<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Send User-Name back to NAD in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/send-user-name-back-to-nad/m-p/3731525#M489178</link>
    <description>&lt;P&gt;oh that's brilliant!&amp;nbsp; Thanks you've just taught me something new in ISE.&amp;nbsp; I guess in hindsight it's quite obvious, but I never thought of trying to overwrite the User-Name (not that I could, because it's IN only).&amp;nbsp; But there're a lot of other dictionary attributes that can be utilised there - might be something I need to keep in mind.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks for that useful pointer.&lt;/P&gt;</description>
    <pubDate>Wed, 24 Oct 2018 11:22:21 GMT</pubDate>
    <dc:creator>Arne Bier</dc:creator>
    <dc:date>2018-10-24T11:22:21Z</dc:date>
    <item>
      <title>Send User-Name back to NAD</title>
      <link>https://community.cisco.com/t5/network-access-control/send-user-name-back-to-nad/m-p/3731444#M489093</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As far as I know, most NADs (ex.: WLC, Catalysts) accept the "User-Name" back from the RADIUS server.&lt;/P&gt;
&lt;P&gt;I'm currently using this, with my current in-house built RADIUS, to send the real user to the WLC when doing MAB.&lt;/P&gt;
&lt;P&gt;So, a user registers it's device by MAC, the NAD makes the request using MAC address but get's back the real name. So, when I go to the WLC page I can see the real user, not the mac.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Unfortunately ISE seems to set the User-Name as Input only (Direction = IN), so I can't send it back on Access-Accept, and as far as I can see I can't edit the dictionary entry because it's a default one.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How can I overcome this problem?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 24 Oct 2018 09:22:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/send-user-name-back-to-nad/m-p/3731444#M489093</guid>
      <dc:creator>Ricardo T Duarte</dc:creator>
      <dc:date>2018-10-24T09:22:03Z</dc:date>
    </item>
    <item>
      <title>Re: Send User-Name back to NAD</title>
      <link>https://community.cisco.com/t5/network-access-control/send-user-name-back-to-nad/m-p/3731484#M489097</link>
      <description>&lt;P style="text-align: justify;"&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/99094"&gt;@Ricardo T Duarte&lt;/a&gt;&amp;nbsp;- amen brother!&amp;nbsp; that's the feature I've also been looking for and waitng for in ISE 2.4 but it never made it. It's such a trivial request too.&amp;nbsp; Any radius server should be able to do this.&amp;nbsp; Lack of this feature is also causing me pain with my MAB Remember Me call flows.&amp;nbsp;&lt;/P&gt;
&lt;P style="text-align: justify;"&gt;I was doing exactly the same thing with Cisco Acces Registrar (but there I had the power of tcl scripting to add almost unlimited features to the product - attribute manpulation was the most important and most powerful feature of this product - no need to wait for a BU to "introduce new features"!!!).&amp;nbsp; One of my wishes for ISE is that they open the product up to allow scripting points.&amp;nbsp; So that we can interact at various points of the packet processing.&amp;nbsp; Imagine what we could do with this product!&lt;/P&gt;
&lt;P style="text-align: justify;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="text-align: justify;"&gt;if you can add your weight to the discussion then that would be amazing.&amp;nbsp; I think Cisco prefers you send product enhancements via the ISE tool itself ("Feedack" in the Help page) - but not sure where that lands up.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Oct 2018 10:20:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/send-user-name-back-to-nad/m-p/3731484#M489097</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2018-10-24T10:20:34Z</dc:date>
    </item>
    <item>
      <title>Re: Send User-Name back to NAD</title>
      <link>https://community.cisco.com/t5/network-access-control/send-user-name-back-to-nad/m-p/3731490#M489114</link>
      <description>Agree also see &lt;A href="https://community.cisco.com/t5/security-documents/ise-2-3-remember-me-guest-using-guest-endpoint-group-logging/ta-p/3641150" target="_blank"&gt;https://community.cisco.com/t5/security-documents/ise-2-3-remember-me-guest-using-guest-endpoint-group-logging/ta-p/3641150&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;There is a defect there about sending username. Please provide this in your feedback&lt;BR /&gt;</description>
      <pubDate>Wed, 24 Oct 2018 10:26:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/send-user-name-back-to-nad/m-p/3731490#M489114</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-10-24T10:26:25Z</dc:date>
    </item>
    <item>
      <title>Re: Send User-Name back to NAD</title>
      <link>https://community.cisco.com/t5/network-access-control/send-user-name-back-to-nad/m-p/3731502#M489131</link>
      <description>&lt;P&gt;How hard can it be for Cisco to go to the dictionary and set the direction to "BOTH"...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I miss ClearPass. It allowed me to build my responses&amp;nbsp;combining multiple attributes, that could come from multiple sources.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Oct 2018 10:57:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/send-user-name-back-to-nad/m-p/3731502#M489131</guid>
      <dc:creator>Ricardo T Duarte</dc:creator>
      <dc:date>2018-10-24T10:57:44Z</dc:date>
    </item>
    <item>
      <title>Re: Send User-Name back to NAD</title>
      <link>https://community.cisco.com/t5/network-access-control/send-user-name-back-to-nad/m-p/3731509#M489148</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/99094"&gt;@Ricardo T Duarte&lt;/a&gt;&amp;nbsp;- let's say Cisco made it direction = BOTH - what would you do next?&amp;nbsp; I am interested to know what your approach would be.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;cheers&lt;/P&gt;</description>
      <pubDate>Wed, 24 Oct 2018 11:02:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/send-user-name-back-to-nad/m-p/3731509#M489148</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2018-10-24T11:02:24Z</dc:date>
    </item>
    <item>
      <title>Re: Send User-Name back to NAD</title>
      <link>https://community.cisco.com/t5/network-access-control/send-user-name-back-to-nad/m-p/3731520#M489166</link>
      <description>&lt;P&gt;Scenario&amp;nbsp;1 - ISE standalone&lt;/P&gt;
&lt;P&gt;Advanced Attributes&lt;/P&gt;
&lt;P&gt;\ User-Name&amp;nbsp;= PortalUser&lt;/P&gt;
&lt;P&gt;would prefer not to have&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/38580"&gt;@domain&lt;/a&gt; on the PortalUser, but that would already be something.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Scenario&amp;nbsp;2 - External Database&lt;/P&gt;
&lt;P&gt;I also have my own external mysql database that has MAC addresses and UserNames that registered them&lt;/P&gt;
&lt;P&gt;Advanced Attributes&lt;/P&gt;
&lt;P&gt;\ User-Name&amp;nbsp;=&amp;nbsp;Username (from External DB)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Scenario 3 - Passive Id&lt;/P&gt;
&lt;P&gt;Advanced Attributes&lt;/P&gt;
&lt;P&gt;\ User-Name&amp;nbsp;=&amp;nbsp;Username (from Passive Id)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm assuming ISE does expand those values to their values, and will not put a "Username" word there.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would also then use this to update my firewall IP-to-User mapping, by using a accounting proxy in-between ISE and NAD.&lt;/P&gt;
&lt;P&gt;Currently I have to rely on a in-house built pxgrid solution that subscribe&amp;nbsp;for session info and then get's the username.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Oct 2018 11:28:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/send-user-name-back-to-nad/m-p/3731520#M489166</guid>
      <dc:creator>Ricardo T Duarte</dc:creator>
      <dc:date>2018-10-24T11:28:07Z</dc:date>
    </item>
    <item>
      <title>Re: Send User-Name back to NAD</title>
      <link>https://community.cisco.com/t5/network-access-control/send-user-name-back-to-nad/m-p/3731525#M489178</link>
      <description>&lt;P&gt;oh that's brilliant!&amp;nbsp; Thanks you've just taught me something new in ISE.&amp;nbsp; I guess in hindsight it's quite obvious, but I never thought of trying to overwrite the User-Name (not that I could, because it's IN only).&amp;nbsp; But there're a lot of other dictionary attributes that can be utilised there - might be something I need to keep in mind.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks for that useful pointer.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Oct 2018 11:22:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/send-user-name-back-to-nad/m-p/3731525#M489178</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2018-10-24T11:22:21Z</dc:date>
    </item>
    <item>
      <title>Re: Send User-Name back to NAD</title>
      <link>https://community.cisco.com/t5/network-access-control/send-user-name-back-to-nad/m-p/3731534#M489196</link>
      <description>&lt;P&gt;I didn't try to see if ISE does substitute the variable name with it's value, under advanced attributes.&lt;/P&gt;
&lt;P&gt;I'm assuming it does, given that it allows me to select the available attributes from a list.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If it doesn't, then, the problem is worst than I thought. Another feature request.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Oct 2018 11:26:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/send-user-name-back-to-nad/m-p/3731534#M489196</guid>
      <dc:creator>Ricardo T Duarte</dc:creator>
      <dc:date>2018-10-24T11:26:16Z</dc:date>
    </item>
    <item>
      <title>Re: Send User-Name back to NAD</title>
      <link>https://community.cisco.com/t5/network-access-control/send-user-name-back-to-nad/m-p/3731554#M489209</link>
      <description>Great feedback send to PMs&lt;BR /&gt;</description>
      <pubDate>Wed, 24 Oct 2018 11:43:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/send-user-name-back-to-nad/m-p/3731554#M489209</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-10-24T11:43:25Z</dc:date>
    </item>
    <item>
      <title>Re: Send User-Name back to NAD</title>
      <link>https://community.cisco.com/t5/network-access-control/send-user-name-back-to-nad/m-p/3731565#M489219</link>
      <description>&lt;P&gt;Ok,&lt;/P&gt;
&lt;P&gt;Made a quick test, and ISE just puts the text there.&lt;/P&gt;
&lt;P&gt;It does not expand the variables.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Example:&lt;/P&gt;
&lt;P&gt;I put a advanced attribute there, and selected the value as EndPoints:LogicalProfile.&lt;/P&gt;
&lt;P&gt;The response shows the text "EndPoints:LogicalProfile" and not the real value.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Oct 2018 11:56:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/send-user-name-back-to-nad/m-p/3731565#M489219</guid>
      <dc:creator>Ricardo T Duarte</dc:creator>
      <dc:date>2018-10-24T11:56:33Z</dc:date>
    </item>
    <item>
      <title>Re: Send User-Name back to NAD</title>
      <link>https://community.cisco.com/t5/network-access-control/send-user-name-back-to-nad/m-p/3732044#M489231</link>
      <description>&lt;P&gt;If anyone happen to create a TAC SR regarding this, make sure to attach it to the following defect:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvm77990/" target="_blank"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvm77990/&lt;/A&gt; (Certain RADIUS attribute direction is not RFC2865 compliant)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Oct 2018 20:22:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/send-user-name-back-to-nad/m-p/3732044#M489231</guid>
      <dc:creator>howon</dc:creator>
      <dc:date>2018-10-24T20:22:06Z</dc:date>
    </item>
    <item>
      <title>Re: Send User-Name back to NAD</title>
      <link>https://community.cisco.com/t5/network-access-control/send-user-name-back-to-nad/m-p/3891320#M489237</link>
      <description>&lt;P&gt;Why is this marked Solved! This isn't solved at all. I can't understand how this product has made it this far without this very simple and RFC required feature. This is one of the first features I enabled with FreeRADIUS and it was simple, powerful and straight forward. This is just sad.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jul 2019 19:15:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/send-user-name-back-to-nad/m-p/3891320#M489237</guid>
      <dc:creator>klecompte</dc:creator>
      <dc:date>2019-07-16T19:15:21Z</dc:date>
    </item>
    <item>
      <title>Re: Send User-Name back to NAD</title>
      <link>https://community.cisco.com/t5/network-access-control/send-user-name-back-to-nad/m-p/3891340#M489242</link>
      <description>This is marked as solved because technically it can't be done and is a feature request. please reach out to our PMs with your customer info at &lt;A href="http://cs.co/ise-feedback" target="_blank"&gt;http://cs.co/ise-feedback&lt;/A&gt; and attach to the defects under this posting &lt;A href="https://community.cisco.com/t5/security-documents/ise-2-3-remember-me-guest-using-guest-endpoint-group-logging/ta-p/3641150" target="_blank"&gt;https://community.cisco.com/t5/security-documents/ise-2-3-remember-me-guest-using-guest-endpoint-group-logging/ta-p/3641150&lt;/A&gt; &lt;BR /&gt;CSCvh04231 &amp;amp; CSCva66612 Enhancement for future, please reach out to our Product Managers via - &lt;A href="http://cs.co/ise-feedback" target="_blank"&gt;http://cs.co/ise-feedback&lt;/A&gt; Guest remember me radius accounting and access accept not sending guest username</description>
      <pubDate>Tue, 16 Jul 2019 20:03:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/send-user-name-back-to-nad/m-p/3891340#M489242</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2019-07-16T20:03:33Z</dc:date>
    </item>
  </channel>
</rss>

