<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Conditional Guest Authentication Success? in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/conditional-guest-authentication-success/m-p/3559983#M511673</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just an idea. Perhaps, keep it at the authentication success page and then in the success page to test an URL to determine whether to go to MDM or not, based on the authorization profile(s) after CoA.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 13 Mar 2018 15:30:17 GMT</pubDate>
    <dc:creator>hslai</dc:creator>
    <dc:date>2018-03-13T15:30:17Z</dc:date>
    <item>
      <title>Conditional Guest Authentication Success?</title>
      <link>https://community.cisco.com/t5/network-access-control/conditional-guest-authentication-success/m-p/3559978#M511668</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it possible to perform conditional redirection based on the authentication method chosen?&lt;/P&gt;&lt;P&gt;e.g.&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/115859_pastedImage_0.png" style="max-height: 900px; max-width: 1200px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My customer would like to redirect the successful Guest to a different URL, depending on what Identity Source was used to perform the auth.&lt;/P&gt;&lt;P&gt;e.g.&lt;/P&gt;&lt;P&gt;I have an identity source sequence of&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;Guest_Portal_Sequence (Contains search list: Guest Users)&lt;/P&gt;&lt;P&gt;AD_or_Guest_Portal (Contains search list:&amp;nbsp; Guest Users, ADJoinPoint)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the auth was a success performed against Guest Users, then redirect to &lt;A href="http://www.somesite1.com/"&gt;www.somesite1.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;If the auth was a success performed against ADJoinPoint, then redirect to &lt;SPAN style="color: #0066cc; text-decoration: underline;"&gt;&lt;A href="http://www.somesite2.com/"&gt;www.somesite2.com&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The use case is that we want to (ab)use the Guest portal to allow AD users to authenticate using their AD creds, and after they have done so, redirect them to a custom MDM onboarding web site.&amp;nbsp; But regular sponsored guests would be redirected to a generic page like google.com.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If there is a better way to do this then I would be open to hearing about it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Mar 2018 03:05:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/conditional-guest-authentication-success/m-p/3559978#M511668</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2018-03-12T03:05:20Z</dc:date>
    </item>
    <item>
      <title>Re: Conditional Guest Authentication Success?</title>
      <link>https://community.cisco.com/t5/network-access-control/conditional-guest-authentication-success/m-p/3559979#M511669</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Under your portal settings make sure you have a guest type for employees&lt;/P&gt;&lt;P&gt;Under this guest type you would register these devices into an employee endpoint group&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Would suggest authorization rules if guest flow and ad group then redirect to portal&lt;/P&gt;&lt;P&gt;If guest endpoints permit internet&lt;/P&gt;&lt;P&gt;If mab then redirect to portal for login&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Mar 2018 04:49:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/conditional-guest-authentication-success/m-p/3559979#M511669</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-03-12T04:49:45Z</dc:date>
    </item>
    <item>
      <title>Re: Conditional Guest Authentication Success?</title>
      <link>https://community.cisco.com/t5/network-access-control/conditional-guest-authentication-success/m-p/3559980#M511670</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If your ad rule is above your guest endpoints then you don’t need to worry about the portal setting for employees guest type or endpoints&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Mar 2018 05:05:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/conditional-guest-authentication-success/m-p/3559980#M511670</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-03-12T05:05:25Z</dc:date>
    </item>
    <item>
      <title>Re: Conditional Guest Authentication Success?</title>
      <link>https://community.cisco.com/t5/network-access-control/conditional-guest-authentication-success/m-p/3559981#M511671</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jason&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have a Guest Type that we defined for employee guests.&amp;nbsp; We then tie that to the Guest Portal under the option "Employees using this portal as guests inherit login options from:"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All of this is working fine and I can authenticate Sponsored Guests and AD guests without any issues.&amp;nbsp; Their MAC addresses end up in the correct Endpoint Identity Groups.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My question was around the "Authentication Success Settings" radio buttons.&amp;nbsp; I am only allowed to choose one option that then applies to the entire Guest Portal.&amp;nbsp; I wanted to know if this choice could be made conditional - i.e. have the "Success" redirection based on how the user authenticated.&amp;nbsp; Is that possible?&lt;/P&gt;&lt;P&gt;The authentication processing logic is mostly a black box inside ISE (as opposed to the flexible Radius Policy Set logic) and we are constrained by what the GUI allows us to do.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Mar 2018 05:47:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/conditional-guest-authentication-success/m-p/3559981#M511671</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2018-03-12T05:47:05Z</dc:date>
    </item>
    <item>
      <title>Re: Conditional Guest Authentication Success?</title>
      <link>https://community.cisco.com/t5/network-access-control/conditional-guest-authentication-success/m-p/3559982#M511672</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No that cannot be made conditional.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You have to identify authorization flows for different groups with different authorization results&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Mar 2018 06:15:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/conditional-guest-authentication-success/m-p/3559982#M511672</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-03-12T06:15:38Z</dc:date>
    </item>
    <item>
      <title>Re: Conditional Guest Authentication Success?</title>
      <link>https://community.cisco.com/t5/network-access-control/conditional-guest-authentication-success/m-p/3559983#M511673</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just an idea. Perhaps, keep it at the authentication success page and then in the success page to test an URL to determine whether to go to MDM or not, based on the authorization profile(s) after CoA.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Mar 2018 15:30:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/conditional-guest-authentication-success/m-p/3559983#M511673</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-03-13T15:30:17Z</dc:date>
    </item>
  </channel>
</rss>

