal-Sequence for identity. AuthZ policies configured as outlined in that guide, the current working guest authZ profile is if MAB AND guest WLAN-ID then Portal Redirect, and then authZ for authenticated user is if use-case equal guest flow AND called station is Guest, AND identity group is guest-endpoints, then permit access.&lt;BR /&gt;&lt;BR /&gt;JAK &amp;gt; can you fallback for an authc condition that allows all identity sources to check if that's the issue? Your authz looks correct from what you're sharing, a picture would be nice&lt;BR /&gt;&lt;BR /&gt;One piece that I don't have turned on is "apply cisco ISE default settings" and the NAC state is None on that particular WLAN. Like I said that's working so I'm leary of making changes to it and would probably prefer to use a separate SSID for employee devices but redirect to the same portal.
&lt;P class="1559927286291"&gt;JAK &amp;gt; wouldn't mess with that, if guest database works then you have validated the whole wireless flow.&amp;nbsp;&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Please reach out to TAC for further troubleshooting and assistance, not sure what's happening at this point. Perhaps your external identity source is not setup with the correct groups? Did you try the internal database to see if that works with internal account? Does AD work with wireless dot1x SSID?&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jun 2019 17:11:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-guest-portal-not-working-with-ad-in-portal-sequence/m-p/3869628#M441533</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2019-06-07T17:11:53Z</dc:date>
    </item>
  </channel>
</rss>

