<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Launch of my devices portal with MAC attributes in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/launch-of-my-devices-portal-with-mac-attributes/m-p/3581899#M509041</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;https://supportforums.cisco.com/t5/security-blogs/ise-byod-registration-only-without-native-supplicant-or/ba-p/3099290&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 14 Jun 2018 01:52:42 GMT</pubDate>
    <dc:creator>Jason Kunst</dc:creator>
    <dc:date>2018-06-14T01:52:42Z</dc:date>
    <item>
      <title>Launch of my devices portal with MAC attributes</title>
      <link>https://community.cisco.com/t5/network-access-control/launch-of-my-devices-portal-with-mac-attributes/m-p/3581894#M509034</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would like to implement a workflow with an authorisation profile redirecting to a particular "my device" portal, with the ability to pre-populate the deviceId in the registration window.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do we have an available attribute in the my device portal we could use when specifying the redirection link, in addition to the portal ID ? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Something like : &lt;/P&gt;&lt;P&gt;&lt;IMG alt="Screen Shot 2018-06-13 at 18.50.33.png" class="image-1 jive-image" src="/legacyfs/online/fusion/117644_Screen Shot 2018-06-13 at 18.50.33.png" style="height: 69px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;Above the endpointID value is static, but the final URL would be using the actual deviceID as the MAC attribute.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any way to do it ? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks !&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;jean-francois&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Jun 2018 16:54:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/launch-of-my-devices-portal-with-mac-attributes/m-p/3581894#M509034</guid>
      <dc:creator>jpujol</dc:creator>
      <dc:date>2018-06-13T16:54:51Z</dc:date>
    </item>
    <item>
      <title>Re: Launch of my devices portal with MAC attributes</title>
      <link>https://community.cisco.com/t5/network-access-control/launch-of-my-devices-portal-with-mac-attributes/m-p/3581895#M509036</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The only way for ISE natively to glean the MAC address is through the BYOD flow and nsp, why can’t you use that? What are you trying to accomplish?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Jun 2018 17:39:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/launch-of-my-devices-portal-with-mac-attributes/m-p/3581895#M509036</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-06-13T17:39:29Z</dc:date>
    </item>
    <item>
      <title>Re: Launch of my devices portal with MAC attributes</title>
      <link>https://community.cisco.com/t5/network-access-control/launch-of-my-devices-portal-with-mac-attributes/m-p/3581896#M509038</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm trying to register devices authenticated through WPA / LDAP in a simple way, and limit the number of devices per user.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Once authenticated, I guess it's possible to pass the deviceID within an authorisation profile, and to redirect to "my device" portal for device registration. &lt;/P&gt;&lt;P&gt;In case the user needs to register the first device (through the wireless network), that would be easier to present the device MAC address directly on the form. The device is then put into a group, avoiding further redirection later on.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Since there is a need to limit the number of devices per user, there is also the need to provide a solution to manage and remove&amp;nbsp;&amp;nbsp; stale entries ...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The BYOD registration process is too complex for a simple MAC registration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thx, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;jean-francois&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Jun 2018 20:20:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/launch-of-my-devices-portal-with-mac-attributes/m-p/3581896#M509038</guid>
      <dc:creator>jpujol</dc:creator>
      <dc:date>2018-06-13T20:20:16Z</dc:date>
    </item>
    <item>
      <title>Re: Launch of my devices portal with MAC attributes</title>
      <link>https://community.cisco.com/t5/network-access-control/launch-of-my-devices-portal-with-mac-attributes/m-p/3581897#M509039</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Have you thought about using just a hot spot portal that maps to your desired endpoint identity group?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Assuming your users are connecting to an 802.1 SSID with credentials your authorization rules would look like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If MAC address is in the RegisteredDevices endpoint identity group then allow access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Else allow access but sent to the Hotspot portal.&amp;nbsp; The Hotspot portal could simply say "Click continue below to register your device and gain access to the network".&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I haven't tested this out, but I don't see why it wouldn't work.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Jun 2018 21:43:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/launch-of-my-devices-portal-with-mac-attributes/m-p/3581897#M509039</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2018-06-13T21:43:01Z</dc:date>
    </item>
    <item>
      <title>Re: Launch of my devices portal with MAC attributes</title>
      <link>https://community.cisco.com/t5/network-access-control/launch-of-my-devices-portal-with-mac-attributes/m-p/3581898#M509040</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As Paul stated, if looking simply to register a MAC address, then HotSpot can accomplish.&amp;nbsp; CWA flow can tie registration to a user only after initial user authentication.&amp;nbsp; This will also allow tracking of user.&amp;nbsp;&amp;nbsp;&amp;nbsp; Based on overall ask, I think BYOD flow is best.&amp;nbsp; Note that BYOD flow can be used to simply associate user to a device, assign the device to an Identity Group and flag it as registered.&amp;nbsp; It is not required to perform any supplicant provisioning in BYOD flow, just login via web portal first time.&amp;nbsp; It can also be used to enforce the number of devices registered to a specific user.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Jun 2018 00:06:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/launch-of-my-devices-portal-with-mac-attributes/m-p/3581898#M509040</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2018-06-14T00:06:32Z</dc:date>
    </item>
    <item>
      <title>Re: Launch of my devices portal with MAC attributes</title>
      <link>https://community.cisco.com/t5/network-access-control/launch-of-my-devices-portal-with-mac-attributes/m-p/3581899#M509041</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;https://supportforums.cisco.com/t5/security-blogs/ise-byod-registration-only-without-native-supplicant-or/ba-p/3099290&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Jun 2018 01:52:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/launch-of-my-devices-portal-with-mac-attributes/m-p/3581899#M509041</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-06-14T01:52:42Z</dc:date>
    </item>
    <item>
      <title>Re: Launch of my devices portal with MAC attributes</title>
      <link>https://community.cisco.com/t5/network-access-control/launch-of-my-devices-portal-with-mac-attributes/m-p/3581900#M509042</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Paul, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I made the test and it allows the device registration, however the user doesn't have visibility on the registered devices, and there isn't a way to remove a device if the number is limited per user.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Jun 2018 06:42:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/launch-of-my-devices-portal-with-mac-attributes/m-p/3581900#M509042</guid>
      <dc:creator>jpujol</dc:creator>
      <dc:date>2018-06-14T06:42:55Z</dc:date>
    </item>
    <item>
      <title>Re: Launch of my devices portal with MAC attributes</title>
      <link>https://community.cisco.com/t5/network-access-control/launch-of-my-devices-portal-with-mac-attributes/m-p/3581901#M509043</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jason, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, I'll have a try&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Jun 2018 07:30:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/launch-of-my-devices-portal-with-mac-attributes/m-p/3581901#M509043</guid>
      <dc:creator>jpujol</dc:creator>
      <dc:date>2018-06-14T07:30:50Z</dc:date>
    </item>
  </channel>
</rss>

