<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE Hotspot deny page in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-hotspot-deny-page/m-p/3456431#M518756</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have setup a hotspot page for my client in ISE.&amp;nbsp; They are using this for their guest wireless, but it is locked down to only allow certain types of devices on it (i.e. PC's, tablets, etc....not streaming devices like Roku's).&amp;nbsp; At any rate, they asked if there is a way to have a deny page come when someone tries to connect with a device like a Roku.&amp;nbsp; They feel that they will get a lot of phone calls without a deny page.&amp;nbsp; Not sure if this can be done or not.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TIA,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 08 Jan 2018 16:27:19 GMT</pubDate>
    <dc:creator>deyster94</dc:creator>
    <dc:date>2018-01-08T16:27:19Z</dc:date>
    <item>
      <title>ISE Hotspot deny page</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-hotspot-deny-page/m-p/3456431#M518756</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have setup a hotspot page for my client in ISE.&amp;nbsp; They are using this for their guest wireless, but it is locked down to only allow certain types of devices on it (i.e. PC's, tablets, etc....not streaming devices like Roku's).&amp;nbsp; At any rate, they asked if there is a way to have a deny page come when someone tries to connect with a device like a Roku.&amp;nbsp; They feel that they will get a lot of phone calls without a deny page.&amp;nbsp; Not sure if this can be done or not.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TIA,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Jan 2018 16:27:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-hotspot-deny-page/m-p/3456431#M518756</guid>
      <dc:creator>deyster94</dc:creator>
      <dc:date>2018-01-08T16:27:19Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Hotspot deny page</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-hotspot-deny-page/m-p/3456432#M518761</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You could redirect them to a custom portal like Blacklist Portal&lt;/P&gt;&lt;P&gt;Heres a thread on the topic&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.cisco.com/message/236608"&gt;Blacklist for Registered Corporate MAC's on Guest??&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.cisco.com/docs/DOC-76521"&gt;How To Whitelist or Blacklist an Endpoint by Endpoint Profile&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.cisco.com/docs/DOC-76172"&gt;How To Whitelist or Blacklist an Endpoint by MAC Address&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Danny&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Jan 2018 17:04:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-hotspot-deny-page/m-p/3456432#M518761</guid>
      <dc:creator>ldanny</dc:creator>
      <dc:date>2018-01-08T17:04:28Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Hotspot deny page</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-hotspot-deny-page/m-p/3456433#M518769</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You said its locked down to certain devices? How are they doing that? Or is this just a policy that they don’t want to allow it but they aren’t actually restricting it now because they don’t know how?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For this to work you would need to identify the groups of devices that are allowed and then using Plus licensing and profiling setup policies&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem I see however is that when you first come in you will be redirected to the hotspot portal and only then recognized by the browser user agent string on the roku. Then you will have to do a Change of authorization with the profile change to get the new authz policy&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does the roku even have a web browser where they could see this message?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is how it may work but you would have to lab it up. It might prove problematic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If wireless mab and guestendpoints and notallowed then redirect to message portal&lt;/P&gt;&lt;P&gt;If wireless_mab and guestendpoints and alloweddevices then permit access&lt;/P&gt;&lt;P&gt;If wireless_mab then redirect to hotspot portal&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you can get this to work then here is a way to make a message portal.&lt;/P&gt;&lt;P&gt;https://communities.cisco.com/docs/DOC-64018&lt;/P&gt;&lt;P&gt;Look for hotspot as a message portal&lt;/P&gt;&lt;P&gt;For ISE 2.2 and higher you can use the Custom portal files to host an HTML file to redirect to&lt;/P&gt;&lt;P&gt;See powerpoint at this top of that page what’s new in ISE 2.2, look at slide 15&lt;/P&gt;&lt;P&gt;https://communities.cisco.com/docs/DOC-64018#jive_content_id_ISE_22&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Jan 2018 18:08:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-hotspot-deny-page/m-p/3456433#M518769</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-01-08T18:08:07Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Hotspot deny page</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-hotspot-deny-page/m-p/3456434#M518774</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jason,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the response.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The solution was sold as follows.&amp;nbsp; When a device connects, ISE will profile the device and if it it matches an allowed profile, it can access the guest wireless, otherwise they are blocked.&amp;nbsp; This wireless is for guests and residents (this is a retirement community).&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Honestly, I think it would be easier to send a letter out to the residents to let them know what only certain devices can connect, or vice versa.&amp;nbsp; You do bring up a good point of some devices won't be able to display a deny access page.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Jan 2018 18:37:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-hotspot-deny-page/m-p/3456434#M518774</guid>
      <dc:creator>deyster94</dc:creator>
      <dc:date>2018-01-08T18:37:53Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Hotspot deny page</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-hotspot-deny-page/m-p/3456435#M518782</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK well like I said it might be problematic on what you expect to work. With profile changes and COAs and correctly identifying allowed devices vs not allowed devices.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I suggest that its validated and tested in a lab to see if it can work per expectations.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Jan 2018 18:42:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-hotspot-deny-page/m-p/3456435#M518782</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-01-08T18:42:55Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Hotspot deny page</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-hotspot-deny-page/m-p/3456436#M518785</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I talked to them more about this that most, if not all, the devices that will be blocked won't have the ability to display a deny page.&amp;nbsp; Once they thought about it, they agreed to leave it be for now.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Jan 2018 18:58:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-hotspot-deny-page/m-p/3456436#M518785</guid>
      <dc:creator>deyster94</dc:creator>
      <dc:date>2018-01-08T18:58:24Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Hotspot deny page</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-hotspot-deny-page/m-p/3456437#M518791</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Great! Makes sense&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Jan 2018 19:05:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-hotspot-deny-page/m-p/3456437#M518791</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-01-08T19:05:07Z</dc:date>
    </item>
  </channel>
</rss>

