<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE Portal Using Two Different Identity Sources in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-portal-using-two-different-identity-sources/m-p/3703952#M507734</link>
    <description>&lt;P&gt;Hi Cory,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I just changed the account type to guest and contractor type. I am able to connect using the different account type but somehow unable to connect to the internet. And after a few minutes the system keep asking me for relogin. But when I login using the usual account type, it works normally.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any idea why? Thank you.&lt;/P&gt;</description>
    <pubDate>Mon, 10 Sep 2018 12:44:04 GMT</pubDate>
    <dc:creator>fdharmawan</dc:creator>
    <dc:date>2018-09-10T12:44:04Z</dc:date>
    <item>
      <title>ISE Portal Using Two Different Identity Sources</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-portal-using-two-different-identity-sources/m-p/3703788#M507730</link>
      <description>&lt;P&gt;Hi Guys,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a&amp;nbsp;portal configured for internet access that requires the users to login using AD credential. Recently I got a requirement to create local users on ISE and those local users should be able to login to the same portal I mentioned before.&amp;nbsp;Below are&amp;nbsp;my conditions:&lt;/P&gt;
&lt;P&gt;1. I created the local users on ISE using the InternalUser category.&lt;/P&gt;
&lt;P&gt;2. I already set the portal to seek for AD then InternalUser for authentication list.&lt;/P&gt;
&lt;P&gt;3.&amp;nbsp;I set the "Employees using this portal as guests inherit login options from" setting to InternalUser.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Using the setting above, the local users able to login to the portal. But here is the thing. I want to treat those users differently. Let's say the users that login using AD credential can have up to 10 device registered and&amp;nbsp;10 concurrent login. On the other hand, I want to set the local users can only have&amp;nbsp;&lt;SPAN&gt;up to&amp;nbsp;5 device registered and&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;5&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;concurrent login.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;With my settings above, if I change the internal user settings, the AD account also got affected. Is there any way to treat the sources differently?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thank you.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Sep 2018 08:28:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-portal-using-two-different-identity-sources/m-p/3703788#M507730</guid>
      <dc:creator>fdharmawan</dc:creator>
      <dc:date>2018-09-10T08:28:27Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Portal Using Two Different Identity Sources</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-portal-using-two-different-identity-sources/m-p/3703901#M507732</link>
      <description>&lt;P&gt;You need to change the setting in your 3rd point to something different than internal users, I always use Employee.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Then under guest type you can change the Employee settings and it will affect them different then the guest setting.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Sep 2018 11:35:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-portal-using-two-different-identity-sources/m-p/3703901#M507732</guid>
      <dc:creator>Cory Peterson</dc:creator>
      <dc:date>2018-09-10T11:35:57Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Portal Using Two Different Identity Sources</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-portal-using-two-different-identity-sources/m-p/3703942#M507733</link>
      <description>ISE internal users and active directory are considered employees and will have the same guest type assigned to them&lt;BR /&gt;&lt;BR /&gt;A way to accomplish this is to use multiple portals and link them together.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://community.cisco.com/t5/identity-services-engine-ise/linking-one-guest-portal-to-another-guest-portal/td-p/3467537" target="_blank"&gt;https://community.cisco.com/t5/identity-services-engine-ise/linking-one-guest-portal-to-another-guest-portal/td-p/3467537&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Recommendation would be to use the initial portal to handle what a majority of your flows would be&lt;BR /&gt;&lt;BR /&gt;The additional portal flow would be the less used.&lt;BR /&gt;&lt;BR /&gt;Keep in mind Apple Captive network assistant may not like this scripting and redirects and get confused. If In your testing you run into problems  then recommend enabling captive portal bypass on the controller&lt;BR /&gt;</description>
      <pubDate>Mon, 10 Sep 2018 12:34:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-portal-using-two-different-identity-sources/m-p/3703942#M507733</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-09-10T12:34:34Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Portal Using Two Different Identity Sources</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-portal-using-two-different-identity-sources/m-p/3703952#M507734</link>
      <description>&lt;P&gt;Hi Cory,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I just changed the account type to guest and contractor type. I am able to connect using the different account type but somehow unable to connect to the internet. And after a few minutes the system keep asking me for relogin. But when I login using the usual account type, it works normally.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any idea why? Thank you.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Sep 2018 12:44:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-portal-using-two-different-identity-sources/m-p/3703952#M507734</guid>
      <dc:creator>fdharmawan</dc:creator>
      <dc:date>2018-09-10T12:44:04Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Portal Using Two Different Identity Sources</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-portal-using-two-different-identity-sources/m-p/3703955#M507735</link>
      <description>Not sure, depends on your authorization rules. Perhaps you don’t have authorization rules for the different guest types?&lt;BR /&gt;&lt;BR /&gt;Share your rules?&lt;BR /&gt;</description>
      <pubDate>Mon, 10 Sep 2018 12:47:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-portal-using-two-different-identity-sources/m-p/3703955#M507735</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-09-10T12:47:34Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Portal Using Two Different Identity Sources</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-portal-using-two-different-identity-sources/m-p/3704001#M507736</link>
      <description>&lt;P&gt;Each Guest Type should map to its own unique Endpoint Identity Group.&amp;nbsp; My typical portal setup looks something like this:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Guest-Daily- maps to Guest-Daily endpoint group and is purged daily.&lt;/LI&gt;
&lt;LI&gt;Guest-Weekly- maps to Guest-Weekly endpoint group and is purged daily or weekly depending on customer input.&lt;/LI&gt;
&lt;LI&gt;Guest-Custom- maps to Guest-Custom endpoint group and is purged weekly depending on customer input.&lt;/LI&gt;
&lt;LI&gt;Employee-BYOD- maps to Employee-BYOD endpoint group and is purged once a month dependin on customer input.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Then the authorization rules simply state:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;If member of Guest-Daily, Guest-Weekly, Guest-Custom or Employee-BYOD then you get Internet access.&lt;/LI&gt;
&lt;LI&gt;If anything else then you get the guest portal.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Sep 2018 13:39:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-portal-using-two-different-identity-sources/m-p/3704001#M507736</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2018-09-10T13:39:24Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Portal Using Two Different Identity Sources</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-portal-using-two-different-identity-sources/m-p/3704011#M507737</link>
      <description>Paul remember that internal users and AD all map to one guest type set on the self-registration portal so you can’t map internal users to internalendpointgroup and AD users  to another endpoint group&lt;BR /&gt;&lt;BR /&gt;However they could do device registration via the hotspot portal&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://community.cisco.com/t5/identity-services-engine-ise/ise-guest-flow-with-multiple-endpoint-identities/td-p/3500190" target="_blank"&gt;https://community.cisco.com/t5/identity-services-engine-ise/ise-guest-flow-with-multiple-endpoint-identities/td-p/3500190&lt;/A&gt;&lt;BR /&gt;</description>
      <pubDate>Mon, 10 Sep 2018 13:49:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-portal-using-two-different-identity-sources/m-p/3704011#M507737</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-09-10T13:49:34Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Portal Using Two Different Identity Sources</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-portal-using-two-different-identity-sources/m-p/3704022#M507738</link>
      <description>Yep, but there really isn't a reason to use Internal Users.  Just create long term guest accounts.  That is what the Guest-Custom category is for in my builds.  Only certain AD groups can manage that Guest Type and I usually let those accounts go out to 365 days.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Mon, 10 Sep 2018 13:56:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-portal-using-two-different-identity-sources/m-p/3704022#M507738</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2018-09-10T13:56:34Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Portal Using Two Different Identity Sources</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-portal-using-two-different-identity-sources/m-p/3705955#M507835</link>
      <description>&lt;P&gt;Hi Jason,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Sorry for late reply. I was on something else lately.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here are my current rules:&lt;/P&gt;
&lt;P&gt;-When the device is connected to the SSID, ISE will check whether the MAC address is already registered previously. If so, the device will continue to internet access. We already set the period of time of a device listed on registered device. If the device is not registered yet, a captive portal will appear.&lt;/P&gt;
&lt;P&gt;-The portal itself has the authentication method of Guest_Portal_Sequence. I don't know whether this one is default rule or not, but the login checking sequence is like this: AD, Internal User, Guest Users.&lt;/P&gt;
&lt;P&gt;-For the guest inherit option, I picked InternalUser. I suppose it is not default. And regarding the guest user type I&amp;nbsp;will be using on the portal will be InternalUser and Guest (from my understanding, these two are on Internal User sequence). The only differences are the period of account validity and devices allowed to be registered.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Sep 2018 03:02:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-portal-using-two-different-identity-sources/m-p/3705955#M507835</guid>
      <dc:creator>fdharmawan</dc:creator>
      <dc:date>2018-09-13T03:02:08Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Portal Using Two Different Identity Sources</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-portal-using-two-different-identity-sources/m-p/3705959#M507836</link>
      <description>&lt;P&gt;Hi Jason,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Where should I put the script into? Is it on the optional content portal page customizations? Or somewhere else?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;FYI, most of the mobile device on my company unfortunately are apple devices. Is there any other workaround other than this? Since you put an earlier notification regarding the apple captive assistant.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Sep 2018 03:10:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-portal-using-two-different-identity-sources/m-p/3705959#M507836</guid>
      <dc:creator>fdharmawan</dc:creator>
      <dc:date>2018-09-13T03:10:53Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Portal Using Two Different Identity Sources</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-portal-using-two-different-identity-sources/m-p/3705973#M507837</link>
      <description>Would recommend opening different thread but yes optional content 2 will work. Actually any will work&lt;BR /&gt;&lt;BR /&gt;No there isn’t another way besides what I listed &lt;BR /&gt;</description>
      <pubDate>Thu, 13 Sep 2018 03:36:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-portal-using-two-different-identity-sources/m-p/3705973#M507837</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-09-13T03:36:45Z</dc:date>
    </item>
  </channel>
</rss>

