<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Guest Internet Activity in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/guest-internet-activity/m-p/3472848#M519245</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There is nothing documented on our side, we simply send our syslog to splunk for example and then asa would send to them as well&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Up to them to correlate for A guest report&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Splunk may have something&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 08 Dec 2017 13:44:05 GMT</pubDate>
    <dc:creator>Jason Kunst</dc:creator>
    <dc:date>2017-12-08T13:44:05Z</dc:date>
    <item>
      <title>Guest Internet Activity</title>
      <link>https://community.cisco.com/t5/network-access-control/guest-internet-activity/m-p/3472845#M519242</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Our customer would like to map the guest user identity to their Internet activity. From older threads I understand that this is possible using the "Guest Activity Report", now replaced by the "Guest Master Report".&lt;/P&gt;&lt;P&gt;As I have tried to set it up without success, can you confirm that sending IP + URL logs from an ASA/WSA would be parsed by ISE and displayed in the Guest Master Report?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Secondly, is there any recommended solution for User to Web Activity mapping?&lt;/P&gt;&lt;P&gt;Current options I am looking at are:&lt;/P&gt;&lt;P&gt;- ISE Guest master report (see question above)&lt;/P&gt;&lt;P&gt;- SIEM&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Would appreciate any proven solution for this.&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;Gert&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Dec 2017 13:07:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/guest-internet-activity/m-p/3472845#M519242</guid>
      <dc:creator>gtilburg</dc:creator>
      <dc:date>2017-12-08T13:07:13Z</dc:date>
    </item>
    <item>
      <title>Re: Guest Internet Activity</title>
      <link>https://community.cisco.com/t5/network-access-control/guest-internet-activity/m-p/3472846#M519243</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There should be an example in the ISE guides, have you looked there?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes it’s supported as a poor mans reporting&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please be aware there are some bugs around logging of guests seen here in regards to remember me https://communities.cisco.com/docs/DOC-76415&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Recommendation for more robust reporting is SIEM&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Dec 2017 13:29:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/guest-internet-activity/m-p/3472846#M519243</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2017-12-08T13:29:40Z</dc:date>
    </item>
    <item>
      <title>Re: Guest Internet Activity</title>
      <link>https://community.cisco.com/t5/network-access-control/guest-internet-activity/m-p/3472847#M519244</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the quick reply Jason.&lt;/P&gt;&lt;P&gt;Do we have any recommended / proven solutions on how to integrate ISE with a SIEM – particularly on how to correlate the URL info with ISE identity?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Gert&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Dec 2017 13:32:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/guest-internet-activity/m-p/3472847#M519244</guid>
      <dc:creator>gtilburg</dc:creator>
      <dc:date>2017-12-08T13:32:04Z</dc:date>
    </item>
    <item>
      <title>Re: Guest Internet Activity</title>
      <link>https://community.cisco.com/t5/network-access-control/guest-internet-activity/m-p/3472848#M519245</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There is nothing documented on our side, we simply send our syslog to splunk for example and then asa would send to them as well&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Up to them to correlate for A guest report&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Splunk may have something&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Dec 2017 13:44:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/guest-internet-activity/m-p/3472848#M519245</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2017-12-08T13:44:05Z</dc:date>
    </item>
  </channel>
</rss>

