<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Guest Endpoint not switching Identity Group Assignment in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/guest-endpoint-not-switching-identity-group-assignment/m-p/3581410#M518466</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It's not a fresh install (even though we might plan a patch upgrade) and we have the same authorization policies like you mentioned. &lt;/P&gt;&lt;P&gt;If wireless_mab and guestendpoint then permit access&lt;/P&gt;&lt;P&gt;If wireless_mab then redirect&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The endpoint connects and gets profiled as Windows7-Workstation while it gets the URL redirection but remains there even after the guest registers and accepts and hence hits the default rule again.&lt;/P&gt;&lt;P&gt;We have referred the guestendpoint group correctly in the guest portal. &lt;/P&gt;&lt;P&gt;&lt;IMG alt="errorpages.png" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/114695_errorpages.png" style="height: 340px; width: 620px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 22 Jan 2018 22:01:43 GMT</pubDate>
    <dc:creator>umahar</dc:creator>
    <dc:date>2018-01-22T22:01:43Z</dc:date>
    <item>
      <title>Guest Endpoint not switching Identity Group Assignment</title>
      <link>https://community.cisco.com/t5/network-access-control/guest-endpoint-not-switching-identity-group-assignment/m-p/3581406#M518462</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We are running ISE 2.1 patch 5. After guest clicks on Accept we still get the redirection URL and we found that the Identity Group Assignment is never switched to GuestEndpointGroups.&lt;/P&gt;&lt;P&gt;Does this look like a bug ? There is nothing wrong with the configuration. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Jan 2018 21:29:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/guest-endpoint-not-switching-identity-group-assignment/m-p/3581406#M518462</guid>
      <dc:creator>umahar</dc:creator>
      <dc:date>2018-01-22T21:29:05Z</dc:date>
    </item>
    <item>
      <title>Re: Guest Endpoint not switching Identity Group Assignment</title>
      <link>https://community.cisco.com/t5/network-access-control/guest-endpoint-not-switching-identity-group-assignment/m-p/3581407#M518463</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have a concern with the switching identity group part&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you saying that its in one identity group in the beginning and then you want to switch?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Guest is mean to take unknown fresh endpoint and move it into the guestendpointgroup.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don’t believe we support switching identity group through the portal after its already in another group&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Jan 2018 21:33:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/guest-endpoint-not-switching-identity-group-assignment/m-p/3581407#M518463</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-01-22T21:33:40Z</dc:date>
    </item>
    <item>
      <title>Re: Guest Endpoint not switching Identity Group Assignment</title>
      <link>https://community.cisco.com/t5/network-access-control/guest-endpoint-not-switching-identity-group-assignment/m-p/3581408#M518464</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Initially it is profiled as Workstation and is placed into Workstation meanwhile the endpoint gets a web redirection. &lt;/P&gt;&lt;P&gt;Then after the guest registers shouldn't it get placed into GuestEndpoints Identity Group ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Jan 2018 21:39:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/guest-endpoint-not-switching-identity-group-assignment/m-p/3581408#M518464</guid>
      <dc:creator>umahar</dc:creator>
      <dc:date>2018-01-22T21:39:25Z</dc:date>
    </item>
    <item>
      <title>Re: Guest Endpoint not switching Identity Group Assignment</title>
      <link>https://community.cisco.com/t5/network-access-control/guest-endpoint-not-switching-identity-group-assignment/m-p/3581409#M518465</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;By default (unless something was changed in profiler, etc) it wouldn’t be in an endpoint group until you went through the guest flow.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this a fresh install? Why aren’t you on patch 6?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your policy should be&lt;/P&gt;&lt;P&gt;If wireless_mab and guestendpoint then permit access&lt;/P&gt;&lt;P&gt;If wireless_mab then redirect&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Otherwise please open a tac case&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Jan 2018 21:47:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/guest-endpoint-not-switching-identity-group-assignment/m-p/3581409#M518465</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-01-22T21:47:29Z</dc:date>
    </item>
    <item>
      <title>Re: Guest Endpoint not switching Identity Group Assignment</title>
      <link>https://community.cisco.com/t5/network-access-control/guest-endpoint-not-switching-identity-group-assignment/m-p/3581410#M518466</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It's not a fresh install (even though we might plan a patch upgrade) and we have the same authorization policies like you mentioned. &lt;/P&gt;&lt;P&gt;If wireless_mab and guestendpoint then permit access&lt;/P&gt;&lt;P&gt;If wireless_mab then redirect&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The endpoint connects and gets profiled as Windows7-Workstation while it gets the URL redirection but remains there even after the guest registers and accepts and hence hits the default rule again.&lt;/P&gt;&lt;P&gt;We have referred the guestendpoint group correctly in the guest portal. &lt;/P&gt;&lt;P&gt;&lt;IMG alt="errorpages.png" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/114695_errorpages.png" style="height: 340px; width: 620px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Jan 2018 22:01:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/guest-endpoint-not-switching-identity-group-assignment/m-p/3581410#M518466</guid>
      <dc:creator>umahar</dc:creator>
      <dc:date>2018-01-22T22:01:43Z</dc:date>
    </item>
    <item>
      <title>Re: Guest Endpoint not switching Identity Group Assignment</title>
      <link>https://community.cisco.com/t5/network-access-control/guest-endpoint-not-switching-identity-group-assignment/m-p/3581411#M518467</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;is the guest portal set to register the endpoint? guest device registration settings for the portal?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Were any of the profiler setting changed? for workstation?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have a fresh setup to compare it to?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would suggest a tac case&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Jan 2018 22:10:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/guest-endpoint-not-switching-identity-group-assignment/m-p/3581411#M518467</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-01-22T22:10:01Z</dc:date>
    </item>
    <item>
      <title>Re: Guest Endpoint not switching Identity Group Assignment</title>
      <link>https://community.cisco.com/t5/network-access-control/guest-endpoint-not-switching-identity-group-assignment/m-p/3581412#M518468</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;My bad. We were missing Registration &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Jan 2018 18:34:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/guest-endpoint-not-switching-identity-group-assignment/m-p/3581412#M518468</guid>
      <dc:creator>umahar</dc:creator>
      <dc:date>2018-01-25T18:34:44Z</dc:date>
    </item>
  </channel>
</rss>

