<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Missing NetworkAccess UseCase in ISE 2.3 in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/missing-networkaccess-usecase-in-ise-2-3/m-p/3515992#M523156</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I used to use "Network Access:UseCase EQUALS Guest Flow" as the selection criteria to choose Captive Portal authentication in the Policy section. With ISE 2.3 I see no UseCase option anymore...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this a expected behaviour? What is the best alternative?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Roman&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 07 Aug 2017 09:20:06 GMT</pubDate>
    <dc:creator>rovargas</dc:creator>
    <dc:date>2017-08-07T09:20:06Z</dc:date>
    <item>
      <title>Missing NetworkAccess UseCase in ISE 2.3</title>
      <link>https://community.cisco.com/t5/network-access-control/missing-networkaccess-usecase-in-ise-2-3/m-p/3515992#M523156</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I used to use "Network Access:UseCase EQUALS Guest Flow" as the selection criteria to choose Captive Portal authentication in the Policy section. With ISE 2.3 I see no UseCase option anymore...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this a expected behaviour? What is the best alternative?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Roman&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Aug 2017 09:20:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/missing-networkaccess-usecase-in-ise-2-3/m-p/3515992#M523156</guid>
      <dc:creator>rovargas</dc:creator>
      <dc:date>2017-08-07T09:20:06Z</dc:date>
    </item>
    <item>
      <title>Re: Missing NetworkAccess UseCase in ISE 2.3</title>
      <link>https://community.cisco.com/t5/network-access-control/missing-networkaccess-usecase-in-ise-2-3/m-p/3515993#M523157</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;DIV&gt;&lt;P&gt;Make sure you remove any dictionary filters (no icon selected in library) to display all attributes.&amp;nbsp; You can then enter keywords to find network access attributes.&lt;/P&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Aug 2017 11:09:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/missing-networkaccess-usecase-in-ise-2-3/m-p/3515993#M523157</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2017-08-07T11:09:40Z</dc:date>
    </item>
    <item>
      <title>Re: Missing NetworkAccess UseCase in ISE 2.3</title>
      <link>https://community.cisco.com/t5/network-access-control/missing-networkaccess-usecase-in-ise-2-3/m-p/3515994#M523160</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;is that post upgrade?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;try to use the 'Editor'&amp;nbsp; to find the attribute. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/110215_pastedImage_1.png" style="max-width: 1200px; max-height: 900px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Aug 2017 11:27:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/missing-networkaccess-usecase-in-ise-2-3/m-p/3515994#M523160</guid>
      <dc:creator>smashash</dc:creator>
      <dc:date>2017-08-07T11:27:00Z</dc:date>
    </item>
    <item>
      <title>Re: Missing NetworkAccess UseCase in ISE 2.3</title>
      <link>https://community.cisco.com/t5/network-access-control/missing-networkaccess-usecase-in-ise-2-3/m-p/3515995#M523162</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is a fresh install of the FCS code.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I see no UseCase option (with no filters). In fact the only options available are the ones bellow...&lt;/P&gt;&lt;P&gt;&lt;IMG alt="UseCase.PNG" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/110260_UseCase.PNG" style="height: 274px; width: 620px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Aug 2017 17:08:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/missing-networkaccess-usecase-in-ise-2-3/m-p/3515995#M523162</guid>
      <dc:creator>rovargas</dc:creator>
      <dc:date>2017-08-07T17:08:08Z</dc:date>
    </item>
    <item>
      <title>Re: Missing NetworkAccess UseCase in ISE 2.3</title>
      <link>https://community.cisco.com/t5/network-access-control/missing-networkaccess-usecase-in-ise-2-3/m-p/3515996#M523164</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Your screenshot looks like from the conditions studio for authentication policy rules. If that is the case, it's expected not having NA.UseCase, as such attribute will not work correctly during authentication evaluation.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Aug 2017 17:17:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/missing-networkaccess-usecase-in-ise-2-3/m-p/3515996#M523164</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2017-08-07T17:17:11Z</dc:date>
    </item>
    <item>
      <title>Re: Missing NetworkAccess UseCase in ISE 2.3</title>
      <link>https://community.cisco.com/t5/network-access-control/missing-networkaccess-usecase-in-ise-2-3/m-p/3515997#M523166</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In fact, my intention is to use "Network Access:UseCase EQUALS Guest Flow" as the selection criteria to choose Captive Portal authentication in the Policy section, as I have been doing from the first ISE version that supported Policy Sets many years ago...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ISE 2.3 (where I cannot use "Network Access:UseCase EQUALS Guest Flow"):&lt;/P&gt;&lt;P&gt;&lt;IMG alt="ISE23 PolicySet.PNG" class="image-1 jive-image" src="/legacyfs/online/fusion/110261_ISE23 PolicySet.PNG" style="height: 150px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ISE 2.2 (and previous) were I could use "Network Access:UseCase EQUALS Guest Flow"):&lt;/P&gt;&lt;P&gt;&lt;IMG alt="ISE22 PolicySet.PNG" class="jive-image image-2" src="/legacyfs/online/fusion/110262_ISE22 PolicySet.PNG" style="height: 177px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any other alternative?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Aug 2017 17:41:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/missing-networkaccess-usecase-in-ise-2-3/m-p/3515997#M523166</guid>
      <dc:creator>rovargas</dc:creator>
      <dc:date>2017-08-07T17:41:12Z</dc:date>
    </item>
    <item>
      <title>Re: Missing NetworkAccess UseCase in ISE 2.3</title>
      <link>https://community.cisco.com/t5/network-access-control/missing-networkaccess-usecase-in-ise-2-3/m-p/3515998#M523168</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The attribute has been removed as a fix for CSCvc98033 and ISE 2.3 is the only shipping release with this fix.&lt;/P&gt;&lt;P&gt;It's not common to use such attributes for authentications as they would only work for re-auth of an existing session and their existence causes confusion to customers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I do not see any workaround other than for you to re-design the policy sets and moving that inside of an policy set and under authorization.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Aug 2017 18:36:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/missing-networkaccess-usecase-in-ise-2-3/m-p/3515998#M523168</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2017-08-07T18:36:59Z</dc:date>
    </item>
    <item>
      <title>Re: Missing NetworkAccess UseCase in ISE 2.3</title>
      <link>https://community.cisco.com/t5/network-access-control/missing-networkaccess-usecase-in-ise-2-3/m-p/3515999#M523170</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I agree with Hsing.  The session is not considered a guest flow until after authentication.  This means you would have the same session using two different policy sets.  This document has a good description for how that use case is intended to be used: https://supportforums.cisco.com/document/110031/central-web-authentication-cwa-guests-ise  This is another page with a similar description: https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/200273-Configure-ISE-Guest-Temporary-and-Perman.html&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Aug 2017 19:17:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/missing-networkaccess-usecase-in-ise-2-3/m-p/3515999#M523170</guid>
      <dc:creator>gbekmezi-DD</dc:creator>
      <dc:date>2017-08-07T19:17:09Z</dc:date>
    </item>
    <item>
      <title>Re: Missing NetworkAccess UseCase in ISE 2.3</title>
      <link>https://community.cisco.com/t5/network-access-control/missing-networkaccess-usecase-in-ise-2-3/m-p/3516000#M523174</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Correct.&amp;nbsp; I did not catch earlier from mobile device that intent was to use this at Policy Set level.&amp;nbsp; USE_CASE GuestFlow is primarily to match authorization condition, i.e. there is a reauthorization situation where user has just completed successful web auth event.&amp;nbsp;&amp;nbsp; It may have worked in prior model but that was not purpose and need to keep the policy set level for things that are accessible at a higher level in RADIUS conversation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Craig&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Aug 2017 20:26:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/missing-networkaccess-usecase-in-ise-2-3/m-p/3516000#M523174</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2017-08-07T20:26:09Z</dc:date>
    </item>
    <item>
      <title>Re: Missing NetworkAccess UseCase in ISE 2.3</title>
      <link>https://community.cisco.com/t5/network-access-control/missing-networkaccess-usecase-in-ise-2-3/m-p/3516001#M523177</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Along the topic of this thread, am I correct in understanding that "Guest Flow" attribute is set for the RADIUS session when ISE detects the endpoint (ie the user on the endpoint) has authenticated via the CWA portal?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So on first access, user is redirected. They authenticate and then the flag is set and a CoA issued for that session. Upon re-authorization the flag is detected and appropriate access is granted.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Aug 2017 05:44:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/missing-networkaccess-usecase-in-ise-2-3/m-p/3516001#M523177</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-08-25T05:44:44Z</dc:date>
    </item>
    <item>
      <title>Re: Missing NetworkAccess UseCase in ISE 2.3</title>
      <link>https://community.cisco.com/t5/network-access-control/missing-networkaccess-usecase-in-ise-2-3/m-p/3516002#M523180</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Essentially that is correct.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Aug 2017 08:28:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/missing-networkaccess-usecase-in-ise-2-3/m-p/3516002#M523180</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2017-08-25T08:28:20Z</dc:date>
    </item>
    <item>
      <title>Re: Missing NetworkAccess UseCase in ISE 2.3</title>
      <link>https://community.cisco.com/t5/network-access-control/missing-networkaccess-usecase-in-ise-2-3/m-p/4001033#M523183</link>
      <description>I faced the same problem.&lt;BR /&gt;&lt;BR /&gt;How did you solve this?</description>
      <pubDate>Thu, 19 Dec 2019 04:04:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/missing-networkaccess-usecase-in-ise-2-3/m-p/4001033#M523183</guid>
      <dc:creator>JustTakeTheFirstStep</dc:creator>
      <dc:date>2019-12-19T04:04:37Z</dc:date>
    </item>
  </channel>
</rss>

