<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Direct link to MyDevices portal in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/auto-registration-my-devices-management-of-user-devices-through/m-p/3714160#M511209</link>
    <description>Unfortunately can’t have it both ways with apples bug&lt;BR /&gt;&lt;BR /&gt;Also https redirects not recommended but can understand if low traffic might be ok&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://community.cisco.com/t5/identity-services-engine-ise/ise-guest-cwa-and-https-redirection/td-p/3583892" target="_blank"&gt;https://community.cisco.com/t5/identity-services-engine-ise/ise-guest-cwa-and-https-redirection/td-p/3583892&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Would recommend moving byod onboarding to another wlan or disabling https redirect&lt;BR /&gt;&lt;BR /&gt;Use per wlan bypass for byod wlan&lt;BR /&gt;&lt;BR /&gt;Please read the guide&lt;BR /&gt;</description>
    <pubDate>Thu, 27 Sep 2018 11:15:41 GMT</pubDate>
    <dc:creator>Jason Kunst</dc:creator>
    <dc:date>2018-09-27T11:15:41Z</dc:date>
    <item>
      <title>Auto-registration &amp; My Devices management of user devices through BYOD mechanisms</title>
      <link>https://community.cisco.com/t5/network-access-control/auto-registration-my-devices-management-of-user-devices-through/m-p/3510986#M511197</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm trying to work through a workflow where a user logs into ISE via GuestPortal on a capable machine (something with a web browser), logs in with their AD credentials, and self-registers their device (just MAB, no dot1x).&amp;nbsp; This part of the workflow is easy and complete.&amp;nbsp; The second part of the workflow would have them connecting directly to a link from that same workstation and registering multiple devices that don't have a web browser (printers, game consoles, lab devices, etc.) and I can't seem to find any documentation on how to expose the "MyDevices" portal.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If someone could simply point me to some documentation on directly exposing MyDevices, I would greatly appreciate it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Mar 2018 11:50:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/auto-registration-my-devices-management-of-user-devices-through/m-p/3510986#M511197</guid>
      <dc:creator>blandrum</dc:creator>
      <dc:date>2018-03-29T11:50:28Z</dc:date>
    </item>
    <item>
      <title>Re: Direct link to MyDevices portal</title>
      <link>https://community.cisco.com/t5/network-access-control/auto-registration-my-devices-management-of-user-devices-through/m-p/3510987#M511198</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: -webkit-standard;"&gt;Guest flow device registration is not the same as BYOD/ my devices&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: -webkit-standard; font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Guest flow use the guestendpoints group under the guest type&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;BYOD is registereddevice group for associated flow&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: -webkit-standard; font-size: 10pt;"&gt;The recommendation for employees would be to go through the BYOD flow without guest registration and to disable native supplicant and certificate provisioning, use the my devices portal for those dumb devices &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;A href="https://supportforums.cisco.com/t5/security-blogs/ise-byod-registration-only-without-native-supplicant-or/ba-p/3099290"&gt;https://supportforums.cisco.com/t5/security-blogs/ise-byod-registration-only-without-native-supplicant-or/ba-p/3099290&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Connect to GUEST SSID&lt;/P&gt;&lt;P&gt;2. login as non-guest&lt;/P&gt;&lt;P&gt;3. non-guest forced through BYOD flow&lt;/P&gt;&lt;P&gt;4. endpoint registered into registereddevices&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;The my devices portal is accessed under the portal test url under the portal page settings. The recommendation would be to use the easy URL FQDN option&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;For more information on the easy URL FQDN see:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-3/admin_guide/b_ise_admin_guide_23/b_ise_admin_guide_23_chapter_011110.html#reference_5F10051EBA9046468988DCEB54C60853" title="https://www.cisco.com/c/en/us/td/docs/security/ise/2-3/admin_guide/b_ise_admin_guide_23/b_ise_admin_guide_23_chapter_011110.html#reference_5F10051EBA9046468988DCEB54C60853"&gt;Cisco Identity Services Engine Administrator Guide, Release 2.3 - Guest Access User Interface Reference [Cisco Identit…&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Mar 2018 15:11:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/auto-registration-my-devices-management-of-user-devices-through/m-p/3510987#M511198</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-03-29T15:11:32Z</dc:date>
    </item>
    <item>
      <title>Re: Auto-registration &amp; My Devices management of user devices through BYOD mechanisms</title>
      <link>https://community.cisco.com/t5/network-access-control/auto-registration-my-devices-management-of-user-devices-through/m-p/3510988#M511199</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You should be able to do AD User Guest sign in for the initial session from the device that has a web browser.&amp;nbsp; Once they sign in you can map them to an AD User Guest Type which maps them to an endpoint identity group that grants whatever access you want.&amp;nbsp; Then in the success section of the guest portal, you can direct to a URL.&amp;nbsp; That URL could be the MyDevices portal you want to have them register non-browser based devices.&amp;nbsp; The page could say something like:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"You now have access.&amp;nbsp; If you want to register other devices please login with your AD credentials and add the MAC addresses of your other devices."&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Mar 2018 01:59:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/auto-registration-my-devices-management-of-user-devices-through/m-p/3510988#M511199</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2018-03-30T01:59:11Z</dc:date>
    </item>
    <item>
      <title>Re: Auto-registration &amp; My Devices management of user devices through BYOD mechanisms</title>
      <link>https://community.cisco.com/t5/network-access-control/auto-registration-my-devices-management-of-user-devices-through/m-p/3510989#M511200</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;But what URL can I point them to AFTER the initial BYOD workflow?  Think of a student in a dorm who buys a new xbox a month after initial registration of their web enabled device, and they need to enter the MAC of the Xbox into the mydevices portal.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from my iPhone&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Mar 2018 02:19:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/auto-registration-my-devices-management-of-user-devices-through/m-p/3510989#M511200</guid>
      <dc:creator>blandrum</dc:creator>
      <dc:date>2018-03-30T02:19:52Z</dc:date>
    </item>
    <item>
      <title>Re: Auto-registration &amp; My Devices management of user devices through BYOD mechanisms</title>
      <link>https://community.cisco.com/t5/network-access-control/auto-registration-my-devices-management-of-user-devices-through/m-p/3510990#M511201</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The same portal you redirect them to after the initial flow.  Just create a new MyDevices portal and make an FQDN in the portal like mydevices.mycollege.edu.  That shortcut will work anytime they want to go to it.  You limit number of device each user can register though.  It is a global setting that is defaulted to 5.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Mar 2018 02:28:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/auto-registration-my-devices-management-of-user-devices-through/m-p/3510990#M511201</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2018-03-30T02:28:51Z</dc:date>
    </item>
    <item>
      <title>Re: Auto-registration &amp; My Devices management of user devices through BYOD mechanisms</title>
      <link>https://community.cisco.com/t5/network-access-control/auto-registration-my-devices-management-of-user-devices-through/m-p/3510991#M511202</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I don’t agree with this. I would recommend BYOD flow like I stated so that auto registration and manual registration are in same endpoint group&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What is wrong with what I stated?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also I gave the information already about the my devices easy url FQDN&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Mar 2018 03:34:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/auto-registration-my-devices-management-of-user-devices-through/m-p/3510991#M511202</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-03-30T03:34:17Z</dc:date>
    </item>
    <item>
      <title>Re: Auto-registration &amp; My Devices management of user devices through BYOD mechanisms</title>
      <link>https://community.cisco.com/t5/network-access-control/auto-registration-my-devices-management-of-user-devices-through/m-p/3510992#M511203</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Both ways will work and both will use the same endpoint identity group.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1)     Build a new endpoint idenity group called Student_Devices.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2)     Build a MyDevice portal that maps to Student_Devices and has an FQDN of mydevices.mycollege.edu.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3)     Build an Identity Source Sequence called “Active_Directory” that has only AD in the sequence.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;4)     Build a Guest Type called Student that maps to Student_Devices.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;5)     Builde a Guest portal that has the employees using this portal set to use the Student guest type, Active_Directory as source sequence and sets the success page to https://mydevices.mycollege.edu.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All clean using standard guest mechanics with no worries about disabling client provisioning or invoking other flows.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Both work like I said though.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Mar 2018 12:33:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/auto-registration-my-devices-management-of-user-devices-through/m-p/3510992#M511203</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2018-03-30T12:33:29Z</dc:date>
    </item>
    <item>
      <title>Re: Auto-registration &amp; My Devices management of user devices through BYOD mechanisms</title>
      <link>https://community.cisco.com/t5/network-access-control/auto-registration-my-devices-management-of-user-devices-through/m-p/3510993#M511204</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok I see what you’re doing. Don’t forget to set the portal settings for employees to use that specific student group&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you sure the guest registered endpoints will show under my devices portal? Since it’s not the same attributes being used for BYOD?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also not sure is sending them to a success page of the my devices portal is the correct thing to do but all depends on what they want&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Instead would recommend success page give some information like your device has been registered and will be granted access for X amount of days months (nothing dynamic about this, depends on the endpoint purge settings set under portal). If you have more devices to register and they have a browser do XYZ and if they don’t then grab their MAC address and use the my devices portal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Mar 2018 12:46:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/auto-registration-my-devices-management-of-user-devices-through/m-p/3510993#M511204</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-03-30T12:46:41Z</dc:date>
    </item>
    <item>
      <title>Re: Auto-registration &amp; My Devices management of user devices through BYOD mechanisms</title>
      <link>https://community.cisco.com/t5/network-access-control/auto-registration-my-devices-management-of-user-devices-through/m-p/3510994#M511205</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yeah that is the only thing I am not sure about, if the guest registered endpoints (that go into Student_Devices) would show up in the My Devices portal.  It is in the same endpoint identity group associated to the same user ID, but haven’t tested that out.  I agree on the success page.  I would probably link it to a web page that has more information and a link to MyDevices as you described.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Mar 2018 12:57:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/auto-registration-my-devices-management-of-user-devices-through/m-p/3510994#M511205</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2018-03-30T12:57:30Z</dc:date>
    </item>
    <item>
      <title>Re: Direct link to MyDevices portal</title>
      <link>https://community.cisco.com/t5/network-access-control/auto-registration-my-devices-management-of-user-devices-through/m-p/3713977#M511206</link>
      <description>&lt;P&gt;We are using the same flow for our employees (Open SSID, AD-Authentication on CWA, BYOD Auto-Register for MAB only). But this flow is not working with Apples Captive Portal Assistant (Apple Mini Browser) enabled. We get to the following page after authenticated on CWA and accepted the AUP:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 312px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/19239iC04E55568FF7D574/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;But "Done" is never displayed and if you click the link, you will be redirected to the start page of CWA.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any ideas?&lt;/P&gt;</description>
      <pubDate>Thu, 27 Sep 2018 06:34:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/auto-registration-my-devices-management-of-user-devices-through/m-p/3713977#M511206</guid>
      <dc:creator>Marc Aemmer</dc:creator>
      <dc:date>2018-09-27T06:34:21Z</dc:date>
    </item>
    <item>
      <title>Re: Direct link to MyDevices portal</title>
      <link>https://community.cisco.com/t5/network-access-control/auto-registration-my-devices-management-of-user-devices-through/m-p/3714132#M511207</link>
      <description>Yes there are issues with Apple captive network assistant and Apple has open bug yet to be resolved in iOS 12 from what the experts have told me&lt;BR /&gt;&lt;BR /&gt;There are some threads already about that&lt;BR /&gt;&lt;BR /&gt;Current recommendation is to enable captive portal bypass on the wlan for your open guest SSID used for dual SSID&lt;BR /&gt;&lt;BR /&gt;Or chose different flows&lt;BR /&gt;For more information&lt;BR /&gt;&lt;A href="https://community.cisco.com/t5/identity-services-engine-ise/bd-p/5301j-disc-ise" target="_blank"&gt;https://community.cisco.com/t5/identity-services-engine-ise/bd-p/5301j-disc-ise&lt;/A&gt;&lt;BR /&gt;Go to deploy &amp;gt; byod for more information and read the deployment guide&lt;BR /&gt;</description>
      <pubDate>Thu, 27 Sep 2018 10:52:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/auto-registration-my-devices-management-of-user-devices-through/m-p/3714132#M511207</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-09-27T10:52:41Z</dc:date>
    </item>
    <item>
      <title>Re: Direct link to MyDevices portal</title>
      <link>https://community.cisco.com/t5/network-access-control/auto-registration-my-devices-management-of-user-devices-through/m-p/3714149#M511208</link>
      <description>&lt;P&gt;Thanks for the reply, jason.&lt;/P&gt;
&lt;P&gt;Enabling the captive portal bypass leads to another problem: If you open a https website (in most cases) in safari, you will get a certificate error and this is definitely not user friendly.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Sep 2018 11:05:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/auto-registration-my-devices-management-of-user-devices-through/m-p/3714149#M511208</guid>
      <dc:creator>Marc Aemmer</dc:creator>
      <dc:date>2018-09-27T11:05:25Z</dc:date>
    </item>
    <item>
      <title>Re: Direct link to MyDevices portal</title>
      <link>https://community.cisco.com/t5/network-access-control/auto-registration-my-devices-management-of-user-devices-through/m-p/3714160#M511209</link>
      <description>Unfortunately can’t have it both ways with apples bug&lt;BR /&gt;&lt;BR /&gt;Also https redirects not recommended but can understand if low traffic might be ok&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://community.cisco.com/t5/identity-services-engine-ise/ise-guest-cwa-and-https-redirection/td-p/3583892" target="_blank"&gt;https://community.cisco.com/t5/identity-services-engine-ise/ise-guest-cwa-and-https-redirection/td-p/3583892&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Would recommend moving byod onboarding to another wlan or disabling https redirect&lt;BR /&gt;&lt;BR /&gt;Use per wlan bypass for byod wlan&lt;BR /&gt;&lt;BR /&gt;Please read the guide&lt;BR /&gt;</description>
      <pubDate>Thu, 27 Sep 2018 11:15:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/auto-registration-my-devices-management-of-user-devices-through/m-p/3714160#M511209</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-09-27T11:15:41Z</dc:date>
    </item>
    <item>
      <title>Re: Direct link to MyDevices portal</title>
      <link>https://community.cisco.com/t5/network-access-control/auto-registration-my-devices-management-of-user-devices-through/m-p/3714286#M511210</link>
      <description>&lt;P&gt;Is there a Cisco or Apple Bug ID so I can track it?&lt;/P&gt;</description>
      <pubDate>Thu, 27 Sep 2018 13:21:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/auto-registration-my-devices-management-of-user-devices-through/m-p/3714286#M511210</guid>
      <dc:creator>Marc Aemmer</dc:creator>
      <dc:date>2018-09-27T13:21:23Z</dc:date>
    </item>
    <item>
      <title>Re: Direct link to MyDevices portal</title>
      <link>https://community.cisco.com/t5/network-access-control/auto-registration-my-devices-management-of-user-devices-through/m-p/3714449#M511211</link>
      <description>&lt;A href="https://community.cisco.com/t5/security-documents/dealing-with-apple-cna-aka-mini-browser-for-ise-byod/ta-p/3641822" target="_blank"&gt;https://community.cisco.com/t5/security-documents/dealing-with-apple-cna-aka-mini-browser-for-ise-byod/ta-p/3641822&lt;/A&gt;&lt;BR /&gt;defect listed there in the table</description>
      <pubDate>Thu, 27 Sep 2018 16:40:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/auto-registration-my-devices-management-of-user-devices-through/m-p/3714449#M511211</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-09-27T16:40:33Z</dc:date>
    </item>
  </channel>
</rss>

