<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: restrict AD group on guest self-reg portal with remember me option enabled in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/restrict-ad-group-on-guest-self-reg-portal-with-remember-me/m-p/3769658#M486967</link>
    <description>Which one suits you. Did you look over the options?&lt;BR /&gt;</description>
    <pubDate>Thu, 27 Dec 2018 21:18:16 GMT</pubDate>
    <dc:creator>Jason Kunst</dc:creator>
    <dc:date>2018-12-27T21:18:16Z</dc:date>
    <item>
      <title>restrict AD group on guest self-reg portal with remember me option enabled</title>
      <link>https://community.cisco.com/t5/network-access-control/restrict-ad-group-on-guest-self-reg-portal-with-remember-me/m-p/3766472#M486876</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;I want to restrict AD group (VIPUserMAB) on guest self-reg portal with remember me option enabled; how can i do this?&lt;/P&gt;
&lt;P&gt;is it possible?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-family: inherit;"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="2018-12-19_093123.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/26470i3428FBA2416C1B97/image-size/large?v=v2&amp;amp;px=999" role="button" title="2018-12-19_093123.png" alt="2018-12-19_093123.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Dec 2018 08:41:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/restrict-ad-group-on-guest-self-reg-portal-with-remember-me/m-p/3766472#M486876</guid>
      <dc:creator>Paolo Bratti</dc:creator>
      <dc:date>2018-12-19T08:41:30Z</dc:date>
    </item>
    <item>
      <title>Re: restrict AD group on guest self-reg portal with remember me option enabled</title>
      <link>https://community.cisco.com/t5/network-access-control/restrict-ad-group-on-guest-self-reg-portal-with-remember-me/m-p/3766597#M486961</link>
      <description>Can you please explain the use case in detail ?</description>
      <pubDate>Wed, 19 Dec 2018 12:08:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/restrict-ad-group-on-guest-self-reg-portal-with-remember-me/m-p/3766597#M486961</guid>
      <dc:creator>Surendra</dc:creator>
      <dc:date>2018-12-19T12:08:16Z</dc:date>
    </item>
    <item>
      <title>Re: restrict AD group on guest self-reg portal with remember me option enabled</title>
      <link>https://community.cisco.com/t5/network-access-control/restrict-ad-group-on-guest-self-reg-portal-with-remember-me/m-p/3766805#M486962</link>
      <description>&lt;P&gt;The problem you are going to run into is that the authentication is for the endpoint and not the user since user credentials are not apart of the MAB process.&amp;nbsp; The way you currently have policy configured is to allow any MAC address in the VIPUserMAB endpoint identity group will receive the GuestPermit authorization result (if you were to enable it). There is no username component to the authorization rule and because the use case is wireless MAB, you won't receive a username.&amp;nbsp; Just the MAC address.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;-Tim&lt;/P&gt;</description>
      <pubDate>Wed, 19 Dec 2018 16:51:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/restrict-ad-group-on-guest-self-reg-portal-with-remember-me/m-p/3766805#M486962</guid>
      <dc:creator>Timothy Abbott</dc:creator>
      <dc:date>2018-12-19T16:51:01Z</dc:date>
    </item>
    <item>
      <title>Re: restrict AD group on guest self-reg portal with remember me option enabled</title>
      <link>https://community.cisco.com/t5/network-access-control/restrict-ad-group-on-guest-self-reg-portal-with-remember-me/m-p/3766993#M486964</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/26660"&gt;@Timothy Abbott&lt;/a&gt;&amp;nbsp;is correct. there is no way to mix REMEMBER ME based of MAB endpoint group and Active directory group.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There is a way to do it but its a little crude.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Check out special flows&lt;/P&gt;
&lt;P&gt;&lt;A href="http://cs.co/ise-guest" target="_blank"&gt;http://cs.co/ise-guest&lt;/A&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://community.cisco.com/t5/identity-services-engine-ise/ise-cwa-portal-mapping-ad-group-to-endpoint-group/m-p/3554392" target="_blank"&gt;Re: ISE map CWA AD group to Endpoint Group&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://community.cisco.com/t5/identity-services-engine-ise/guest-portal-how-to-restrict-employee-access-to-only-specific-ad/m-p/3460223" target="_blank"&gt;Guest portal: How to restrict employee access to only specific AD group?&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Wed, 19 Dec 2018 23:19:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/restrict-ad-group-on-guest-self-reg-portal-with-remember-me/m-p/3766993#M486964</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-12-19T23:19:30Z</dc:date>
    </item>
    <item>
      <title>Re: restrict AD group on guest self-reg portal with remember me option enabled</title>
      <link>https://community.cisco.com/t5/network-access-control/restrict-ad-group-on-guest-self-reg-portal-with-remember-me/m-p/3769376#M486966</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/199790"&gt;@Jason Kunst&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/26660"&gt;@Timothy Abbott&lt;/a&gt;&amp;nbsp;is correct. there is no way to mix REMEMBER ME based of MAB endpoint group and Active directory group.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There is a way to do it but its a little crude.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;which one?&lt;/P&gt;</description>
      <pubDate>Thu, 27 Dec 2018 07:59:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/restrict-ad-group-on-guest-self-reg-portal-with-remember-me/m-p/3769376#M486966</guid>
      <dc:creator>Paolo Bratti</dc:creator>
      <dc:date>2018-12-27T07:59:04Z</dc:date>
    </item>
    <item>
      <title>Re: restrict AD group on guest self-reg portal with remember me option enabled</title>
      <link>https://community.cisco.com/t5/network-access-control/restrict-ad-group-on-guest-self-reg-portal-with-remember-me/m-p/3769658#M486967</link>
      <description>Which one suits you. Did you look over the options?&lt;BR /&gt;</description>
      <pubDate>Thu, 27 Dec 2018 21:18:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/restrict-ad-group-on-guest-self-reg-portal-with-remember-me/m-p/3769658#M486967</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-12-27T21:18:16Z</dc:date>
    </item>
  </channel>
</rss>

