<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Sponsor mail and AD Existence in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/sponsor-mail-and-ad-existence/m-p/4027018#M442585</link>
    <description>&lt;P&gt;Hi Team,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have experiencing some problems in ISE deployment, basically about the sponsor mail.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We configured for guests "Person being visited" so its mandatory to add the mail of the sponsored visited.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The issue comes when ISE is permitting send mail to anyone (if its in AD or not), this is a normal behavior? AFAIK ISE checks inside AD if the email address exists, if not exists the mail isn't sended.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How can we force (restrict) that only people inside sponsor group (AD mapped group) have the opportunity of receive mail?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, i.e the company domain is example1.com, inside AD Group a sponsor with mail account user1@example1.com, if I fill the guest portal with email to person being visited with user2@example2.com, the mail is sended (example2.com is outside our company).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you in advance,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 10 Feb 2020 18:35:24 GMT</pubDate>
    <dc:creator>nanu</dc:creator>
    <dc:date>2020-02-10T18:35:24Z</dc:date>
    <item>
      <title>Sponsor mail and AD Existence</title>
      <link>https://community.cisco.com/t5/network-access-control/sponsor-mail-and-ad-existence/m-p/4027018#M442585</link>
      <description>&lt;P&gt;Hi Team,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have experiencing some problems in ISE deployment, basically about the sponsor mail.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We configured for guests "Person being visited" so its mandatory to add the mail of the sponsored visited.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The issue comes when ISE is permitting send mail to anyone (if its in AD or not), this is a normal behavior? AFAIK ISE checks inside AD if the email address exists, if not exists the mail isn't sended.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How can we force (restrict) that only people inside sponsor group (AD mapped group) have the opportunity of receive mail?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, i.e the company domain is example1.com, inside AD Group a sponsor with mail account user1@example1.com, if I fill the guest portal with email to person being visited with user2@example2.com, the mail is sended (example2.com is outside our company).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you in advance,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Feb 2020 18:35:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/sponsor-mail-and-ad-existence/m-p/4027018#M442585</guid>
      <dc:creator>nanu</dc:creator>
      <dc:date>2020-02-10T18:35:24Z</dc:date>
    </item>
    <item>
      <title>Re: Sponsor mail and AD Existence</title>
      <link>https://community.cisco.com/t5/network-access-control/sponsor-mail-and-ad-existence/m-p/4027063#M442586</link>
      <description>&lt;P&gt;&lt;A href="https://community.cisco.com/t5/security-documents/ise-guest-self-registration-restrict-validate-the-person-being/ta-p/3637001" target="_blank"&gt;https://community.cisco.com/t5/security-documents/ise-guest-self-registration-restrict-validate-the-person-being/ta-p/3637001&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Feb 2020 19:34:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/sponsor-mail-and-ad-existence/m-p/4027063#M442586</guid>
      <dc:creator>Parag Mahajan</dc:creator>
      <dc:date>2020-02-10T19:34:30Z</dc:date>
    </item>
    <item>
      <title>Re: Sponsor mail and AD Existence</title>
      <link>https://community.cisco.com/t5/network-access-control/sponsor-mail-and-ad-existence/m-p/4027069#M442587</link>
      <description>&lt;P&gt;Hi Parag,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It isn't checked in AD?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you,&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Feb 2020 19:43:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/sponsor-mail-and-ad-existence/m-p/4027069#M442587</guid>
      <dc:creator>nanu</dc:creator>
      <dc:date>2020-02-10T19:43:00Z</dc:date>
    </item>
    <item>
      <title>Re: Sponsor mail and AD Existence</title>
      <link>https://community.cisco.com/t5/network-access-control/sponsor-mail-and-ad-existence/m-p/4027150#M442588</link>
      <description>&lt;P&gt;No, ISE does not check the email account specified as the person being visited against AD.&lt;/P&gt;
&lt;P&gt;You might have a look at the following post for additional options on limiting the email addresses available:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/security-documents/ise-guest-self-registration-person-being-visited-sponsor-choose/ta-p/3636453" target="_self"&gt;ISE Guest Self-Registration person being visited (sponsor) choose list or assign&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;Greg&lt;/P&gt;</description>
      <pubDate>Mon, 10 Feb 2020 22:51:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/sponsor-mail-and-ad-existence/m-p/4027150#M442588</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2020-02-10T22:51:13Z</dc:date>
    </item>
    <item>
      <title>Re: Sponsor mail and AD Existence</title>
      <link>https://community.cisco.com/t5/network-access-control/sponsor-mail-and-ad-existence/m-p/4027606#M442589</link>
      <description>&lt;P&gt;That's OK, I will apply one of your recommendations,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2020 15:13:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/sponsor-mail-and-ad-existence/m-p/4027606#M442589</guid>
      <dc:creator>nanu</dc:creator>
      <dc:date>2020-02-11T15:13:55Z</dc:date>
    </item>
    <item>
      <title>Re: Sponsor mail and AD Existence</title>
      <link>https://community.cisco.com/t5/network-access-control/sponsor-mail-and-ad-existence/m-p/4032093#M442590</link>
      <description>&lt;P&gt;Hi Greg,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I want to add another last question to this topic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Actually we solve the domain issue, so only mails to company users will be sended.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But, how can limit inside the company who can receive mails?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regarding these post looks like ISE is checking against AD:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.cisco.com/t5/identity-services-engine-ise/ise-2-2-guest-features-quot-supported-with-internal-ad-ldap/td-p/3601338" target="_blank"&gt;https://community.cisco.com/t5/identity-services-engine-ise/ise-2-2-guest-features-quot-supported-with-internal-ad-ldap/td-p/3601338&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also this bug:&lt;/P&gt;&lt;P&gt;&lt;A href="https://quickview.cloudapps.cisco.com/quickview/bug/CSCve76134" target="_blank"&gt;https://quickview.cloudapps.cisco.com/quickview/bug/CSCve76134&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Definetely:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-2/admin_guide/b_ise_admin_guide_22/b_ise_admin_guide_22_chapter_01110.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/2-2/admin_guide/b_ise_admin_guide_22/b_ise_admin_guide_22_chapter_01110.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"If the email address for the sponsor is not for a valid sponsor, the approval email is not sent."&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(How ISE can validate if isn't valid Sponsor if not check against AD)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, what do you think?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;</description>
      <pubDate>Wed, 19 Feb 2020 09:42:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/sponsor-mail-and-ad-existence/m-p/4032093#M442590</guid>
      <dc:creator>nanu</dc:creator>
      <dc:date>2020-02-19T09:42:04Z</dc:date>
    </item>
    <item>
      <title>Re: Sponsor mail and AD Existence</title>
      <link>https://community.cisco.com/t5/network-access-control/sponsor-mail-and-ad-existence/m-p/4032550#M442591</link>
      <description>&lt;P&gt;As per Jason Kunst's post, "NO there is no lookup of the person being visited less using single click"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;* I expect this is meant to be "unless using single click"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm familiar with the enhancement bug you referenced and I'm not aware that this enhancement has been implemented in any current versions of ISE. From prior customer engagements, I have not seen that ISE does a lookup against AD so we have used the 'choose list' option that I referenced in my previous response as a workaround.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/199790"&gt;@Jason Kunst&lt;/a&gt;, can you confirm the current capabilities around AD/LDAP lookups of 'person being visited' for self-registered Guests?&lt;/P&gt;</description>
      <pubDate>Wed, 19 Feb 2020 20:25:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/sponsor-mail-and-ad-existence/m-p/4032550#M442591</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2020-02-19T20:25:19Z</dc:date>
    </item>
  </channel>
</rss>

