<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE Sponsor Portal per AD Group possible? in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-sponsor-portal-per-ad-group-possible/m-p/3472788#M520006</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I don’t see a way to do what you’re looking for unfortunately without creating your own customizations with api which is a lot of work&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I suggested that link solution so that you can create a different sponsor portal and only allow certain groups to use it&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This ways sponsor group x can only use sponsor portal x&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 10 Nov 2017 22:07:45 GMT</pubDate>
    <dc:creator>Jason Kunst</dc:creator>
    <dc:date>2017-11-10T22:07:45Z</dc:date>
    <item>
      <title>ISE Sponsor Portal per AD Group possible?</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-sponsor-portal-per-ad-group-possible/m-p/3472785#M519999</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Guest Sponsor experts,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My customer ISE deployment currently runs on one Guest Sponsor portal. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have various Sponsor Groups based on AD Group membership.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Customer asked me today whether we can present a customised Sponsor Portal &lt;EM&gt;&lt;STRONG&gt;per AD Group&lt;/STRONG&gt;&lt;/EM&gt;, specifically for one reason:&amp;nbsp; When notifying guests via email, they want to be able to specify a custom .png file, depending on the AD Group that the Sponsor belongs to.&amp;nbsp; The logo on the email needs to represent the Group that sent it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I thought about this.&amp;nbsp; If I created a new Sponsor Portal (which also runs on port 8445), I could perhaps use the Identity Source Sequence to differentiate Portal A from Portal B - but the Identity Source Sequence doesn't work at the AD Group level &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;The only option I can see right now is to create a new Portal, on port 8446, using a new FQDN, new cert, and then I can customise it however I need.&amp;nbsp; Is there a better way?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;cheers&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Nov 2017 05:43:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-sponsor-portal-per-ad-group-possible/m-p/3472785#M519999</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2017-11-10T05:43:47Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Sponsor Portal per AD Group possible?</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-sponsor-portal-per-ad-group-possible/m-p/3472786#M520000</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Craig Hyps has a document that is used for granting access to a sponsor portal depending on LDAP grouping this was used before&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This may work&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;https://communities.cisco.com/docs/DOC-64526?mobileredirect=true&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Point ISE to itself for the different portals and have an fqdn for each&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Nov 2017 15:04:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-sponsor-portal-per-ad-group-possible/m-p/3472786#M520000</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2017-11-10T15:04:44Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Sponsor Portal per AD Group possible?</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-sponsor-portal-per-ad-group-possible/m-p/3472787#M520003</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jason&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;The notification functionalities like SMS and email are tied to the Sponsor Portal definition, and not to the Sponsor Group definitions.&amp;nbsp; I don't think Mr Craig's docoment addresses that use case&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My Use case 1: Sponsors print account emails with Logo X&lt;/P&gt;&lt;P&gt;My Use case 2: Sponsors print account emails with Logo Y&lt;/P&gt;&lt;P&gt;Therefore I have to create a new Sponsor Portal where I can tinker around with that Notification stuff. &lt;/P&gt;&lt;P&gt;My intuition tells me that the Sponsor Portal look and feel should be tied to Sponsor Group definitions, then this would work.&amp;nbsp; Currently there is a lot of "shared/central" Portal config that is share by all the Sponsor Groups.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Maybe I need to rephrase my question&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I don't see a way of keeping my existing &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://sponsor.company.com" rel="nofollow" target="_blank"&gt;https://sponsor.company.com&lt;/A&gt;&lt;SPAN&gt; FQDN that can service both types of use cases above, because in order to produce two different looking account emails, I need to invoke a Specific Sponsor Portal - and how are those enumerated in any logic?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I believe I need to create a new Sponsor Portal Y, and use the existing Sponsor Group concept to restrict access to that AD Group.&amp;nbsp; New Sponsor Portal would have different TCP port and FQDN, and new cert etc.&lt;/P&gt;&lt;P&gt;It would be handy to make the Sponsor Portal look and feel dependent on the AD Groups somehow (kind of like how Guest Portals are enumerated for Authorization Profiles - same&amp;nbsp; TCP port, but separate virtual https servers).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'll try this out in the lab if I get time&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Nov 2017 20:47:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-sponsor-portal-per-ad-group-possible/m-p/3472787#M520003</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2017-11-10T20:47:53Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Sponsor Portal per AD Group possible?</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-sponsor-portal-per-ad-group-possible/m-p/3472788#M520006</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I don’t see a way to do what you’re looking for unfortunately without creating your own customizations with api which is a lot of work&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I suggested that link solution so that you can create a different sponsor portal and only allow certain groups to use it&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This ways sponsor group x can only use sponsor portal x&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Nov 2017 22:07:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-sponsor-portal-per-ad-group-possible/m-p/3472788#M520006</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2017-11-10T22:07:45Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Sponsor Portal per AD Group possible?</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-sponsor-portal-per-ad-group-possible/m-p/3472789#M520007</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The ask here is a bit different in that you are NOT looking for authorization to portal based on AD, but rather AD-based portal/notification content per user (i.e. content changes AFTER auth based on AD membership) which is not something built into ISE today.&amp;nbsp; Mr Kunst has proposed variable-based portal content (in this case, the Sponsor Group is variable), but that would require requests from customers to help prioritize.&amp;nbsp; I suggest work with your Cisco account/partner SE to provide use case and impact to help with prioritization.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Craig&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 11 Nov 2017 12:44:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-sponsor-portal-per-ad-group-possible/m-p/3472789#M520007</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2017-11-11T12:44:26Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Sponsor Portal per AD Group possible?</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-sponsor-portal-per-ad-group-possible/m-p/3472790#M520010</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Exactly Craig&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My proposal is to create a portal per customization and to restrict who can login that portal based off your document&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 11 Nov 2017 13:05:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-sponsor-portal-per-ad-group-possible/m-p/3472790#M520010</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2017-11-11T13:05:58Z</dc:date>
    </item>
  </channel>
</rss>

